GoodLeap logo

Lead Product Security Engineer

🔍 Found ClimateTechList useful?

ClimateTechList is free for job seekers, no registration required, and I, Steven, run it by myself at cost part-time.

The site gets about 30,000-40,000 users a month. Help support this site and make it easier for other future climate job seekers!

You can buy me a coffee to support the site below. Thanks!

Job Description

About GoodLeap:

GoodLeap is a technology company delivering best-in-class financing and software products for sustainable solutions, from solar panels and batteries to energy-efficient HVAC, heat pumps, roofing, windows, and more. Over 1 million homeowners have benefited from our simple, fast, and frictionless technology that makes the adoption of these products more affordable, accessible, and easier to understand. Thousands of professionals deploying home efficiency and solar solutions rely on GoodLeap’s proprietary, AI-powered applications and developer tools to drive more transparent customer communication, deeper business intelligence, and streamlined payment and operations. Our platform has led to more than $27 billion in financing for sustainable solutions since 2018.

GoodLeap is also proud to support our award-winning nonprofit, GivePower, which is building and deploying life-saving water and clean electricity systems, changing the lives of more than 1.6 million people across Africa, Asia, and South America.


Position Summary

The GoodLeap security team is responsible for both business enablement and safeguarding the organization’s information assets; it is involved in virtually all aspects of the business, from product safety and resilience, to building security paved roads, customer, partner, and regulatory trust, managing technology governance and compliance, and ensuring the privacy, and safety of GoodLeap’s customer, partner, and employee information.


The product and application lead engineer role provides a unique opportunity to shape the security and resilience of GoodLeap products, services, and applications. In this role, you will work closely with the product, engineering, and business teams within GoodLeap's business units, acting as the key individual with both the authority and responsibility to ensure the safety and resilience of the products and services developed and operated by the business unit.


You will be embedded within the business unit and have a dotted-line reporting relationship to the product or business lead for the unit. Your oversight will encompass:


Product features: Identifying potential misuse and abuse cases, proposing features to address these scenarios, and defining product features to meet resilience requirements.

Build-time controls: Managing application security controls and activities during development.

Runtime controls: Overseeing security measures for deployed products.

Additionally, you will represent all areas of security for the business unit(s) you are embedded in, spanning governance, risk, and compliance (GRC) to security monitoring. You will also have the authority to involve other security team members as needed.


While you will take on multiple responsibilities—from advisor to builder and beyond—your primary focus will be designing and building product security services and processes, creating product and application security patterns and practices, and fostering strong relationships with product, business, and engineering teams.

ClimateTechList.com logo

GoodLeap number of job openings over time by month

ClimateTechList is the web's largest aggregator of climate, clean tech, renewable energy & green jobs. Contact us if you'd like to use partner or use our current or historical jobs data in any way.

Apply to Job

👉 Please mention that you found the job on ClimateTechList, this helps us get more climate tech companies listed here, thanks!

Get a referral to GoodLeap

If possible, try to get a warm intro/referral to GoodLeap before applying! Do a LinkedIn search to see who you may know at the company. See this LinkedIn post from Steven for more details on this tactic.

All job openings from GoodLeap

Join ClimateTechList Talent Collective

Want to be matched with companies directly? Apply to the talent collective.

Here's how it works:

  1. You submit an application

  2. We'll share your profile with climate tech companies potentially interested in chatting with you

  3. We'll reach out if there's a company interested in talking to you.

Join ClimateTechList Talent Collective

Want to be matched with companies directly? Apply to the talent collective.

Here's how it works:

  1. You submit an application

  2. We'll share your profile with climate tech companies potentially interested in chatting with you

  3. We'll reach out if there's a company interested in talking to you.