AppSec Jobs
← Back to all jobs

Playlist

Sr Product Security Engineer

São Paulo, São Paulo, BrazilPosted 3 weeks agoWebsite
Apply on LinkedIn →

At a Glance

4+ years experiencePythonJavaScript/TypeScriptC#/.NETKubernetesDocker

About This Role

As a Senior Security Engineer on the Product Security team, you will be responsible for reducing security friction across engineering by fostering partnership and collaboration to enhance the security posture. Security enablement will be crucial, spanning devsecops integration, automation, vulnerability identification, remediation, and hands-on tooling development. You will own the integration and operation of SAST, DAST, SCA, and CNAPP solutions within CI/CD pipelines, identifying issues, submitting remediation PRs, and validating fixes through automated retesting. You will build, maintain, and continuously improve agentic security tooling that scales the team's capabilities across all phases of the SDLC. You'll ensure software solutions are secure by default, facilitate continuous security testing, measurability, and reporting on security initiative impact, and pursue continuous improvement to help Playlist achieve its mission of powering the world's fitness and wellness businesses.

Responsibilities

  • Partner with software engineering and platform teams to identify and solve complex security problems
  • Operate, integrate, and continuously tune SAST, DAST, SCA, and CNAPP tooling within pipelines — supporting engineering, triaging findings, driving remediation, and measuring coverage and effectiveness over time
  • Design, build, and maintain agentic security tools — including LLM-assisted workflows for exploitable code identification, vulnerability triage, and remediation guidance — deployed across planning, development, testing, and production phases of the SDLC
  • Identify security gaps and demonstrate strategic recommendations for remediation
  • Address security issues identified throughout the secure software development lifecycle
  • Conduct security testing, beginning with the product planning phase continuing through production deployment
  • Define and integrate security requirements ensuring alignment with industry standards and best practices
  • Ability to work independently, and lead both cyber security and cross functional security initiatives
  • Stay abreast of emerging security threats, vulnerabilities and controls
  • Reduce security friction across engineering by fostering partnership and collaboration to enhance security posture
  • Facilitate continuous security testing, measurability, and reporting on the impact of security initiatives

Requirements

devsecopsPythonTypeScriptSASTDASTSCASemgrepCheckmarxSnykCI/CDBurp SuiteDockerKubernetes
  • 4+ years experience across multiple security domains with an emphasis on product security and cloud-native security
  • Verifiable software engineering and penetration testing skills
  • 2+ years senior security experience leading and executing product security initiatives (devsecops, security consulting, and penetration testing)
  • Proficiency with modern languages including Python, .NET, or TypeScript
  • Hands-on experience building security automation, integrations, and agentic tooling
  • Hands-on experience operating and integrating SAST, DAST, SCA, WAF, and CNAPP solutions (e.g., Semgrep, Checkmarx, Snyk, Wiz, or equivalents) within CI/CD pipelines
  • Hands-on experience with design, code review, and securing products and solutions for public cloud-based applications and infrastructure
  • Experience with offensive testing tools like Burp Suite and Kali Linux
  • Experience securing applications deployed using Docker, Kubernetes, and public cloud environments
  • Product Security experience working for a SaaS-based organization or within a consulting firm
  • Excellent leadership skills with a track record of driving security initiatives within software development teams
  • Excellent communication skills (both written and verbal)
  • Self-motivated, self-directed, and self-organized
  • Deep expertise in devsecops, cloud security, and application security
  • Ability to write code to solve security problems, not just identify them
  • Fluency in one or more modern languages with comfort building automation, integrations, and agentic tooling

About Playlist

Playlist is an AI-driven SaaS company based in Portola Valley, California. It focuses on enhancing the experiences economy through its brands, which include Mindbody, Booker, and ClassPass. With a reported revenue of $6.4 million and a team of fewer than 25 employees, Playlist has raised $104 million in funding, including a recent $100 million round, in partnership with Vista Equity Partners. The company offers a suite of interconnected tools designed for the fitness, wellness, beauty, and lifestyle sectors. Mindbody is a leading platform that helps businesses manage and grow their operations. Booker provides back-office software for spas and salons, while ClassPass is a consumer membership app that allows users to explore various fitness and wellness classes. These offerings support entrepreneurs and service providers in delivering enriching community experiences.

Industry

information technology & services

Employees

2,500

103 engineers

Revenue

$5M

Website

Visit →

Security at Playlist

Compiled from public job postings, careers pages, and company materials. Data may not reflect current state — verify during interviews.

3 Intel Signals

Security Philosophy

  • Playlist's core AppSec mission is to prevent unauthorized access to customer data.
  • The company follows a Defense in Depth approach, protecting its organization and customer data at every layer, aligned with CIS CSC and the NIST cyber security framework.
  • The philosophy emphasizes developer enablement over gatekeeping, focusing on reducing security friction across engineering by fostering partnership and collaboration.
  • Security enablement is crucial, spanning devsecops integration, automation, vulnerability identification, and remediation.
  • The program conducts continuous security testing from product planning through production deployment, with emphasis on identifying security gaps and demonstrating strategic recommendations for remediation.
  • The company seeks to stay abreast of emerging security threats, vulnerabilities and controls, and to measure the impact and effectiveness of security initiatives over time.

Security Team

  • Playlist's Application Security team operates under the CISO with dedicated sub-functions: "The CISO is supported by dedicated experts across Product Security, Security Engineering, Cyber Defense, Detection and Response." Org structure includes a centralized Product Security function under CISO, with embedded Business Security Partners working across business units.
  • Key leaders include Michael Jacobs (Deputy CISO/Director, Security Operations & Engineering, Mindbody), Celeste Sibbach (Lead Business Security Partner), and Matt D./decapua (Cyber Security Director of Product Security).
  • Team size estimate based on public LinkedIn profiles and active job postings is approximately 8–15 people across Product Security + Security Champions coordination.
  • Active AppSec hiring shows 4 open security-engineering postings (3 Sr Product Security Engineer roles in Brazil, 1 Business Security Partner role).

Key Initiatives

  • Security Champions Program (partial evidence): Team works closely with security champions, engineering teams, and company leadership, though no published charter or operating model is publicly available.
  • Shift Left practices: Security testing begins in product planning phase and continues through production deployment, with devsecops integration and automation.
  • Vulnerability Management: Sources include SAST, DAST, SCA, CNAPP tools, offensive testing tools (Burp Suite, Kali Linux), and penetration testing.
  • Process includes LLM-assisted workflows for exploitable code identification, vulnerability triage, and remediation guidance.
  • Secure SDLC: Includes security requirements definition aligned with industry standards, code review, and addressing security issues throughout the development lifecycle.
  • Recent initiatives include EGYM merger completion (Apr 2026), Playlist brand launch (Jun 2025), and active AppSec team expansion with multiple open senior-level positions.

Preparing for an AppSec interview?

Get the weekly briefing 2,000+ security pros trust.

Interested in this role?

Apply on LinkedIn