Role Overview
Yahoo is hiring a Paranoids Senior Product Security Engineer. This is a full-time role in United States of America. Part of Yahoo's Security hiring, posted today. applications are still in the early window, before most candidates have applied. Full responsibilities, required qualifications, and the apply link are listed in the description below.
Salary Context
Salary is not disclosed in this posting. Market median for Senior-level Security roles is $144k-$190k (based on 216 comparable listings). Many employers share specifics during the interview process or after an initial screen.
Resume Keywords to Include
Make sure these keywords appear in your resume to improve ATS scoring
Job description
A Little About Us
When you impact millions of people every day, you become a large target for adversaries of all types within all layers of the stack. Our job is to keep our users safe and make Yahoo one of the safest places on the Internet. We are the information security team at Yahoo; known as "The Paranoids".
Within the Paranoids, the Product Security team is on the front line — embedded directly in how Yahoo's products get built. We live inside the software development lifecycle, from the first line of code to production, hunting for weaknesses before an adversary can. Threat Modeling, Static and Dynamic reviews, architecture review, bug bounty — this is where security meets engineering, and where we make sure "shipping fast" and "shipping safe" are never a tradeoff.
A Lot About You
As a Paranoids Product Security Engineer, you have the opportunity to guide secure development for a product area and in addition, own and drive secure development initiatives affecting the overall enterprise.
Responsibilities
Independently lead application and mobile security assessments, from design to deployment, for key enterprise products.
Drive threat modeling and risk assessments for high-impact systems, guiding engineering teams through secure design trade-offs.
Partner with developers to embed security into build and release pipelines, and identify opportunities for automation.
Develop and maintain internal security tooling and reusable frameworks to scale security across teams.
Lead the remediation of critical vulnerabilities and help coordinate with incident response when needed.
Mentor other security engineers and advocate for secure development practices across product and engineering teams.
Collaborate cross-functionally with cloud security, infrastructure, and compliance teams to ensure holistic protection of applications and data.
Stay informed on emerging threats, frameworks, and technologies, and proactively improve security posture through innovation.
Minimum Requirements
5+ years of experience in application or product security, with demonstrated impact securing large-scale web and/or mobile applications.
Deep understanding of secure application architecture, including authentication, authorization, encryption, and data protection across distributed systems.
Proven hands-on experience performing threat modeling, secure design reviews, and code assessments for complex applications and APIs.
Strong technical knowledge of web technologies (HTTP, TLS, CSP, cookies, OAuth, JWTs, GraphQL, REST APIs) and mobile security (iOS/Android app security models, keychains, secure storage, code obfuscation).
Proficiency using and integrating application security tooling (SAST, DAST, IAST, dependency scanning, container scanning) into CI/CD pipelines.
Practical experience with vulnerability triage and remediation workflows — coordinating across engineering teams to ensure timely fixes.
Hands-on skills in at least one backend or systems programming language (e.g., Go, Java, Python, C#) and one frontend or mobile language (e.g., JavaScript/TypeScript, Swift, Kotlin).
Experience contributing to or automating security testing and validation in continuous integration environments.
Strong ability to communicate security risks and solutions clearly to engineers, managers, and non-technical stakeholders.
Track record of driving security improvements across teams — through frameworks, documentation, training, or developer engagement.
Working knowledge of AI/LLM application security fundamentals — including prompt injection, insecure output handling, sensitive data exposure through model inputs/outputs, and the OWASP Top 10 for LLM Applications.
Experience reviewing applications that integrate LLMs or AI services, with the ability to identify common risks across AI pipelines (RAG, agentic tools, model APIs).
Bachelors Degree in a relevant field or equivalent work experience
Preferred
Experience designing and maintaining secure frameworks or libraries used by multiple engineering teams.
Familiarity with cloud-native application security (AWS/GCP/Azure), identity and access management, and secrets management.
Experience leading or mentoring junior engineers in secure coding, threat modeling, and vulnerability management.
Background with mobile application hardening, anti-tampering, and reverse engineering defenses.
Understanding of supply chain security, including dependency management and integrity verification.
Contributions to open-source security tools, security research, or industry standards bodies.
Experience threat modeling AI/ML systems, including RAG pipelines, agentic workflows, and tool-use frameworks (e.g., Model Context Protocol).
Familiarity with model supply chain security — model and dataset provenance, weight integrity, and risks of third-party models and embeddings.
Hands-on experience with AI-assisted security tooling (e.g., LLM-powered code review, automated triage, security agents) and an understanding of their limitations and failure modes.
Awareness of emerging AI security frameworks such as NIST AI RMF, MITRE ATLAS, and the OWASP Top 10 for LLM Applications.
Certifications such as GWEB, GWAPT, OSWE, or CSSLP a plus, but not required.
The material job duties and responsibilities of this role include those listed above as well as adhering to Yahoo policies; exercising sound judgment; working effectively, safely and inclusively with others; exhibiting trustworthiness and meeting expectations; and safeguarding business operations and brand integrity.
At Yahoo, we offer flexible hybrid work options that our employees love! While most roles don’t require regular office attendance, you may occasionally be asked to attend in-person events or team sessions. You’ll always get notice to make arrangements. Your recruiter will let you know if a specific job requires regular attendance at a Yahoo office or facility. If you have any questions about how this applies to the role, just ask the recruiter!
Yahoo is proud to be an equal opportunity workplace. All qualified applicants will receive consideration for employment without regard to, and will not be discriminated against based on age, race, gender, color, religion, national origin, sexual orientation, gender identity, veteran status, disability or any other protected category. Yahoo will consider for employment qualified applicants with criminal histories in a manner consistent with applicable law. Yahoo is dedicated to providing an accessible environment for all candidates during the application process and for employees during their employment. If you need accessibility assistance and/or a reasonable accommodation due to a disability, please submit a request via the Accommodation Request Form (www.yahooinc.com/careers/contact-us.html) or call +1.866.772.3182. Requests and calls received for non-disability related issues, such as following up on an application, will not receive a response.
We believe that a diverse and inclusive workplace strengthens Yahoo and deepens our relationships. When you support everyone to be their best selves, they spark discovery, innovation and creativity. Among other efforts, our 11 employee resource groups (ERGs) enhance a culture of belonging with programs, events and fellowship that help educate, support and create a workplace where all feel welcome.
The compensation for this position ranges from $128,250.00 - $266,875.00/yr and will vary depending on factors such as your location, skills and experience.The compensation package may also include incentive compensation opportunities in the form of discretionary annual bonus or commissions. Our comprehensive benefits include healthcare, a great 401k, backup childcare, education stipends and much (much) more.Currently work for Yahoo? Please apply on our internal career site.
About Yahoo
Yahoo
legal.yahoo.com
37 other open roles at Yahoo on TryApplyNow.
Frequently Asked Questions
How do I apply for the Paranoids Senior Product Security Engineer position at Yahoo?
Use the Apply button above to submit your application directly to Yahoo. Most applications take less than 5 minutes if your resume and contact details are ready, and you'll be routed to the employer's official application system to finish.
Where is the Paranoids Senior Product Security Engineer position at Yahoo located?
This position is based in United States of America. Yahoo has not indicated remote or hybrid options for this role, so candidates should plan for on-site work.
What does a Paranoids Senior Product Security Engineer at Yahoo earn?
Yahoo has not disclosed a salary range in this posting. Many employers share specifics later in the interview process; you can also ask during a recruiter screen if compensation transparency is important to you.
When was the Paranoids Senior Product Security Engineer role at Yahoo posted?
This role was posted on July 24, 2026 (today). It's still listed as actively hiring; we re-confirm openings against the source system multiple times per day and remove closed roles.
How much experience does the Paranoids Senior Product Security Engineer role at Yahoo require?
This is a senior-level position. Most senior roles call for 5+ years of directly relevant experience. Yahoo lists their specific requirements in the description below, so review the must-have qualifications closely before applying.
Similar Jobs
Bank Operations Specialist
Commerce Bank
Facilities Maintenance Technician
Ken Garff Auto Group
Mechanical Engineer I - Electronics Packaging
RTX
Patient Services Associate II - Urology - Center City - Full-Time Days
Jefferson Health
Nightlife/Events Admission Agent
Wynn Resorts
More Jobs at Yahoo
View all →AI-powered job search
Get every job scored to your resume
Upload your resume and get jobs ranked, your resume tailored, and employee contacts found automatically.
Get started freeNo credit card to start