NextGenEnergyJobsRenewable Energy Jobs
CompaniesCitiesIndustries

NextGenEnergyJobs

The #1 platform for renewable energy careers. Join thousands of professionals who've found their dream jobs in renewable energy, sustainability, and renewable tech.

0+Newsletter subscribers
25K+Jobs posted
100+Companies

Sustainability Partners

Sustainability Software DirectoryRefurbished Tech Guide

Find Jobs

  • All Jobs
  • By Location
  • By State
  • International
  • By Industry
  • Top Companies
  • Job Titles

Job Types

  • Remote Jobs
  • Hybrid Jobs
  • Full-time
  • Part-time
  • Contract
  • Internships
  • Visa Sponsored

Experience

  • Entry Level
  • Mid Level
  • Senior Level
  • Executive
  • Remote Internships

Resources

  • Career Advice Hub
  • Top 10 Jobs
  • Solar Sales Salary
  • Become Solar Engineer
  • Salary Insights
  • CV Analyzer
  • Post a Job

Popular Job Locations

San Francisco
245 jobs
Boston
189 jobs
Denver
167 jobs
Austin
143 jobs
New York
298 jobs
Chicago
132 jobs
Seattle
201 jobs
Portland
98 jobs
Los Angeles
176 jobs
San Diego
87 jobs
Washington DC
203 jobs
Atlanta
112 jobs

Hot Remote Specializations

Project ManagerSolar SalesCustomer SuccessData EntryAll Data Entry
© 2026 NextGenEnergyJobs. All rights reserved.
Privacy PolicyTerms of ServiceAbout UsContact
  1. Home
  2. Jobs
  3. Senior Security Engineer, Product Security
GoodLeap logo

Senior Security Engineer, Product Security

GoodLeap

Remote
Full Time
Posted August 28, 2026
$146k - $185k
Solar Energy
Remote
~28 people viewed this recently
Apply Now

Application opens on company website

Job Description

GoodLeap is a technology company delivering best-in-class financing and software products for sustainable solutions, from solar panels and batteries to energy-efficient HVAC, heat pumps, roofing, windows, and more.

Key Responsibilities

  • Adversarially test our AI and LLM-backed features. Design and run attacks against LLM-backed applications and agents — prompt injection, jailbreaks, tool abuse, data exfiltration — and turn findings into pass/fail criteria product teams will act on.
  • Build and operate production security services. Backend services and internal tooling — APIs, streaming transports, proxy/CLI/chat interfaces — in whichever of TypeScript, Node.js, .NET, or Python fits the problem, held to the same bar as any other production service: test coverage, CI, dependency management.
  • Find new ways to automate the work. Notice when something we do by hand has become automatable, prototype it, and make the case— even when it means replacing a tool we bought last year.
  • Review pull request vulnerability findings. Triage what scanning and AI-assisted review surface across our stacks, separating real findings from noise. Go deep by hand on auth paths and high-risk changes, and feed what you learn back into the tooling.
  • Threat model from product designs. Review PRDs and technical designs before code exists, infer trust boundaries and data flows in unfamiliar domains, and raise security questions while the design is still cheap to change.
  • Test by hand and validate what you find. Manual testing of web applications and APIs, triage for real exploitability, and retest fixes. Support the red team’s bug bounty and continuous penetration testing programs.
  • Keep the AppSec tooling estate running and low-friction. SAST/dependency scanning tuning, finding triage and routing, SSO and access management, and automating the repetitive parts so the program scales without headcount.
  • Secure the infrastructure your tooling runs on. IAM least-privilege scoping, secrets management, and container/network lifecycle — as infrastructure as code, with automated drift checks.
  • Enable engineers to do the right thing. Build security training and documentation engineers will actually use.
  • Evaluate tools and help set the AI bar. Run structured bake-offs of security products against defined requirements and help set the standards AI/agent systems must satisfy before reaching production.
  • Back up the rest of the security team. Support investigations, threat hunting, and incident response for the products you cover, and contribute to the vulnerability management lifecycle and security analytics platform.

Requirements

  • You ship production code. Strong backend engineering in at least one modern language, with at least one service you built that others depend on — async patterns, HTTP APIs, and streaming transports are familiar ground. We work across TypeScript, Node.js, .NET, and Python; depth in one plus the willingness to move between them matters more than any particular stack on your résumé.
  • You can read code you didn’t write, across more than one language and stack, well enough to judge whether a reported finding is real, catch the ones tooling missed, and propose a fix the engineer can act on.
  • You know how identity and authorization actually fail: token exchange and scope handling, session lifetime and revocation, request signing, OAuth pitfalls, and network-layer issues like SSRF and DNS rebinding. We’re looking for reasoning that finds real bugs, not checklist recall.
  • You understand API standards and how to secure them: REST and GraphQL in practice, OpenAPI and schema contracts, input validation, rate limiting, gateway-level auth, and webhook and service-to-service verification.
  • Hands-on testing of web applications and APIs — manual, not just scanner-driven — plus the triage, the clear write-up, and the retest.
  • Threat modeling from written designs. You can read a PRD in an unfamiliar domain, infer trust boundaries and data flows, and ask the right questions while the answer is still cheap.
  • Working AWS and infrastructure-as-code competence: IAM scoping, secrets management, container/compute lifecycle, network egress control, and infrastructure defined as code.
  • Practical exposure to AI/LLM security. You have attacked an LLM-backed application or agent — at work, in a CTF, in published research, or in your own lab — and can tell us what you found and why it worked.
  • You write and speak for people who are not in security. Findings engineers act on, documentation they use, and explanations that hold up in front of a product manager, an executive, or Legal.
  • Having owned an AppSec tooling estate: SAST/SCA tuning, finding routing, false-positive reduction
  • Running structured vendor evaluations or proofs of concept
  • Contributing to security policy or standards, including for AI systems
  • Delivering security training or building hands-on learning environments
  • Depth in cryptography and key management
  • Detection engineering, incident response, or threat hunting exposure
  • An understanding of how SaaS products get built — roadmaps, prioritization, why the ship date exists. Prior product or engineering management experience is a plus, not an expectation.

Ready to Apply?

Join GoodLeap and make an impact in renewable energy

Apply Now

Stay Updated on Sustainability Jobs

Get the latest renewable energy jobs and career tips delivered to your inbox.

Job Alerts

Get notified about new sustainability jobs

More at GoodLeap

IT Support Specialist

Plano$68k

Bilingual Client Support Manager

Bentonville$0k

Bilingual Client Support Manager

Roseville$0k

Similar Jobs

Solar Installer

Sunrun$0k

INSIDE SALES ASSOCIATE ENERGY STORAGE, ITALY (f/m/d)

Canadian Solar$110k

Senior Manager, Environmental Permitting

Arevon$175k

Jobs in Remote

IT Specialist

Samsara$142k

Principal Business Systems Analyst

Samsara$150k

Staff Offensive Security Engineer

Samsara$174k

More jobs at GoodLeap

GoodLeap logo

IT Support Specialist

GoodLeap
NEW
PlanoPlano, TX
Full Time
13h
$58k-68k
GoodLeap logo

Bilingual Client Support Manager

GoodLeap
NEW
BentonvilleBentonville, Argentina
Full Time
13h
$0k-0k/hr
GoodLeap logo

Bilingual Client Support Manager

GoodLeap
NEW
RosevilleRoseville, United States
Full Time
13h
$0k-0k/hr

Similar jobs in Solar Energy

Sunrun logo

Solar Installer

Sunrun
HoustonHouston, TX
Full Time
Jun 30
$0k-0k/hr
Canadian Solar logo

INSIDE SALES ASSOCIATE ENERGY STORAGE, ITALY (f/m/d)

Canadian Solar
RemoteRemote
Full Time
Jul 30
$76k-110k
Arevon logo

Senior Manager, Environmental Permitting

Arevon
ScottsdaleScottsdale, AZ
Full Time
Jul 30
$123k-175k

More jobs in Remote

Samsara logo

IT Specialist

Samsara
NEW
RemoteRemote
INTERN
13h
$89k-142k
Samsara logo

Principal Business Systems Analyst

Samsara
NEW
RemoteRemote
INTERN
13h
$111k-150k
Samsara logo

Staff Offensive Security Engineer

Samsara
NEW
RemoteRemote
INTERN
13h
$139k-174k
Is this your company?Claim your listing — free →