Find Jobs
Find Jobs Near You – Available Work in Your Location
Skip to job details
E
Envestnet
Product Security Engineering Director
Career Insights for Cyber Security Engineer
See where this job fits in the broader career landscape. Knowing your career path helps you see what's possible from here.
Scorecard
Based on national data
Review key factors to help you decide if this role fits your goals. How is this calculated?
What they do
A Cyber Security Engineer designs systems that protect the security of large databases, including databases with customer information and patient files. Examines client computer systems, identifies weak points in security, develops and implements new systems, monitors and responds to security issues.
$108,221 / year median in the U.S.
-0% projected decline
Job Description
Description The application window will close August 5, 2026. Job Location The primary work location for this role is East Coast with a remote work model. About Envestnet Envestnet is an adaptive WealthTech company that is redefining the future of wealth management by helping advisors meet the moment with its comprehensive technology, actionable insights, and industry leading support. Backed by over 25 years of experience and approximately $7.0 trillion in platform assets, Envestnet is trusted by over one third of financial advisors across leading banks, wealth managers, brokerages, and RIAs. For a deeper look at how Envestnet is shaping the future of financial advice, visit www.envestnet.com . The Team You'll Join The Product Security Engineering team plays a critical role in embedding security into Envestnet's products and platforms from the very beginning of the development lifecycle. Working closely with product managers, architects, engineers, and cybersecurity teams, they help design secure, resilient solutions through architecture reviews, threat modeling, and security-by-design practices. The team supports modern applications, APIs, distributed systems, and emerging AI-powered capabilities, helping identify risks early and guide secure innovation. What makes this team especially exciting is its forward-looking focus on securing next-generation technologies, including AI and LLM-based solutions, while influencing key product decisions that strengthen the security and trustworthiness of the platforms our clients rely on every day. How You'll Contribute Responsible for embedding strong security practices into the design, development and operation of Envestnet financial technology platforms. Partners with product management, software engineering, architecture and infrastructure teams to identify and mitigate security risks early in the product lifecycle. Defines secure design standards, performs threat modeling and security reviews and helps teams remediate vulnerabilities in applications, APIs and cloud services.
- Acts as a technical expert in product and application security, supporting multiple product lines or platforms.
- Leads threat modeling, secure design reviews and architecture assessments for complex applications, APIs and cloud-native services.
- Partners with engineering and product teams to identify security risks early and recommend practical, scalable mitigations.
- Define secure development requirements, architecture standards, and security review criteria aligned with the Secure Development Lifecycle (SDLC).
- Performs and oversees application security testing, vulnerability analysis and remediation validation.
- Helps prioritize security findings based on risk, business impact and regulatory requirements.
- Review significant security incidents to identify architectural weaknesses, systemic control gaps, and long-term remediation opportunities.
- Defines and promotes secure-by-design patterns for modern applications, APIs, distributed systems, and AI-enabled solutions, including LLM-based capabilities.
- Mentors product security engineers through technical guidance and reviews.
- Participates in audits, assessments and compliance activities by providing detailed technical input and documentation.
- Establishes product security requirements related to encryption, identity, authentication, authorization, secrets management, and secure configuration, while ensuring alignment with industry standards and regulatory requirements.
- Assess and govern the security of Generative and Agentic AI architectures, including LLMs, RAG, AI agents, MCP integrations, orchestration frameworks, and third-party AI services through architecture reviews and threat modeling.
- Define AI security standards, guardrails, and secure-by-design patterns, and provide strategic guidance for secure adoption of AI-enabled products and AI-assisted development capabilities.
- Identify and address cross-product security risks by driving reusable security patterns, reference architectures, and strategic security improvements, while influencing product roadmaps, architecture decisions, and technology strategy through security-focused design guidance and risk assessments. What You'll Need to Bring
- Candidates should demonstrate the relevant experience, skills, and capabilities needed to successfully perform in the role. Relevant experience may be gained through current responsibilities, prior roles, project work, leadership opportunities, or other comparable experiences.
- Bachelor's/Master's in Computer Science, Cybersecurity, or related field.
- Strong experience in product or application security architecture, with a focus on design‑level security preferably in a financial services industry.
- Hands‑on experience with threat modeling, security architecture reviews, and secure system design including AI-enabled systems.
- Solid understanding of modern application architectures, including microservices, APIs, and cloud‑native platforms.
- Working knowledge of AI/LLM concepts, including model integration patterns, RAG architectures, and agentic workflows.
- Knowledge of identity and access management, encryption standards, and secure integration patterns.