Sr./Staff Security Engineer
Leads product and application security for a multi-tenant AI risk platform, including threat modeling, identity controls, AppSec tooling, incident response, and LLM security guardrails. Requires 5+ years of software development experience and 3+ years in application or product security.
About the job
Responsibilities
- Own threat modeling across core platform APIs, risk decisioning and event-ingestion systems, and agentic AI products.
- Harden multi-tenant isolation and data handling across designs and pull requests.
- Design, implement, and deploy authentication, authorization, user and API access controls, and RBAC.
- Establish the application security program, including SAST, SCA, secret scanning, and container scanning.
- Build guardrails for LLM usage, including prompt-injection defenses, output validation, and cost and abuse monitoring for Bedrock, Anthropic, and OpenAI calls.
- Drive security incident processes, vulnerability triage, and responsible disclosure.
- Maintain
SECURITY.mdand a threat registry, and promote secure-by-default patterns across engineering. - Partner with IT on incident response, access reviews, and audit evidence collection.
- Collaborate with product and engineering teams to embed security early in feature design.
- Track current security standards and trends, including OWASP, MITRE ATT&CK, and emerging LLM and agent security guidance.
Requirements
- 5+ years building software, with the last 3+ years focused on application or product security.
- Strong software engineering fundamentals, ideally in a fintech or data-heavy SaaS environment.
- Hands-on Java, Python, or Go code review experience.
- Experience with SSO, SAML, OAuth 2.0, JWT, mTLS, JOSE, multi-tenant authorization, and PII handling or tokenization.
Nice to Have
- Familiarity with AWS security primitives, including IAM, KMS, Secrets Manager, and VPC.
- Kubernetes experience.
- Experience providing technical evidence and controls for SOC 2, PCI, or ISO 27001 audits.
- Experience building or tuning SAST rules with Semgrep or CodeQL.
- OSCP, CISSP, or a meaningful bug-bounty track record.
Compensation and Benefits
- Competitive salary; candidates are hired as CLT employees.
- Stock options.
- 100% company-paid medical and dental coverage for employees and dependents.
- 100% company-paid life and long-term disability insurance.
- Caju Card monthly meal allowance.
- Remote-first flexibility.
- Family-friendly environment, team events, and offsites.
- Learning and professional development opportunities.
Skills
Java, Python, Go, SSO, SAML, Oauth 2.0, Jwt, Mtls, Jose, RBAC, Semgrep, Dependabot, Snyk, Kubernetes, Aws Iam
Similar jobs
Security Engineering jobsLeads interpretation and productization of federal compliance controls for Vanta’s public-sector platform, translating FedRAMP and related frameworks into technically testable guidance, automated detectors, mappings, and machine-readable authorization workflows. Requires 8–10+ years of hands-on federal compliance experience, especially FedRAMP program and SSP work.
Own and scale security governance, risk, compliance, and customer assurance programs, including audits, controls monitoring, third-party risk, policies, and security questionnaires. The role requires 3–5 years of security GRC experience and hands-on understanding of IAM, endpoint, and cloud controls.
Senior Product Security Engineer who partners with developers to secure web applications and APIs throughout the SDLC. The role leads threat modeling, security reviews, penetration testing, secure code review, and security-tooling programs.
The Technical GRC Analyst evaluates technical controls, validates evidence, performs risk assessments, and advances AI governance, compliance automation, and assurance reporting. The role requires 8+ years in technical security, Security GRC, or regulatory compliance, with cloud and enterprise technology experience.
Leads a global Security Operations team, setting detection, response, and security strategy while driving incident response and risk remediation. The role requires strong SaaS and cloud security experience, leadership ability, familiarity with major security standards, and responsible use of AI.