Sequoia Capital Global Equities is seeking a Staff Product Security Engineer at Reddit, a leading platform for authentic online conversations. The role focuses on designing and implementing secure frameworks and controls to enhance product security, particularly in the context of AI-assisted development.
Responsibilities:
- Build and evolve secure frameworks, guardrails, and library-level controls that make common vulnerability classes harder to introduce
- Design security controls for AI-assisted development — including reusable rule packs and skills that shape how engineers and coding agents generate, review, and ship code
- Embed security into the workflows engineers already use
- Drive product security reviews for new launches and major architectural changes
- Identify and eliminate systemic security debt
- Shape strategy, influence architecture, and drive execution across teams
Requirements:
- 8+ years of experience in software engineering, product security, or application security, with at least 2 years operating at a staff level of scope and impact
- Proficiency in one or more languages (Go, Python, JS/TS)
- Experience designing, building, and operating production-quality systems and developer-facing platforms
- Experience building secure frameworks, libraries, or guardrails that improve security across many teams at once
- Demonstrated ability to integrate security into developer workflows: CI/CD, code review, release processes, and internal platforms
- Clear communicator who can explain technical detail and business impact to both engineers and leadership
- Comfortable in fast-moving environments where AI-assisted development is reshaping how software is built and reviewed
- Experience with vulnerability discovery and remediation pipelines, including bug bounty or researcher-reported findings
- Track record of mentoring engineers and raising the technical bar across a security or platform engineering org
- Experience securing AI/LLM systems, agentic workflows, or AI-assisted development tooling
- Familiarity with authentication/authorization systems, cloud-native platforms, and how to secure them