What are the responsibilities and job description for the Application / Product Security Engineering Roles position at The Phoenix Group?
Application / Product Security Engineering Roles
Location: New York City (Hybrid or Flexible)
We work with a range of NYC-based organizations across fintech, asset management, SaaS, and other technology-driven companies that build and operate customer-facing products and platforms.
This posting reflects the types of application and product security engineering roles we consistently see across these teams, rather than a single isolated opening. These environments tend to embed security directly into the software development lifecycle, with security engineers working closely alongside product and engineering teams.
What These Roles Typically Involve
Across these teams, application and product security engineers are commonly responsible for:
- Identifying and mitigating security risks in application code, APIs, and system design
- Partnering with software engineering teams to integrate secure development practices into day-to-day workflows
- Conducting application security reviews, threat modeling, and design assessments
- Supporting vulnerability management and remediation efforts related to application-layer risks
- Helping shape security standards, tooling, and processes as products and platforms evolve
Experience That Tends to Translate Well
Professionals who tend to align well with these roles often bring:
- Hands-on experience securing web applications, APIs, and distributed systems
- Strong understanding of common application security risks and mitigation strategies
- Experience working with modern development stacks and CI/CD pipelines
- Comfort collaborating directly with engineers rather than operating as a separate audit function
- A pragmatic, risk-based approach to security focused on enablement rather than gatekeeping
Backgrounds We Commonly See
Many engineers placed into these types of roles come from:
- Application or product security teams within fintech, SaaS, or technology-forward organizations
- Software engineering backgrounds that transitioned into security-focused roles
- Environments where security is treated as a shared responsibility across engineering teams
- Teams where security engineers have influence over design decisions and long-term architecture
What Differentiates These Environments
Across these organizations, application security is treated as a core engineering function rather than a compliance exercise. Security engineers are expected to understand how products are built, engage early in the development process, and help teams ship secure systems without slowing down delivery.
Compensation
Compensation varies by organization and scope, but typically reflects senior-level responsibility and the business impact of application security.
How to Start a Conversation
If this type of application or product security work aligns with your background or where you want to take your career next, you are welcome to apply or reach out directly to start a conversation. We are happy to share more context about specific teams and environments during an initial discussion.