Staff Engineer, Product Security

2 months ago


Chicago, United States Grubhub Full time

Grubhub is seeking a seasoned Staff-level Software Engineer to design, develop, and maintain security infrastructure and tools to protect the company's platform and data. Grubhub is in growth-mode and we need standardized processes and tools that can be scaled across the organization, to ensure that security measures keep up with the pace of the business. You will work closely with cross-functional teams, including software engineering (FE + BE), IT, and SRE, to ensure our security practices are robust and scalable. Your expertise will help us achieve our goal of building secure, resilient, and efficient systems. A key part of your role will be to develop and maintain "paved roads" for security, creating standardized and streamlined paths that make secure practices the easiest and most efficient options for our teams. This role reports directly to the head of cybersecurity with broad latitude to work with both senior and new-grad engineers to make a measurable impact on Grubhub’s security posture.


Your Impact

  • You will enhance the overall security posture of Grubhub by identifying and mitigating security defects proactively.
  • You will contribute to a culture of cybersecurity awareness and continuous improvement within the organization, enabling Grubhub to launch and sustain key business initiatives with minimal risk.
  • You will champion high-integrity + high-assurance outcomes in order to ensure the delivery of secure and trustworthy experiences
  • You’ll tangibly reinforce our #1 technology philosophy: “security first” by integrating security into the development process from the start, rather than as an afterthought.


What You Will Do

  • Identify lacking security-sensitive functionality in Grubhub’s applications and services, translating those control gaps into actionable engineering remediation plans and solutions
  • Design, build, deploy and drive adoption of embedded security tooling in conjunction with internal services and platform teams
  • Perform threat modeling, design, and code reviews to assess security implications and requirements for the introduction of new security systems and technologies
  • Drive initiatives with outside teams to re-engineer existing services to ensure that Grubhub remains resilient against the latest security threats
  • Bridge security domain knowledge gaps through technical mentorship of a team of passionate engineers while also delivering uniquely challenging projects.


What we’re expecting you to have

  • Bachelor's in Computer Science, Engineering or a related field
  • Professional experience of 8+ years in at least two security domains: web security (inclusive of APIs, backends, frontend and microservices), edge/perimeter security, mobile security, cloud security, systems security, or reverse engineering
  • 7+ years of industry experience in a software development environment with expert-level proficiency in programming languages like Java, Python, or C++
  • Demonstrable experience developing libraries and frameworks that are pre-vetted for security, which developers can use to avoid common vulnerabilities.
  • Hands-on experience incorporating security checks and tests into the CI/CD pipeline so that every code change is automatically reviewed for security issues before it is deployed.
  • Demonstrable experience in conducting code reviews to identify security deficiencies in how business logic is implemented.
  • Experience designing, implementing, and deploying production-quality security engineering systems and incorporating security standards into supporting subsystems as needed.
  • Hands-on experience with middleware, message queues, caches, and other related technologies.
  • Strong experience in architecture design, high-availability, high-performance, distributed systems and working with 5x9/ zero-downtime systems.
  • Demonstrable commitment to engineering and operational excellence–to include development + monitoring of SLOs/SLIs to assure adherence to EOE standards–with direct experience in driving security outcomes within an engineering culture.
  • A broad knowledge of attack vectors, exploits and mitigations that work at scale or may be linked together for chained attacks
  • Working familiarity with version control systems (Git), issue tracking tools (Jira) and ability to define + support your commitments within an Agile working model.
  • Ability to communicate ideas and proposals concisely to a wide-range of audiences
  • Ability to author both technical and non-technical documentation on a continuous cadence.
  • Ability to fully participate in our on-call rotation as a service owner


What does a strong candidate have?

  • Master’s (or Ph.D) in Computer Science, Engineering or a related field
  • A security industry-related certification such as Certified Information Systems Security Professional (CISSP) or Offensive Security Certified Professional (OSCP)
  • Knowledge of both iOS and Android architecture and development
  • Expert-level knowledge within identity and access management security domain, inclusive of role-based access controls, factors-based authentication and identity-based attack (both legacy and emergent) patterns.
  • Willingness to participate in incidents as needed as a security SME
  • Familiarity with industry-standard threat modeling, risk modeling and vulnerability classification.
  • Prior experience leading the design or reconstruction of complex systems, preferably in e-commerce or retail-related fields.
  • Deep understanding of the related theories of distributed systems, such as load balancing, distributed transactions, CAP/BASE, etc
  • (Bonus) Experience with hardware or embedded device security such as what you would find in a kiosk or a point-of-sale system


And Of Course, Perks

  • Flexible PTO. Grubhub employees enjoy a generous amount of time to recharge.
  • Health and Wellness. Excellent medical, dental and vision benefits, 401k matching, employee network groups and paid parental leave are just a few of our programs to support your overall well-being.
  • Compensation. You'll receive a highly-competitive compensation package with eligibility for generous incentives, bonuses, commission, and RSUs.
  • Free Meals. Our employees get a weekly Grubhub credit to enjoy and support local restaurants.
  • Social Impact. We believe in giving back through programs like the Grubhub Community Relief Fund, and provide our employees opportunities to support causes that are important to them.



  • Chicago, Illinois, United States SpotOn: Product Full time

    Job OverviewAt SpotOn, we empower restaurants and small enterprises to thrive through adaptable payment solutions and software technology, supported by dedicated professionals who genuinely care. Our tools, ranging from integrated restaurant management systems to seamless point-of-sale solutions, are crafted to enhance profitability and improve experiences...

  • Sales Engineer

    4 weeks ago


    Chicago, United States Keeper Security, Inc. Full time

    Job DescriptionJob DescriptionKeeper Security is hiring an experienced Sales Engineer to join our B2B sales team. This is a 100% remote position with an opportunity to work a hybrid schedule for candidates who live near our global headquarters in Chicago.Keeper’s cybersecurity software is trusted by millions of people and thousands of organizations,...

  • Sales Engineer

    1 month ago


    Chicago, United States Keeper Security, Inc. Full time

    Job DescriptionJob DescriptionKeeper Security is hiring an experienced Sales Engineer to join our B2B sales team. This is a 100% remote position with an opportunity to work a hybrid schedule for candidates who live near our global headquarters in Chicago.Keeper’s cybersecurity software is trusted by millions of people and thousands of organizations,...


  • Chicago, Illinois, United States TEKsystems Full time

    Description: Position Accountability / ScopeThis role reports to the Global Director, Information Security. Candidate is responsible for overseeing cross-functional activities that help product R&D teams build safe and secure medical devices & services that are compliant with industry regulation and meet customer and patient security/safety expectations....


  • Chicago, United States Kraft Heinz Full time

    Job DescriptionKraft Heinz is seeking a passionate and innovative Staff Product Architect to play a pivotal role in building cutting-edge digital products. You will be responsible for defining and shaping the technical foundation of our products, ensuring they align with business goals, user needs, and technical feasibility.What You'll Do: Craft...


  • Chicago, Illinois, United States Kraft Heinz Full time

    Job DescriptionKraft Heinz is seeking a passionate and innovative Staff Product Architect to play a pivotal role in building cutting-edge digital products. You will be responsible for defining and shaping the technical foundation of our products, ensuring they align with business goals, user needs, and technical feasibility.What You'll Do:Craft Product...

  • Security Engineer

    1 month ago


    Chicago, Illinois, United States Hudson River Trading Full time

    Hudson River Trading (HRT) is looking for a senior-level Security Engineer to join our growing Identity & Access Management (IAM) team. In this role, you'll have the opportunity to design identity, authentication, and access control solutions that strategically impact HRT's global cyber security systems.We are looking for someone with a strong knowledge of...

  • Sales Engineer

    5 days ago


    Chicago, Illinois, United States Keeper Security, Inc. Full time

    About the RoleWe are seeking an experienced Sales Engineer to join our team at Keeper Security, Inc. as an Enterprise Sales Engineer. This is a 100% remote position with an opportunity to work a hybrid schedule for candidates who live near our global headquarters.Keeper Security is a leading provider of cybersecurity software, trusted by millions of people...

  • IT Security Engineer

    1 month ago


    Chicago, United States eTek IT Services, Inc. Full time

    Job DescriptionJob DescriptionRole : Senior Security Engineer with EnterprisesLocation: Chicago ILExperience : 10+ yearsW2 Contract& Required SkillsExperience with security concepts and engineering security vulnerability mitigation solutions in both Windows end user compute and mobile environments. Broad infrastructure technology concepts around software,...

  • IT Security Engineer

    2 months ago


    Chicago, United States eTek IT Services, Inc. Full time

    Job DescriptionJob DescriptionRole : Senior Security Engineer with EnterprisesLocation: Chicago ILExperience : 10+ yearsW2 Contract& Required SkillsExperience with security concepts and engineering security vulnerability mitigation solutions in both Windows end user compute and mobile environments. Broad infrastructure technology concepts around software,...


  • Chicago, Illinois, United States SpotOn: Product Full time

    Job OverviewAt SpotOn, we empower restaurants and small enterprises to thrive through adaptable payment solutions and software technology, supported by dedicated professionals who genuinely care. Our comprehensive tools, from intuitive point-of-sale systems to integrated management solutions, are crafted to enhance profitability and improve experiences for...


  • Chicago, United States Grubhub Full time

    Grubhub’s Product Security organization is looking for a Penetration Tester to help build our Offensive Testing & Adversary Emulation capabilities. Your primary task will be to conduct offensive pen-testing activities against our microservices, applications, infrastructure and data-layer systems. You will work closely with our engineering groups to define...


  • Chicago, United States Grubhub Full time

    Grubhub’s Product Security organization is looking for a Penetration Tester to help build our Offensive Testing & Adversary Emulation capabilities. Your primary task will be to conduct offensive pen-testing activities against our microservices, applications, infrastructure and data-layer systems. You will work closely with our engineering groups to define...


  • Chicago, Illinois, United States SpotOn: Product Full time

    Job OverviewAt SpotOn, we empower restaurants and small enterprises to thrive through adaptable payment solutions and software technology, supported by dedicated professionals who genuinely care. Our offerings, from integrated point-of-sale systems to comprehensive restaurant management tools, are crafted to enhance profitability and improve experiences for...


  • Chicago, United States Premier Solutions Hi, LLC Full time

    Job DescriptionJob DescriptionSalary: Job Description:The Lead Cyber Security Engineer serves as the principal technical advisor and subject matter expert for system categorization, security controls, and ATO for approved cybersecurity tools. Leverages tools to build, harden, maintain, and instrument a comprehensive security orchestration platform for...

  • Special Events

    3 months ago


    Chicago, United States Halo Security Group Full time

    Job DescriptionJob DescriptionWe are seeking Special Events - Security Officer to become an integral part of our HALO security team. We looking to deploy individuals for the following event dates:July 4th - 7thAugust 2nd - 4thAugust 9th - 11thAugust 19th - 22ndLocation: Details will be discussed upon hire due to sensitive site information.Security staff are...


  • Chicago, Illinois, United States eTek IT Services, Inc. Full time

    Job DescriptionWe are seeking an experienced Senior Security Engineer to join our team at eTek IT Services, Inc. as a key member of our security team. The successful candidate will be responsible for detecting, remediating, and mitigating workstation and mobile security vulnerabilities, as well as conducting extensive testing and supporting of critical...


  • Chicago, United States Keeper Security Full time

    Keeper is hiring a talented System Support Engineer to join the Keeper family. This is a 100% remote position! Keepers cybersecurity software is trusted by millions of people and thousands of organizations, globally. Keeper is published in 21 languages and is sold in over 120 countries. Join one of the fastest growing Cybersecurity companies and gain...


  • Chicago, United States Venmo Full time

    At PayPal (NASDAQ: PYPL), we believe that every person has the right to participate fully in the global economy. Our mission is to democratize financial services to ensure that everyone, regardless of background or economic standing, has access to affordable, convenient, and secure products and services to take control of their financial lives. Job...


  • Chicago, United States OpenGov Full time

    OpenGov is home to an exceptional team - passionate about our mission to power more effective and accountable government. By bringing the OpenGov Cloud to our nation's state and local government, we're transforming communities so they can thrive! Imagine yourself being able to help small business owners open their doors faster, ensuring our tax dollars are...