Back to search
EngineeringNot provided by source

Senior Product Security Engineer

Anyscale · Not provided by source

Apply
Last seen by MeritLog September 8, 2026Source: AshbySource version: ashby-public-job-posting-v1

MeritLog read this listing from Anyscale's Ashby job board and last checked it on September 8, 2026.

Source: the employer's Ashby job board. Open the original listing for current details.

Job details

Work model
Not provided by source
Salary
$180K - $210K
Location
San Francisco
Company website
www.anyscale.com

Hiring context

How this role compares at Anyscale

Anyscale has 19 live roles in MeritLog’s catalog across 4 job families, and 11 of them are in engineering. 16 of those listings publish a pay range, a disclosure rate of 84%.

This role's posted range of $180K - $210K sits above 13% of the 15 other Anyscale roles quoted over the same currency and period.

Anyscale concentrates this hiring in:

Counted across the job boards MeritLog tracks, at the time this page was served. Pay comparisons use only listings that publish a complete range in the same currency and period.

What the role asks for

What you'd do

  • Own and operate a scalable secure software development lifecycle: threat modeling, security requirements, secure design practices, and scanning that engineering can readily adopt.
  • Partner with engineering on security features and secure-by-design architecture, from early design through implementation.
  • Review the security of existing systems and new initiatives, and turn findings into prioritized, actionable work.
  • Own vulnerability management for what we ship: enumerate components, map known vulnerabilities, and produce accurate posture reporting on demand.
  • Drive vulnerabilities to resolution with engineering against defined SLAs.
  • Own software composition analysis, secret scanning, and SAST across product repositories, and set the bar for secure-development checks.
  • Mentor other engineers and raise the security bar across the organization.

What they're asking for

  • 8+ years in product or application security, with senior-level depth, ideally at a high-growth startup.ExperiencePreferred
  • Demonstrated ownership of a secure software development lifecycle at scale, including threat modeling and secure design review.Skill
  • A strong hands-on background partnering with engineering on security features and architecture, not just reporting findings.Skill
  • Deep experience with software composition analysis, secret scanning, and SAST or secure-development tooling in real repositories.Skill
  • A solid understanding of software supply chain security and how to enumerate what an organization ships, including SBOM approaches.Skill
  • Experience triaging vulnerabilities using CVSS and business context and driving them to resolution with engineering.Skill
  • The communication and seniority to set direction, review others' work, and raise the bar for those around you.Skill
  • Experience producing vulnerability or security posture reporting for enterprise or regulated customers.SkillPreferred
  • Familiarity with container artifact security, including image scanning, signing, and SBOM generation.SkillPreferred
  • Experience building or maturing an SSDL program at scale.SkillPreferred
  • Background in AI or ML platforms or distributed systems.SkillPreferred

Parsed by MeritLog from the employer’s own posting. The full description follows below.

Job description

At Anyscale https://www.anyscale.com/, we're on a mission to democratize distributed computing and make it accessible to software developers of all skill levels. We’re commercializing Ray https://docs.ray.io/en/latest/, a popular open-source project that's creating an ecosystem of libraries for scalable machine learning. Companies like OpenAI https://thenewstack.io/how-ray-a-distributed-ai-framework-helps-power-chatgpt/, Uber https://www.uber.com/blog/horovod-ray/, Spotify https://engineering.atspotify.com/2023/02/unleashing-ml-innovation-at-spotify-with-ray/, Instacart https://www.youtube.com/watch?v=3t26ucTy0Rs&list=PLzTswPQNepXmLUiL4F_1VHrPcCz1OeILw&index=23&pp=iAQB, Cruise https://www.youtube.com/watch?v=gj0BqvfX_wI&list=PLzTswPQNepXmLUiL4F_1VHrPcCz1OeILw&index=46&pp=iAQB, and many more, have Ray in their tech stacks to accelerate the progress of AI applications out into the real world. With Anyscale, we’re building the best place to run Ray, so that any developer or data scientist can scale an ML application from their laptop to the cluster without needing to be a distributed systems expert. Proud to be backed by Andreessen Horowitz, NEA, and Addition https://www.wsj.com/articles/ai-startup-anyscale-adds-99-million-to-andressen-horowitz-led-funding-round-11661254200 with $250+ million raised to date. ABOUT THE ROLE Anyscale's product security needs are growing as we ship to larger and more demanding customers. We're looking for a Senior Product Security Engineer to own our secure software development lifecycle and to be engineering's partner on building security into the product. Reporting to the Head of Security, you will work in close partnership with engineering. This is a senior, high-ownership role. You will own and operate a scalable SSDL, partner with engineering on security features and secure design, review the security of existing systems and new initiatives, and own how we find, track, drive to resolution and report on vulnerabilities in what we ship. This role is based in India. In your first year, success looks like an SSDL that scales with engineering rather than gating it, security review embedded in how new initiatives ship, and accurate, on-demand vulnerability reporting backed by a working path to resolution. WHAT YOU'LL DO - Own and operate a scalable secure software development lifecycle: threat modeling, security requirements, secure design practices, and scanning that engineering can readily adopt. - Partner with engineering on security features and secure-by-design architecture, from early design through implementation. - Review the security of existing systems and new initiatives, and turn findings into prioritized, actionable work. - Own vulnerability management for what we ship: enumerate components, map known vulnerabilities, and produce accurate posture reporting on demand. - Drive vulnerabilities to resolution with engineering against defined SLAs. - Own software composition analysis, secret scanning, and SAST across product repositories, and set the bar for secure-development checks. - Mentor other engineers and raise the security bar across the organization. WHAT YOU'LL BRING - 8+ years in product or application security, with senior-level depth, ideally at a high-growth startup. - Demonstrated ownership of a secure software development lifecycle at scale, including threat modeling and secure design review. - A strong hands-on background partnering with engineering on security features and architecture, not just reporting findings. - Deep experience with software composition analysis, secret scanning, and SAST or secure-development tooling in real repositories. - A solid understanding of software supply chain security and how to enumerate what an organization ships, including SBOM approaches. - Experience triaging vulnerabilities using CVSS and business context and driving them to resolution with engineering. - The communication and seniority to set direction, review others' work, and raise the bar for those around you. NICE TO HAVE - Experience producing vulnerability or security posture reporting for enterprise or regulated customers. - Familiarity with container artifact security, including image scanning, signing, and SBOM generation. - Experience building or maturing an SSDL program at scale. - Background in AI or ML platforms or distributed systems.

Privacy choices

Analytics and advertising stay off unless you allow them. Private data stays out.

Read the privacy notice