Security Engineer
Builds foundational security systems for AI SaaS infrastructure, including secure execution for AI agents, AWS guardrails with Terraform, identity management, and observability. Requires strong application security, DevOps, and AWS experience with a focus on automation and developer-friendly tools.
About the job
Responsibilities
- Develop sandboxing and secure execution patterns for AI-powered workflows and agents.
- Implement secure-by-default infrastructure guardrails across AWS using Terraform and GitOps workflows.
- Build automated systems that reduce operational risk.
- Create paved-road security tooling that helps engineers ship securely by default.
- Build a unified identity and access system across internal tooling, infrastructure, and production systems.
- Design secrets management and credential rotation systems with strong auditing and least-privilege guarantees.
- Improve application security around authentication, authorization, API protection, and multi-tenant isolation.
- Build security observability pipelines for logging, detection, and incident response.
Requirements
- Strong background in application security, infrastructure, DevOps, or platform engineering.
- Experience designing and shipping production systems end-to-end.
- Hands-on experience with AWS infrastructure and security primitives (IAM, networking, RDS, etc.).
- Experience with infrastructure-as-code tools like Terraform.
- Familiarity with identity systems such as SSO, IAM, or IdPs.
- Strong communication skills and the ability to drive projects independently.
Nice-to-Haves
- Interest in AI/LLM security, prompt injection, data poisoning, model extraction, etc. and mitigations.
- Experience with tools like Wiz, Doppler, or 1Password.
- Experience with SIEM or security event pipelines.
- Kubernetes or service mesh security experience.
- Experience with sandboxing or secure execution environments.
Skills
AWS, Terraform, IAM, SSO, Idps, Kubernetes, GitOps, SIEM, Wiz, Doppler
Similar jobs
Security Engineering jobsThe Application Security Engineer will embed security practices throughout the SaaS software development lifecycle, including threat modeling, automated testing, vulnerability remediation, and incident response. The role requires 5+ years of application or product security experience and expertise with DevSecOps workflows, web applications, and CI/CD automation.
The Cyber Threat Intel Analyst tracks, investigates, attributes, and reports on advanced threats targeting cloud, AI, and developer environments. The role requires at least three years of security or threat research experience and strong technical analysis and writing skills.
The GRC Analyst will operate and mature security and compliance programs across major privacy and security frameworks, supporting risk assessments, access reviews, third-party risk, control monitoring, and audits. The role requires 3–5 years of GRC or information security experience and strong cross-functional communication.
Manages FedRAMP compliance for a cloud service provider by implementing security controls, supporting audits and remediation, maintaining SSP documentation, and coordinating authorization activities. Requires 5+ years of IT audit or compliance experience and hands-on FedRAMP ATO leadership.
Develops safety requirements, analyses, and fail-operational architectures for autonomous-vehicle sensing and perception systems. The role requires 3+ years analyzing safety-critical systems and familiarity with functional-safety standards, sensing hardware, perception, and cross-functional systems engineering.