Skip to content
Scale AIScale AI

Security Engineer, Product Security

Security Engineer conducts code reviews, implements secure CI/CD pipelines, performs SAST/DAST testing, and secures AWS infrastructure using Terraform. Requires expertise in TypeScript, Python, NodeJS, and product security best practices to mitigate vulnerabilities in AI/ML products.

About the job

Responsibilities

  • Leverage broad product security expertise to build and maintain software tooling that secures every layer of the modern AI/ML software ecosystem.
  • Conduct in-depth code reviews to identify and remediate security vulnerabilities.
  • Evaluate and enhance the security of product offerings through RFC and service review.
  • Implement and maintain CI/CD pipelines with a strong focus on security.
  • Perform SAST and DAST to identify vulnerabilities in production code.
  • Utilize Terraform orchestration to ensure secure and efficient infrastructure management.
  • Guide engineering teams to build robust long-term solutions that consider security and privacy.
  • Clearly explain the mechanics and significance of security vulnerabilities, including their exploitability and potential impact.
  • Influence the security strategy and direction of the team, advocating for best practices and continuous improvement.

Requirements

  • Proven experience as a Security Engineer with a focus on product security.
  • Proficiency in NodeJS, TypeScript, Python, and/or Kubernetes.
  • Strong understanding of modern Javascript application design.
  • Production experience operating and securing AWS infrastructure at scale.
  • Hands-on experience with SAST and DAST tools and methodologies.
  • Familiarity with Terraform orchestration for infrastructure management.
  • Ability to structure complex problems and diagnose root causes independently.
  • Excellent communication skills to present technical concepts to technical and non-technical stakeholders.
  • Demonstrated ability to influence security strategies and drive improvements.

Nice-to-Haves

  • Demonstrated ability to drive multi-month security initiatives independently.
  • Relevant security certifications (e.g., CISSP, CEH, OSCP).

Skills

TypeScript, Python, AWS, CI/CD, SAST, DAST, Terraform, Kubernetes, Node.js, JavaScript

OpenAI

OpenAI

San Francisco, CA
Red Team Specialist - Cyber
$198k+/yrHybridSecurity Engineering

The Red Team Specialist evaluates AI models for cyber capabilities, safeguard failures, and agentic-system abuse risks. The role combines hands-on security testing, automated evaluation infrastructure, risk assessment, and cross-functional communication.

Vercel

Vercel

San Francisco, CA
Software Engineer, Trust & Safety
$196k+/yrHybrid5+ YOESecurity Engineering

Build and operate trust and safety systems that detect and mitigate abuse at internet scale. The role combines security engineering, large-scale data analysis, and applied LLM techniques, requiring 5+ years of relevant experience and strong Python and JavaScript/TypeScript skills.

Tailscale

Tailscale

United States
Security Infrastructure Engineer
CA$218k+/yrRemoteSecurity Engineering

This role builds and improves infrastructure security controls across cloud, operating system, Kubernetes, network, and CI/CD environments. It requires cloud security expertise, programming and Infrastructure as Code proficiency, threat-modeling experience, and the ability to lead infrastructure containment during security incidents.

1Password

1Password

United States
Manager, Security Incident Response
$192k+/yrRemote5+ YOESecurity Engineering

Leads and develops a security incident response team while driving automation, AI-assisted workflows, operational maturity, and response strategy. The role requires 5+ years of incident response experience, people leadership, technical depth, and calm management of high-severity incidents.

Fluidstack

Fluidstack

New York, NY
Security Engineer, Threat Intelligence
$220k+/yrOn-siteSecurity Engineering

The Security Engineer will track advanced adversaries targeting frontier AI infrastructure, build intelligence pipelines, conduct threat hunts, and create production detections. The role requires hands-on malware and infrastructure analysis, production programming, and close collaboration with detection and incident response teams.