Product Security Engineer
About this role
About DevRev
At DevRev, we're building the future of work with Computer – your AI teammate. Unlike traditional tools, Computer unifies all your data sources, tools, and workflows into a single AI-ready platform, giving employees real-time insights, proactive suggestions, and powerful agentic actions. It extends your existing software with AI-native apps and agents that work alongside your teams and customers – updating workflows, coordinating across teams, and eliminating repetitive work. We call this Team Intelligence: human-AI collaboration that breaks down silos, brings people back together, and frees you to solve bigger problems. Backed by Khosla Ventures and Mayfield with $150M+ raised, DevRev is trusted by global companies across industries.
About the Role:
We’re a growing SaaS startup building our security team from the ground up. We’re looking for a hands-on Product Security Engineer who enjoys breaking things (responsibly) and helping teams fix them fast.
This role is very practical and impact-driven. You’ll be embedded close to the product and engineering teams, proactively attacking our own systems before anyone else does. If you like moving fast, owning problems end-to-end, and thinking like a real attacker, this role is for you.
What You'll Do:
- Actively test our SaaS product for security vulnerabilities across web apps, APIs, and cloud infrastructure.
- Perform manual security testing and targeted penetration tests (beyond automated scanners).
- Implement and help implement automated security test suites.
- Identify abuse cases, business logic flaws, and real-world attack paths.
- Work directly with engineers to reproduce issues and drive fixes.
- Help introduce lightweight security practices into the development process (threat modeling, secure design reviews).
- Validate fixes and ensure issues are fully resolved.
- Stay current on new vulnerabilities, attack techniques, and SaaS-relevant threats.
What You'll Bring:
- 8+ years of experience in application security, offensive security, or penetration testing.
- Strong understanding of web and API security (OWASP Top 10, auth, sessions, access control).
- Experience testing modern SaaS products.
- Comfort working in cloud environments (AWS / GCP / Azure at a practical level).
- Experience with common security testing tools (Burp Suite, Nuclei, etc.).
- Ability to communicate findings clearly and pragmatically to engineers.
- Self-starter mindset — comfortable operating with limited process and high ownership.
Preferred, but not required:
- Startup experience or early-stage product exposure.
- Bug bounty or responsible disclosure experience.
- Secure code review experience (any major language).
- Familiarity with CI/CD and modern SDLC security.
- Offensive security certifications (OSCP, GWAPT, etc.).
DevRev is an equal opportunity employer and does not discriminate on the basis of race, gender, sexual orientation, gender identity/expression, national origin, disability, age, genetic information, veteran status, marital status, pregnancy or related condition, or any other basis protected by law.
Company at a glance
Computer is the most precise, efficient, and safe AI platform for enterprise search, employee service/help desk, and customer support (including voice).
It works by unifying all your existing systems and data into a patented, AI-ready knowledge graph: Native Shared Memory. Every tool, every team, every customer conversation lives in this compounding context. So every answer and action is grounded in what your company knows, and how it operates. With permissions and safety guardrails respected, always.
PROVEN EFFICIENCY, PRECISION, AND SAFETY
We tested Computer against the market-leading AI on enterprise data:
- 48% more accurate
- 4.4x fewer tokens used
- Cost stays flat at 256x data growth (vs. 29% growth)
These results are from “Enterprise-Bench” – the AI industry’s first open, vendor-neutral benchmarking tool. Developed with Laude Institute, validated by Professor Alexandros Dimakis (UC Berkeley). The benchmark model, dataset, and traces are all public. (Feel free to get in touch to learn more.)
REAL-WORLD RESULTS
More and more companies are trusting Computer
- Bolt: 40% faster ticket resolution. 43% cut in live ticket volume. 25% increase in customer retention.
- Bill: 70% of support tickets fully resolved without a human. 100% deployment across all market segments in 15 weeks. Up to $6M in annual savings.
- $1.1B org*: 2,000+ new hires onboarded in one year without hiring extra IT staff. 10 weeks to full deployment across all teams.
*We can’t reveal the name of our (very) happy customer just yet – but we will soon.
DevRev is headquartered in Palo Alto, with eight global offices. We’re backed by Khosla Ventures and Mayfield, with $150M+ raised. Founded by Dheeraj Pandey, former co-founder and CEO of Nutanix [NASDAQ: NTNX], and board member at Adobe [NASDAQ: ADBE], alongside Manoj Agarwal, former SVP of Engineering at Nutanix.
Tired of cold applications?
Sign up with Clera and we'll reach out the moment a role actually fits you — no more spraying applications into the void.
Know someone who'd be great for this?