College Board

Product Security Engineer IV

United States full-time Senior $140,000 - $151,000
full-time Senior level Technology & IT Salary listed Curated
Sign in to apply Free account — we bring you straight back to this role.

About the role

Product Security Engineer IV
College Board – Technology – Product Security
Location: 1) This is a fully remote role. Candidates who live near CB offices have the option of being fully remote or hybrid (Tuesday and Wednesday in office).
Type: This is a full-time position
 
About the Team 
The College Board Product Security team is a close-knit and enthusiastic group of technologists with a thirst for knowledge in security and cloud. We collaborate closely to investigate and solve problems and have strong alignment with our product teams to be a step ahead in securing the organization’s suite of products. We are an agile organization, embracing AI and cloud-native systems, and are focused on improving speed and security of service delivery in support of our important mission. Our team comes from a wide variety of backgrounds as well as experience within the security space and we work to ensure everyone on the team has a voice.
Product Security Engineers work closely with Product teams as well as other organizational stakeholder groups to achieve product and security business objectives. They support threat modelling, architecture design, and implementation of secure development practices. In addition, they help define organizational security standards and organizational capability and tooling adoption decisions.
  
About the Opportunity  
As a Product Security Engineer IV, you will work alongside other security engineers to support security across the development lifecycle for assigned College Board product teams. You will participate in threat modeling, vulnerability assessment, and design review—including for products that incorporate AI-powered features and use AI coding tools in development. You will build and apply your security knowledge on real work and document your findings clearly.
Day-to-day, you will conduct security code reviews, operate assigned security tooling, and support the remediation of identified vulnerabilities. You will also contribute to the Product Security Partners program, helping product engineers understand and apply secure development practices.
This is hands-on product security work with real stakes—your contributions help protect platforms that serve millions of students and educators worldwide.
In this role, you will:
Support Product Team Partnerships (55%)
Participate in planning, grooming, and design sessions for assigned product teams; contribute to security discussions.
Contribute to threat models and risk registers for assigned products; document findings clearly and escalate issues to leadership as needed.
Conduct vulnerability assessments on assigned products; apply exploitability frameworks to support accurate risk prioritization.
Apply CB's security policies, audit requirements (SOC 2, ISO 27002, PCI, PII), and GRC standards—with guidance—to support compliance activities.
Review code and security design documentation; identify security issues and contribute feedback in design reviews.
Support remediation of security gaps in assigned products; track and report progress against Product Security Framework requirements.
Support the Product Security Program (20%)
Participate in security training sessions; help product engineers apply secure coding practices, including responsible use of AI coding tools.
Support the Product Security Partners program by contributing to security champion activities in assigned product teams.
Document security learnings and patterns; contribute to the team's shared knowledge base.
Invest in developing your security expertise: learn from industry advancement, attend team learning events, apply new skills in your daily work, and contribute to Hackathons.
Contribute to Operational Improvement (25%)
Operate and monitor assigned security tooling across cloud environments; support the integration of security controls into CI/CD pipelines.
Contribute to security metrics tracking and reporting; collect and organize data that measures partner team security posture.
Participate in agile ceremonies; manage assigned stories and tasks with clear documentation and timely delivery.
Serve as on-call first responder for security tooling your team owns; support the Information Security team on incident response.
About you, you have
4+ years of experience in product security, application security, cloud security, or software engineering with security responsibilities.
Deep application security knowledge, including common vulnerability classes (OWASP Top 10), secure coding practices, and security testing.
Solid experience with securing AWS Services, AWS Secure Architectures, Application Security and Cloud Applications, including Software Supply Chain and micro service architecture
Familiarity with cloud environments (AWS preferred) and CI/CD pipelines; developing knowledge of how security controls integrate into software delivery.
Familiarity with audit and compliance frameworks such as SOC 2, ISO 27002, PCI, and PII, and the ability to apply them with guidance to product teams.
Experience reading and reviewing code; proficiency or active development of skills in JavaScript/TypeScript or Python is a plus.
Clear, concise written and verbal communication; the ability to document findings and explain security concepts to technical peers.
A growth mindset: you seek feedback, apply it, and invest actively in developing your security expertise.
Ability to travel 2-3 times per year to College Board offices in New York or Reston, VA.
All roles at College Board require:
A passion for expanding educational and career opportunities and mission-driven work
Curiosity and enthusiasm for emerging technologies, with a willingness to experiment with and adopt new AI-driven solutions and comfort with learning and applying new digital tools independently and proactively.
Clear and concise communication skills, written and verbal
A learner's mindset and a commitment to growth: welcoming diverse perspectives, giving and receiving timely, respectful feedback, and continuously improving through iterative learning and user input.
A drive for impact and excellence: solving complex problems, making data-informed decisions, prioritizing what matters most, and continuously improving through learning, user input, and external benchmarking.
A collaborative and empathetic approach: working across differences, fostering trust, and contributing to a culture of shared success
Authorization to work in the United States
About Our Process
Application review will begin immediately and will continue until the position is filled. This role is expected to accept applications for a minimum of 5 business days.
While the hiring process may vary, it generally includes: resume and application submission, recruiter phone/video screen, hiring manager interview, performance exercise such as live coding, a panel interview, a conversation with leadership and reference checks.
What We Offer
At College Board, we offer more than a paycheck: we provide a meaningful career, a supportive team, and a comprehensive package designed to help you thrive. We’re a self-sustaining nonprofit that believes in fair and competitive compensation grounded in your qualifications, experience, impact, and the market.

A Thoughtful Approach to Compensation
The hiring range for this role is $140,000 to $151,000.
Your exact salary will depend on your location, experience, and how your background compares to others in similar roles at the College Board.
We aim to make our best offer upfront, rooted in fairness, transparency, and market data.
We adjust salaries by location to ensure fairness, no matter where you live.

You’ll have open, transparent conversations about compensation, benefits, and what it’s like to work at College Board throughout your hiring process. Check out our careers page for more.

Originally posted on Himalayas

Interview prep

Walk in with sharper answers.

Use this as a quick practice sheet before you speak with the employer.

Senior
Technology & IT API integration Business Development Data Analysis Javascript Project Management Senior level

Likely questions

  1. Tell us about work you have done that is close to the Product Security Engineer IV role.
  2. How would you approach your first 30 days at College Board?
  3. Which of API integration, Business Development and Data Analysis have you used recently, and what did it help you achieve?
  4. How have you led people, improved a process, or made a hard decision in a previous role?
  5. How do you handle busy days, changing priorities, or pressure at work?

Prepare before the call

  • A recent example that proves your experience with API integration, Business Development and Data Analysis.
  • One short story with a problem, your action, and the result.
  • Two examples that show the strengths listed on your CV.
  • A clear reason why this role and company interest you.
  • Your availability, preferred work style, and salary expectations.

Ask them

  • What would success look like in the first 90 days?
  • What are the main problems this hire should help solve?
  • How does the team give feedback and measure good work?
  • What does a normal working week look like for this role?
Practice line

I am interested in the Product Security Engineer IV role because I can bring practical experience in API integration, Business Development and Data Analysis, learn the team quickly, and contribute to the outcomes College Board needs from this hire.

Related jobs.

More roles from this company or category.