AppSec Jobs
← Back to all jobs

GitHub

Product Security Engineer III

Alberta, CanadaWebsite

Full details on LinkedIn

The complete job description, requirements, and application details are available on the original posting.


About GitHub

GitHub is a web-based platform for version control, collaboration, and software development. It allows developers to share, edit, and store programming code online. Founded in 2007 and launched in 2008, GitHub has grown to over 150 million users and hosts more than 420 million projects. The platform is owned by Microsoft, which acquired it in 2018. GitHub offers a range of services, including repository hosting, version control, code review, issue tracking, and project management. Users can create their own copies of repositories, track project changes, and host web pages through GitHub Pages. GitHub Enterprise provides secure on-premises repository hosting for large teams. Additionally, GitHub Copilot, an AI-powered developer tool, significantly contributes to the company's revenue growth. Major companies like Google, Facebook, and Microsoft utilize GitHub for their development needs. The company is headquartered in San Francisco.

Industry

information technology & services

Employees

6,200

2190 engineers

Revenue

$2.0B

Website

Visit →

Security at GitHub

Compiled from public job postings, careers pages, and company materials. Data may not reflect current state — verify during interviews.

3 Intel Signals

Security Philosophy

  • GitHub's AppSec philosophy is centered on 'Powerful security, designed for developers.' Their approach emphasizes developer enablement by providing tools that allow developers to find and fix vulnerable code and dependencies automatically.
  • The philosophy focuses on shifting security into the developer workflow through automation and AI-supported triage, aiming to prevent issues like secret leaks before exploitation.

Security Team

  • GitHub's security organization is led by Alexis Wales, the Chief Information Security Officer.
  • The team includes the GitHub Security Lab, which is described as a group of security experts focused on cultivating a collaborative community.
  • While specific organizational charts for the internal AppSec team are not fully public, the Security Lab represents a significant public-facing component of their security expertise.
  • Team size estimates and specific reporting lines for sub-teams are not explicitly detailed in the provided public documentation.

Key Initiatives

  • Current initiatives include the expansion of application security coverage using AI-powered detections and the implementation of AI-supported vulnerability triage via the GitHub Security Lab Taskflow Agent.
  • GitHub is also focusing on 'Copilot Autofix,' which provides targeted recommendations for fixing code scanning alerts.
  • Additionally, they emphasize coordinated disclosure of security vulnerabilities as a collaborative effort between reporters and maintainers.

Preparing for an AppSec interview?

Get the weekly briefing 2,000+ security pros trust.