Talent.com
Sr. Staff Product Security Engineer (Hybrid - Pleasanton, CA)

Sr. Staff Product Security Engineer (Hybrid - Pleasanton, CA)

Blackhawk NetworkPleasanton, CA, United States
20 hours ago
Job type
  • Full-time
Job description

About Blackhawk Network

Today, through BHN’s single global platform, businesses of all kinds can tap into the world’s largest network of branded payment solutions. BHN helps businesses grow revenue, increase loyalty, motivate and reward their teams, disburse funds and engage consumers. Branded payment solutions include the issuance and distribution of gift cards, egifts, corporate payouts and rewards, along with the technology to deliver these products in seamless, integrated ways. BHN’s network spans the globe with more than 400,000 consumer touchpoints. Learn more at BHN.com.

Overview

We’re hiring a Senior Penetration Tester to help defend our fintech platform against large-scale payment fraud, carding attacks, and other financially motivated threats. You’ll lead offensive security assessments targeting our transaction systems, authentication flows, and APIs — with a heavy focus on automation and scalability. Your work will directly impact our fraud defenses, detection strategy, and customer trust.

This is a highly technical, hands-on role for someone who thrives in a fast-paced, high-stakes fintech environment.

This position will be Hybrid (Tuesdays & Wednesdays) out of our Pleasanton, CA office.

Responsibilities

  • Lead penetration testing engagements focused on payment abuse, transaction manipulation, and business logic exploitation.
  • Design and execute automated attack simulations to test our defenses against :
  • Carding and BIN attacks
  • Credential stuffing and account takeovers
  • Checkout and payment flow abuse
  • API-level enumeration and fraud
  • Build custom tooling and frameworks to mimic the behavior of real-world fraudsters and cybercriminals.
  • Partner with fraud engineering, product security, and risk teams to identify weak points in our controls, detection systems, and architecture.
  • Conduct threat modeling and red teaming exercises related to payments, authentication, and user account abuse.
  • Document findings in technical reports with clear risk impact, exploitability, and remediation guidance.
  • Mentor junior testers and contribute to a culture of security innovation and continuous improvement.

Qualifications

  • 7+ years of experience in offensive security, penetration testing, or red teaming.
  • Strong background in payment systems, financial fraud tactics, and transaction-level attack surfaces.
  • Fluency in scripting and automation (e.g., Python, JavaScript, Go, Bash) to simulate attacker workflows at scale.
  • Familiarity with tools like Burp Suite Pro, Selenium, Scapy, ffuf, SQLMap, Metasploit, and bot automation frameworks.
  • In-depth knowledge of fintech technologies (e.g., tokenized payments, card vaulting, 3DS, ACH, real-time payment APIs).
  • Solid grasp of common attacker techniques : carding, fake identity generation, bypassing rate limits, evading fraud filters, and abusing web / app logic.
  • Strong communication skills for explaining findings to both technical and non-technical audiences.
  • Certifications : OSCP, OSEP, GWAPT, GPEN, GCPN, GXPN, GX-PT, CPSA / CRSA by CREST, CHECK, or TIGER.
  • Prior experience in a fintech, digital banking, or payment gateway environment.
  • Familiarity with OWASP Automated Threats, PCI DSS, MITRE ATT&CK for Financial Services, or fraud detection systems.
  • Experience building or testing real-time risk scoring engines and fraud defense pipelines.
  • Benefits

    Salary Range for California Residents Only : $157,030.00 - $212,000.00

    Pay is based on several factors including but not limited to education, work experience, certifications, etc. In addition to your salary, Blackhawk Network offers benefits including 401k with employer match, medical, dental, vision, 12 paid holidays in the year 2025, 1 hour of sick pay accrual for every 30 hours worked, parental leave, life insurance, disability insurance, accident and illness insurance, health and dependent care flexible spending accounts, wellness benefits, and flexible time off for all full-time employees.

    EEO Statement

    Blackhawk Network provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws.  Blackhawk Network believes that diversity leads to strength. This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation, and training.

    Blackhawk Network encourages applicants with previous criminal records to apply to all positions and, pursuant to the San Francisco and Los Angeles Fair Chance Acts (and other “Fair Chance” laws), Blackhawk Network will consider for employment qualified applicants with arrest and conviction records. For Philadelphia applicants or jobs, please see a copy of Philadelphia’s ordinance on this topic by clicking this link :

    Create a job alert for this search

    Staff Security Engineer • Pleasanton, CA, United States

    Related jobs
    • Promoted
    Staff Product Security Engineer

    Staff Product Security Engineer

    RipplingSan Francisco, CA, United States
    Full-time
    Rippling gives businesses one place to run HR, IT, and Finance.It brings together all of the workforce systems that are normally scattered across a company, like payroll, expenses, benefits, and co...Show moreLast updated: 30+ days ago
    • Promoted
    • New!
    Product Security Engineer

    Product Security Engineer

    AirtableSan Francisco, CA, United States
    Full-time
    Airtable is the no-code app platform that empowers people closest to the work to accelerate their most critical business processes. More than 500,000 organizations, including 80% of the Fortune 100,...Show moreLast updated: 20 hours ago
    • Promoted
    • New!
    Product Security Engineer

    Product Security Engineer

    CHYMSan Francisco, CA, United States
    Full-time
    We are looking for an early-career Security Engineer to join our Product Security team, someone who has a builder's mindset, is eager to learn, and is excited to contribute to both planned initiati...Show moreLast updated: 20 hours ago
    • Promoted
    • New!
    Senior Product Security Engineer, Secure Design

    Senior Product Security Engineer, Secure Design

    DigitalOceanSan Francisco, CA, United States
    Full-time
    Senior Product Security Engineer, Secure Design.Were looking for a Senior Product Security Engineer who is passionate about partnering with engineers to assess the security risk of new products and...Show moreLast updated: 20 hours ago
    • Promoted
    Staff Product Manager, Agentic Offensive Security

    Staff Product Manager, Agentic Offensive Security

    hackeroneSan Francisco, CA, United States
    Full-time
    HackerOne is a global leader in Continuous Threat Exposure Management (CTEM).The HackerOne Platform unites agentic AI solutions with the ingenuity of the world's largest community of security resea...Show moreLast updated: 14 days ago
    • Promoted
    Senior Product Security Engineer

    Senior Product Security Engineer

    CrusoeSan Francisco, CA, United States
    Full-time
    Senior Product Security Engineer.Crusoe is building the World's Favorite AI-first Cloud infrastructure company.We're pioneering vertically integrated, purpose-built AI infrastructure solutions trus...Show moreLast updated: 30+ days ago
    • Promoted
    • New!
    Sr. Security Engineer - GTM Partnership

    Sr. Security Engineer - GTM Partnership

    ZapierSan Francisco, CA, United States
    Full-time
    Were humans who simply think computers should do more work.At Zapier, were not just making softwarewere building a platform to help millions of businesses globally scale with automation and AI.Our ...Show moreLast updated: 20 hours ago
    • Promoted
    • New!
    Senior Product Security Engineer

    Senior Product Security Engineer

    Tools for HumanitySan Francisco, CA, United States
    Full-time
    World is a network of real humans, built on privacy-preserving proof-of-human technology, and powered by a globally inclusive financial network that enables the free flow of digital assets for all....Show moreLast updated: 20 hours ago
    • Promoted
    • New!
    Product Security Engineer

    Product Security Engineer

    Cascading AI IncSan Francisco, CA, United States
    Full-time
    Casca is building AGI for banking.We're replacing decades-old legacy systems with AI-native technology that automates 90% of the manual work humans once had to do. We're seeking a Product Security E...Show moreLast updated: 20 hours ago
    • Promoted
    Senior Security Engineer, Product

    Senior Security Engineer, Product

    DecagonSan Francisco, CA, United States
    Full-time
    Decagon is the leading conversational AI platform empowering every brand to deliver concierge customer experience.Our AI agents provide intelligent, human-like responses across chat, email, and voi...Show moreLast updated: 30+ days ago
    • Promoted
    Product Security Engineer

    Product Security Engineer

    Databricks Inc.San Francisco, CA, United States
    Full-time
    RDQ326R24 - This role can be based remotely anywhere in the United States.The Product Security Team's mission is to Left-shift SDLC (Security Development Lifecycle) processes for ALL code written i...Show moreLast updated: 30+ days ago
    • Promoted
    Sr. Staff Engineer

    Sr. Staff Engineer

    Bio-Rad LaboratoriesPleasanton, CA, United States
    Full-time
    You'll drive the development of hardware products that directly impact healthcare innovation and improve lives worldwide. You'll collaborate cross-functionally to.Your expertise in electrical engine...Show moreLast updated: 30+ days ago
    • Promoted
    • New!
    Staff+ Product Security Engineer

    Staff+ Product Security Engineer

    VerkadaSan Mateo, CA, United States
    Full-time
    Designed with simplicity in mind, Verkada's six product lines - video security cameras, access control, environmental sensors, alarms, workplace, and intercoms - provide unparalleled building secur...Show moreLast updated: 20 hours ago
    • Promoted
    • New!
    Senior Product Security Engineer

    Senior Product Security Engineer

    LMArenaSan Francisco, CA, United States
    Full-time
    Senior Product Security Engineer.You'll work across product, infrastructure, and data pipelines to proactively identify risks, embed security into core features, and build scalable defenses against...Show moreLast updated: 20 hours ago
    • Promoted
    Product Security Engineer

    Product Security Engineer

    CascaSan Francisco, CA, United States
    Full-time
    Casca is building AGI for banking.We’re replacing decades-old legacy systems with AI-native technology that automates 90% of the manual work humans once had to do. We're seeking a Product Security E...Show moreLast updated: 30+ days ago
    • Promoted
    Sr. Full Stack Software Engineer, Security (Starlink)

    Sr. Full Stack Software Engineer, Security (Starlink)

    SpaceXSunnyvale, CA, United States
    Permanent
    Full Stack Software Engineer, Security (Starlink).SpaceX was founded under the belief that a future where humanity is out exploring the stars is fundamentally more exciting than one where we are no...Show moreLast updated: 30+ days ago
    • Promoted
    Sr Staff Engineer Software (L7 Security)

    Sr Staff Engineer Software (L7 Security)

    Jobs via DiceSanta Clara, CA, United States
    Full-time
    Sr Staff Engineer Software (L7 Security) Palo Alto Networks.Innovate, design, develop and improve the Next-Generation Firewall in terms of functionality and performance, working on device identity ...Show moreLast updated: 4 days ago
    • Promoted
    • New!
    Security Engineer - Product SecurityNew

    Security Engineer - Product SecurityNew

    FigureSan Jose, CA, United States
    Full-time
    Figure is an AI Robotics company developing a general purpose humanoid.Our humanoid robot, Figure 02, is designed for commercial tasks and the home. We are based in San Jose, CA and require 5 days / w...Show moreLast updated: 20 hours ago