Stubhubinc
OpenSoftware Engineer II - Product Security
- Location
- Los Angeles, California, United States
- Posted
- Jul 15, 2026
- Last seen
- Aug 7, 2026
About the role
StubHub is on a mission to redefine the live event experience on a global scale. Whether someone is looking to attend their first event or their hundredth, we’re here to delight them all the way from the moment they start looking for a ticket until they step through the gate. The same goes for our sellers. From fans selling a single ticket to the promoters of a worldwide stadium tour, we want StubHub to be the safest, most convenient way to offer a ticket to the millions of fans who browse our platform around the world.
StubHub's Product Security Engineering Team is seeking a Software Engineer II to enhance our security posture within the end user and services product domain. The perfect candidate will possess experience in CI/CD pipeline security, product and application architecture reviews, contextualized vulnerability management processes, and automation.
Location: Hybrid (3 days in office/2 days remote) – New York, NY or Century City, CA
About the team:
StubHub’s Product Security Engineering Team plays a critical role in securing the platforms that power the world’s largest ticket marketplace. This team works hands-on with cutting-edge tools and cloud-native technologies to embed security into every layer of the software development lifecycle—from architecture to automation. If you're passionate about offensive security, CI/CD hardening, and driving real impact across modern product teams, this is your opportunity to lead and innovate at global scale.
What You’ll Do:
- Conduct security assessments, code reviews, and penetration tests on web applications, APIs, and mobile apps to identify vulnerabilities and flaws.
- Collaborate with development teams to embed security into CI/CD pipelines, including the implementation of automated code scanning tools.
- Develop and maintain secure coding guidelines and conduct security awareness training for developers.
- Respond to security incidents, perform root cause analyses, and recommend effective remediations.
- Stay current on emerging security threats, vulnerabilities, and mitigation strategies; proactively share insights across teams.
- Help develop and enforce application security policies, standards, and procedures aligned with industry regulations and best practices.
- Conduct architectural reviews to ensure the security of new technologies and controls.
- Build and maintain robust product vulnerability management processes and procedures.
- Write and maintain production-grade APIs to automate security processes and streamline infrastructure and developer workflows. <span data-ccp-props="{"134233117&am
