Senior Product Security Engineer



Software Engineering, Product
Canada · Ontario, Canada · Remote
Posted on Saturday, April 13, 2024

We're transforming the grocery industry

At Instacart, we invite the world to share love through food because we believe everyone should have access to the food they love and more time to enjoy it together. Where others see a simple need for grocery delivery, we see exciting complexity and endless opportunity to serve the varied needs of our community. We work to deliver an essential service that customers rely on to get their groceries and household goods, while also offering safe and flexible earnings opportunities to Instacart Personal Shoppers.

Instacart has become a lifeline for millions of people, and we’re building the team to help push our shopping cart forward. If you’re ready to do the best work of your life, come join our table.

Instacart is a Flex First team

There’s no one-size fits all approach to how we do our best work. Our employees have the flexibility to choose where they do their best work—whether it’s from home, an office, or your favorite coffee shop—while staying connected and building community through regular in-person events. Learn more about our flexible approach to where we work.


We're looking for experienced Security Engineers to join our fast moving security team. We work on a range of interesting and challenging problems, from supporting thousands of concurrent shoppers and processing millions of data points in real time, to developing and enhancing internal tools, addressing vulnerabilities and managing secrets.

Our goal is to run the world's most trusted and secure delivery platform. We work across all layers of our infrastructure to ensure we deploy trustworthy systems and protect our customers’, shoppers’, and partners’ data.

About the Team

You will be a key member of the Security Engineering team that is responsible for developing security-focused features and frameworks for Instacart in both production and infrastructure space. Ideally a hybrid builder/breaker, you will have an opportunity to lead high impactful projects across the platform and assist in defining the internal team processes. You will be directly influencing the security posture of many products and systems across the company.

About the Job

  • Design, implement and ship high-quality security features for the product and internal tools across Instacart with a strong sense of urgency and accountability such as:
    • Secrets & Vulnerability management
    • IAM and Zero Trust
    • Platform abuse prevention & mitigation
    • Data analytics hardening
  • Work closely with product managers, designers, data scientists, and peer engineering teams to define project requirements and execution plans.
  • Identify unaddressed areas of security weakness and help the teams come up with efficient and scalable solutions.
  • Provide software engineering resource for sister teams in the areas of infrastructure hardening, detection, and response
  • Participate in the team’s on-call by handling and running security incidents

About You


  • 5+ years of experience in Security Engineering or related role
  • Strong knowledge of common back-end web technologies (such as Ruby on Rails, Python, Golang, SQL, etc.) in a large scale distributed system environment
  • Experience with threat modeling, security assessments, product security concepts, and security architecture reviews
  • An ability to make data-driven decisions & prioritize initiatives that improve key security metrics
  • An ability to balance a sense of urgency with shipping high-quality and pragmatic solutions.
  • Strong self-management and organizational skills
  • Experience developing tools and automation using common devops toolsets and programming languages


  • Bachelor’s degree in Computer Science, Engineering, Math or related work experience
  • In depth knowledge on the best remediation techniques for different application vulnerabilities and the ability to explain them to product teams
  • An ability to create written work products and detailed technical documents to work effectively with cross functional teams and drive alignment on security objectives and plans.
  • Breaker experience, such as web/application penetration testing
  • Experience working with highly ephemeral environments
  • A security-related or architecture-related certification such as CISSP, OSCP, CEH