Summary
✨ AI‑Generated
A senior security professional is sought to own security outcomes across multiple products, lead security reviews, establish technical standards, and create processes and tools that help engineering teams manage risk effectively.
Highlights
High-ownership security role with opportunities to define standards, influence engineering practices, and build scalable security programs.
Description
We're looking for a Security Engineer to join our AI Platform Security team.
It is a high-ownership, low-oversight role for an application/product security generalist who has already done the work and is ready to set direction rather than follow it.
You'll own security outcomes for a portfolio of products, define how security reviews and standards operate across the organization, and build the tooling and programs that let a lean team cover a large surface area.
We are a lean, high-trust team.
You'll make real risk calls, push back on engineering leadership when the data supports it, and be accountable for the areas you own while helping to shape how this team operates as it scales.
What You'll Do:
Own end-to-end security for an assigned portfolio of products: design reviews, threat modeling, risk acceptance, and driving high-severity findings to closureSet technical direction for your program areas: define the review bar, standards, checklists, and intake processes other engineers followLead vulnerability management and the bug bounty program: complex triage, escalation, researcher relations, SLA ownership, and program evolutionDesign and build security automation and internal tooling that removes manual toil and scales coverage beyond headcountDrive shift-left adoption across the SDLC through pipeline gates, guardrails, paved-path patterns, and developer enablementLead the team's AI/LLM security practice: assessment methodology, testing approach, and applied frameworks for agentic and model-backed featuresCommunicate risk and program health to engineering and executive leadership through metrics, reporting, and clear written narratives
Who We're Looking For:
Experience in security engineering, application security, offensive security, or a closely related technical disciplineDeep, demonstrated knowledge of vulnerability classes and exploitation: injection, authentication and session flaws, access control, deserialization, SSRF, and their real-world variantsAbility to read, review, and write code in at least one language (Python, JavaScript/TypeScript, Go, or Java), and to reason about unfamiliar codebases quicklyTrack record of owning a security program area independently and driving cross-functional remediation without formal authorityExperience threat modeling non-trivial systems and translating findings into decisions engineering teams will actually act onExcellent written communication.
You will produce standards, risk narratives, executive reporting, and researcher-facing correspondenceComfort operating with ambiguity and building structure where none exists yet
Preferred:
Experience running or substantially maturing a bug bounty or vulnerability disclosure programHands-on depth with security tooling such as Snyk, Burp Suite, DAST, or SAST platforms, including tuning and integration rather than just usageDemonstrated ability to build security automation or internal tooling used by othersApplied understanding of AI/LLM security risks: prompt injection, insecure tool use, context and data leakage, model supply chainPrior mentorship, tech lead, or team lead experienceBug bounty participation as a researcher, published research, or CVE credit