Product Security Engineer
Fellow Insights Inc. · Canada
Software Development · 51-200 employees
About the role
You will identify and mitigate security risks across the product and infrastructure while partnering with engineering teams to design secure systems. Additionally, you will build security tooling and define practices to ensure safe development, particularly regarding AI-native software.
What they look for
Requirements
The role requires professional experience in product or application security and strong software engineering skills, preferably in Python. Candidates must have experience with threat modeling, vulnerability remediation, and a deep understanding of cloud security and AI-assisted development workflows.
Full description
About Fellow
Fellow is an AI meeting assistant that helps teams record, transcribe, summarise, and act on their meetings.
We are a Series A company backed by Craft Ventures, iNovia Capital, and Felicis Ventures, and were founded by the team behind Fluidware, which was acquired by SurveyMonkey. Fellow is trusted by organisations including Shopify, HubSpot, WarnerMedia, Tucows, and Dynatrace.
People trust Fellow with their company’s most important conversations. Protecting that information shapes how we design our systems, how we develop software, and how we earn the confidence of the organizations that depend on us.
The Role
We are looking for a Product Security Engineer to build on Fellow’s strong security foundation as our product, platform, and use of AI continue to grow. You will have meaningful ownership over identifying what needs attention next, turning broad risks into concrete priorities, and driving improvements from idea through implementation.
You will work directly with engineers across the company to identify risks early, design secure systems, iterate on our development practices, and build tools that make the safest path the easiest one. The work will span application security, cloud infrastructure, authentication and authorization, vulnerability management, incident response, and the new security challenges introduced by AI-native software development.
This is a hands-on engineering role. You will review designs and code, investigate vulnerabilities, contribute fixes, build internal tooling, and help teams turn security findings into durable improvements rather than one-off patches.
It is also an AI-native role. We use tools like Claude Code and Cursor throughout the development process, and we are looking for someone who understands both the enormous leverage and the new risks they introduce. You will help shape how Fellow builds securely in a world where agents increasingly write code, use tools, access data, and participate in engineering workflows.
What you will do
- Proactively identify the highest-leverage opportunities to strengthen Fellow’s security, define a practical path forward, and take ownership of driving the work across teams.
- Build on the systems and practices already in place, continually raising the bar as Fellow’s product, architecture, and threat landscape evolve.
- Partner with engineering teams early in the development process to threat model new features, review designs, and identify practical ways to reduce risk before code reaches production.
- Perform security-focused code reviews and provide practical guidance on authentication, authorization, data protection, input handling, secrets, and business logic.
- Build and improve reusable security primitives, paved-road patterns, libraries, and platform controls that help engineers create secure systems by default.
- Introduce and evolve security tooling across the development lifecycle, including static analysis, dependency scanning, secret detection, infrastructure scanning, and CI/CD guardrails.
- Find, prioritize, and drive the remediation of vulnerabilities identified through internal testing, automated tooling, penetration tests, customer reports, or external researchers.
- Contribute to security incident response, from investigation and containment through root-cause analysis and post-incident hardening.
- Help engineers build strong security judgment through practical guidance, shared learning, and collaboration rather than gates and hand-offs.
- Evaluate the security implications of AI agents and AI-assisted development, and build the tools, controls, and workflows required to use them safely at scale.
What we are looking for
- Professional experience in product security, application security, software engineering, infrastructure security, or a role that combined several of these areas.
- Strong software engineering skills and proficiency in at least one modern programming language, ideally Python.
- Experience identifying and remediating common application vulnerabilities, including issues related to authentication, authorization, injection, data exposure, secrets, and business logic.
- Experience conducting threat models, security design reviews, and security-focused code reviews for production software.
- The ability to move beyond identifying risks by writing code, building tooling, and helping engineering teams implement durable solutions.
- Experience with security tooling such as SAST, SCA, DAST, secret scanning, cloud posture management, or infrastructure-as-code scanning.
- Familiarity with cloud infrastructure and security concepts across areas such as IAM, networking, containers, Kubernetes, and infrastructure as code.
- A strong self-starter mindset and a track record of taking ambiguous, important problems from initial investigation through implementation and measurable improvement.
- The ability to operate with significant ownership, set direction within your area, and bring the right people together without waiting for work to be fully defined for you.
- Deep, practical use of AI coding agents such as Claude Code, Cursor, Codex, or similar tools, paired with strong judgment and a track record of developing new agentic workflows, tools, or practices that materially improve how software gets built.
- Curiosity about emerging threats and a desire to keep learning as both software development and attack surfaces evolve.
Nice to have
- Experience with penetration testing, offensive security, bug bounty programs, or working directly with external security researchers.
- Experience securing AI-powered products, agentic systems, model integrations, or tools that allow AI systems to access data and take actions.
- Participation in the security community through research, open-source contributions, writing, or speaking.
How we work
Fellow is a remote-first company with core collaboration hours from 10 a.m. to 4 p.m. Eastern Time.
This role is open to candidates located in Canada. Optional office space is available in Ottawa, Montreal, and Toronto.
We move quickly, share work early, and help one another get unstuck. We like ambitious goals, practical solutions, and people who bring energy to solving problems.
And we believe work should be fun! The work matters, but we do our best work when people are curious, collaborative, direct, and genuinely excited to solve difficult problems together.