Close is hiring its first dedicated Product Security Engineer to make security work systematic across its product and infrastructure. The role involves finding vulnerabilities, determining their importance, and driving remediation. This is a new role at Close with significant room to shape security practices and tooling.
🏢 About Close
Since 2013, Close has been building a CRM that helps sales teams sell more, faster. Now, they're integrating AI into every part of it, so Close does the busywork and your team does the selling. Close is bootstrapped and profitable, with a 120-person, 100% remote team focused on building a sales CRM that helps small, scaling businesses succeed.
🎯 The Role
You'll report to the Backend Platform team manager within EPD (Engineering, Product, and Design), while working across the entire product and infrastructure surface. You'll find vulnerabilities, determine which findings matter most, and drive them through remediation. Often you'll fix the problem yourself. Other times you’ll give the owning team a clear reproduction, a practical path forward, and enough context to prioritize correctly.
✅ Key Responsibilities
Analyze code, build proof-of-concepts, test running applications, tune or replace noisy tools, and automate the repetitive parts of vulnerability management.
Partner closely with the Infrastructure team on cloud security, access, and secrets, and with the Security & Trust Lead on GRC Engineering, compliance (SOC 2) goals, audits, and corporate security.
Find vulnerabilities conventional scanners may miss, using modern AI-assisted review pipelines to uncover subtle flaws in web apps and APIs.
Threat-model designs, white-box review code, and test running systems.
Turn findings into safe reproductions, assess exploitability and business impact, and retest the eventual fix.
📌 Required Qualifications
An application security engineer who writes code, able to move from reading an unfamiliar code path to reproducing an exploit to proposing or shipping a production-quality fix.
Strong Python or TypeScript experience; fluency across both backend and frontend systems is even better.
Skilled at finding vulnerabilities conventional scanners may miss.
Experience with SAST, DAST, software composition analysis, container scanning, secrets scanning, or cloud posture tooling.
Offensive-minded and operationally responsible, knowing how to test like an attacker without being careless with customer data or production systems.
Competitive pay plus an organization-wide goal-based bonus
~5 weeks of PTO to start, plus a 1-week all-company Winter Holiday Break and paid US holidays. Earn 2 extra days for every year with Close.
80% Work Option: Work with your manager to choose between a standard 5-day week or a 4-day week at 80% pay
Parental Leave: Paid leave for primary and secondary caregivers
Sabbatical: A 1-month paid sabbatical every 5 years with the team
Healthcare (US residents): Two medical plans with Close covering 99% of your premium, plus Dental, Vision, HSA, FSA, and company-paid Long-Term Disability
401k (US residents): We match your contributions up to 6%, vested immediately