Security Engineer, Product Security
Security Engineer conducts code reviews, implements secure CI/CD pipelines, performs SAST/DAST testing, and secures AWS infrastructure using Terraform. Requires expertise in TypeScript, Python, NodeJS, and product security best practices to mitigate vulnerabilities in AI/ML products.
About the job
Responsibilities
- Leverage broad product security expertise to build and maintain software tooling that secures every layer of the modern AI/ML software ecosystem.
- Conduct in-depth code reviews to identify and remediate security vulnerabilities.
- Evaluate and enhance the security of product offerings through RFC and service review.
- Implement and maintain CI/CD pipelines with a strong focus on security.
- Perform SAST and DAST to identify vulnerabilities in production code.
- Utilize Terraform orchestration to ensure secure and efficient infrastructure management.
- Guide engineering teams to build robust long-term solutions that consider security and privacy.
- Clearly explain the mechanics and significance of security vulnerabilities, including their exploitability and potential impact.
- Influence the security strategy and direction of the team, advocating for best practices and continuous improvement.
Requirements
- Proven experience as a Security Engineer with a focus on product security.
- Proficiency in NodeJS, TypeScript, Python, and/or Kubernetes.
- Strong understanding of modern Javascript application design.
- Production experience operating and securing AWS infrastructure at scale.
- Hands-on experience with SAST and DAST tools and methodologies.
- Familiarity with Terraform orchestration for infrastructure management.
- Ability to structure complex problems and diagnose root causes independently.
- Excellent communication skills to present technical concepts to technical and non-technical stakeholders.
- Demonstrated ability to influence security strategies and drive improvements.
Nice-to-Haves
- Demonstrated ability to drive multi-month security initiatives independently.
- Relevant security certifications (e.g., CISSP, CEH, OSCP).
Skills
TypeScript, Python, AWS, CI/CD, SAST, DAST, Terraform, Kubernetes, Node.js, JavaScript
Similar jobs
Security Engineering jobsThe Red Team Specialist evaluates AI models for cyber capabilities, safeguard failures, and agentic-system abuse risks. The role combines hands-on security testing, automated evaluation infrastructure, risk assessment, and cross-functional communication.
Build and operate trust and safety systems that detect and mitigate abuse at internet scale. The role combines security engineering, large-scale data analysis, and applied LLM techniques, requiring 5+ years of relevant experience and strong Python and JavaScript/TypeScript skills.
This role builds and improves infrastructure security controls across cloud, operating system, Kubernetes, network, and CI/CD environments. It requires cloud security expertise, programming and Infrastructure as Code proficiency, threat-modeling experience, and the ability to lead infrastructure containment during security incidents.
Leads and develops a security incident response team while driving automation, AI-assisted workflows, operational maturity, and response strategy. The role requires 5+ years of incident response experience, people leadership, technical depth, and calm management of high-severity incidents.
The Security Engineer will track advanced adversaries targeting frontier AI infrastructure, build intelligence pipelines, conduct threat hunts, and create production detections. The role requires hands-on malware and infrastructure analysis, production programming, and close collaboration with detection and incident response teams.