Product Security Engineering Director

Envestnet

  • ALL USA
  • 2 days ago
  • Remote
  • $184,200–$224,200 Per Year
  • Full-time

Highlights

Identify and address cross-product security risks by driving reusable security patterns, reference architectures, and strategic security improvements, while influencing product roadmaps, architecture decisions, and technology strategy through security-focused design guidance and risk assessments. What makes this team especially exciting is its forward-looking focus on securing next-generation technologies, including AI and LLM-based solutions, while influencing key product decisions that strengthen the security and trustworthiness of the platforms our clients rely on every day.

Numbers & Facts

LocationALL USA (
Remote
)
Job TypeFull-time
Salary$184,200–$224,200 Per Year

Description

Description

The application window will close August 5, 2026.
 
Job Location   
 
The primary work location for this role is East Coast with a remote work model.   
  
About Envestnet  
Envestnet is an adaptive WealthTech company that is redefining the future of wealth management by helping advisors meet the moment with its comprehensive technology, actionable insights, and industry leading support. Backed byover 25 years of experience and approximately $7.0 trillion in platform assets, Envestnet is trusted by over one third of financial advisors across leading banks, wealth managers, brokerages, and RIAs.   
   
For a deeper look at how Envestnet is shaping the future of financial advice, visit www.envestnet.com.   
   
The Team You’ll Join  
The Product Security Engineering team plays a critical role in embedding security into Envestnet’s products and platforms from the very beginning of the development lifecycle. Working closely with product managers, architects, engineers, and cybersecurity teams, they help design secure, resilient solutions through architecture reviews, threat modeling, and security-by-design practices. The team supports modern applications, APIs, distributed systems, and emerging AI-powered capabilities, helping identify risks early and guide secure innovation. What makes this team especially exciting is its forward-looking focus on securing next-generation technologies, including AI and LLM-based solutions, while influencing key product decisions that strengthen the security and trustworthiness of the platforms our clients rely on every day.
 
How You’ll Contribute   

Responsible for embedding strong security practices into the design, development and operation of Envestnet financial technology platforms. Partners with product management, software engineering, architecture and infrastructure teams to identify and mitigate security risks early in the product lifecycle. Defines secure design standards, performs threat modeling and security reviews and helps teams remediate vulnerabilities in applications, APIs and cloud services.

•    Acts as a technical expert in product and application security, supporting multiple product lines or platforms. 
•    Leads threat modeling, secure design reviews and architecture assessments for complex applications, APIs and cloud-native services. 
•    Partners with engineering and product teams to identify security risks early and recommend practical, scalable mitigations.  
•    Define secure development requirements, architecture standards, and security review criteria aligned with the Secure Development Lifecycle (SDLC). 
•    Performs and oversees application security testing, vulnerability analysis and remediation validation. 
•    Helps prioritize security findings based on risk, business impact and regulatory requirements. 
•    Review significant security incidents to identify architectural weaknesses, systemic control gaps, and long-term remediation opportunities. 
•    Defines and promotes secure-by-design patterns for modern applications, APIs, distributed systems, and AI-enabled solutions, including LLM-based capabilities. 
•    Mentors product security engineers through technical guidance and reviews. 
•    Participates in audits, assessments and compliance activities by providing detailed technical input and documentation. 
•    Establishes product security requirements related to encryption, identity, authentication, authorization, secrets management, and secure configuration, while ensuring alignment with industry standards and regulatory requirements. 
•    Assess and govern the security of Generative and Agentic AI architectures, including LLMs, RAG, AI agents, MCP integrations, orchestration frameworks, and third-party AI services through architecture reviews and threat modeling. 
•    Define AI security standards, guardrails, and secure-by-design patterns, and provide strategic guidance for secure adoption of AI-enabled products and AI-assisted development capabilities. 
•    Identify and address cross-product security risks by driving reusable security patterns, reference architectures, and strategic security improvements, while influencing product roadmaps, architecture decisions, and technology strategy through security-focused design guidance and risk assessments. 

What You’ll Need to Bring  

•    Candidates should demonstrate the relevant experience, skills, and capabilities needed to successfully perform in the role. Relevant experience may be gained through current responsibilities, prior roles, project work, leadership opportunities, or other comparable experiences.
•    Bachelor’s/Master’s in Computer Science, Cybersecurity, or related field.
•    Strong experience in product or application security architecture, with a focus on design‑level security preferably in a financial services industry.
•    Hands‑on experience with threat modeling, security architecture reviews, and secure system design including AI-enabled systems.
•    Solid understanding of modern application architectures, including microservices, APIs, and cloud‑native platforms.
•    Working knowledge of AI/LLM concepts, including model integration patterns, RAG architectures, and agentic workflows.
•    Knowledge of identity and access management, encryption standards, and secure integration patterns.

Nice-to-Have
  • Familiarity with industry frameworks such as OWASP, NIST, and security requirements for regulated environments including emerging AI governance practices.
  • Certifications (optional): CISSP, CSSLP, CCSP.
  • Strong communication skills to influence design decisions without direct ownership of delivery teams.
  • Ability to translate security risks into clear architectural guidance for product and engineering teams. 
Why You’ll Enjoy Working at Envestnet  
Help shape the future of WealthTech. At Envestnet you’ll gain hands-on experience and collaborate with some of the industry’s brightest minds to deliver meaningful, innovative solutions that make a real difference. 
 
We value flexibility in how and where work gets done, and we recognize strong performance with meaningful rewards—because your contributions should drive both business success and your own personal growth. If you’re looking for a place where your work has impact, your development is supported, and your contributions are truly valued, Envestnet is where you can build your future.  
 
The opportunity is now!  
  
Sponsorship  
This position is not open to candidates requiring visa sponsorship  
  
Our Investment in You 
This role offers a base salary range of $184,200.00 to $224,200. The range listed represents a good-faith estimate of base salary compensation for this position and does not include incentive compensation, equity or benefits. Individual pay will be determined based on factors including, but not limited to, relevant experience, skills, education, certifications, and geographic location, in accordance with applicable pay transparency laws.  This role is eligible for an additional incentive component as part of the total rewards package.   
 
We provide a comprehensive suite of benefits - subject to Envestnet’s plan eligibility rules - that support your overall well-being including, medical insurance, paid time off (PTO), 401k company match, paid parental leave, education reimbursement, disability coverage and mental health & wellness support. Our investment in you means supporting you professionally, financially, and personally at every stage of your journey with us.  Please visit our benefits page on our career site to learn more.  
  
Our Commitment to Inclusion & Belonging  
Envestnet is an Equal Opportunity Employer and is committed to creating an inclusive environment for all employees and applicants. We welcome and value individuals of all backgrounds and do not discriminate based on race, color, religion, creed, sex (including pregnancy or related medical conditions), gender identity or expression, sexual orientation, national origin, ancestry, age, disability, genetic information, military or veteran status, citizenship status, or any other status protected by applicable law. We encourage individuals from all backgrounds to apply.  
 
We strive to provide an inclusive application and interview process. If you are a candidate with a disability and require reasonable accommodation, please contact us at  careers@envestnet.com. Please include your full name, the title of the role you are applying for, and the accommodation necessary to assist you with the recruiting process.
 
Recruitment Fraud 
At Envestnet, safeguarding the trust and safety of job seekers is a top priority. We are aware that scammers may impersonate Envestnet recruiters or create fake job opportunities to deceive candidates. Review the information on our recruitment fraud awareness page to help you recognize and avoid recruitment fraud. 
#LI-AA1 #LI-REMOTE

Similar Jobs

See more jobs