Senior Security Engineer, AI Incident Response
Leads product security incident response for Snowflake’s AI products and infrastructure, developing detection, containment, and remediation capabilities for LLM and agentic threats. Requires 5+ years in security, incident command experience, cloud-native expertise, and strong knowledge of AI attack surfaces.
About the job
Responsibilities
- Lead incident response for product-level security events, focusing on AI-specific threats including prompt injection, model abuse, agent hijacking, and data exfiltration through AI workloads.
- Integrate incident response into AI product pipelines across Cortex features, Snowflake Intelligence, and AI-powered developer experiences.
- Develop detection, containment, and remediation playbooks for LLM misuse, adversarial inputs, and AI-assisted attacks.
- Improve incident-response readiness across Cortex and agentic architectures.
- Represent incident response with cloud engineering, AI platform, corporate security, and customer-facing teams.
- Secure AI-native codebases across multi-cloud environments, including container-based inference services, RAG pipelines, vector stores, and agent orchestration layers.
- Advise AI and security engineering teams on secure architecture for high-impact AI features.
- Design and manage response capabilities across model-serving endpoints, Cortex Search indexes, and Snowpark ML pipelines.
- Build automation and tooling to accelerate detection and response for product security incidents.
Requirements
- 5+ years of experience in information security, incident response, security engineering, or product/application security.
- Experience serving as incident commander for product-focused security incidents.
- Experience building or leading an application or security engineering program, with expertise in securing AI/ML systems.
- Experience with threat modeling and security testing across AI attack surfaces, including prompt injection, indirect injection, model inversion, embedding extraction, and AI dependency supply-chain attacks.
- Familiarity with data governance and security challenges associated with LLMs, RAG architectures, and agentic systems.
- Working knowledge of AWS, Azure, or Google Cloud and the threat landscape for SaaS and AI platforms.
- SQL proficiency and experience building automation with common programming languages, preferably Python.
- Strong communication skills and the ability to translate security risks into actionable product guidance.
- Bachelor's degree in Computer Science or a related field, or equivalent experience.
Nice-to-haves
- Experience securing AI/ML infrastructure, including model serving, vector databases, embedding pipelines, API gateways, and LLM-integrated applications.
- Experience building agentic incident-response capabilities, including skills, agents, and pipelines.
- Understanding of attacker TTPs, adversarial ML, agent manipulation, and LLM jailbreaking in enterprise contexts.
- Familiarity with CI/CD and secure release lifecycle patterns for AI feature pipelines.
- Certifications such as GCIA, GCIH, GCSA, GDAT, CISSP/GISP, or AWS, Azure, or Google Cloud certifications.
Compensation
- Annual salary range: $176,000–$253,000.
Skills
Incident Response, Ai Security, Llm Security, Threat Modeling, Security Testing, Python, SQL, AWS, Azure, GCP, RAG, Vector Databases, CI/CD, Prompt Injection, Kubernetes
Similar jobs
Security Engineering jobsLeads product security incident response for Snowflake’s AI and agentic products, developing detection, containment, remediation, and automation capabilities. Requires 5+ years in security, incident command experience, cloud expertise, and knowledge of AI/ML attack surfaces.
Leads security risk identification, prioritization, and remediation across an infrastructure organization while building a security program and advising technical leaders. Requires a bachelor’s degree, 8+ years of software or infrastructure engineering experience, and substantial security experience.
Own and scale Starburst’s application and product security program through secure-by-default engineering, automated vulnerability management, threat modeling, and autonomous offensive testing. The role requires 5–7 years of security-focused experience, strong software supply chain expertise, and the ability to engage enterprise customers and lead engineers.
The Senior Security Engineer will secure Jasper’s AI systems, cloud infrastructure, software supply chain, and compliance workflows while building automation and security standards for a growing program. The role requires 8+ years of security engineering experience and hands-on expertise across AI, cloud, or GRC security.
Own and scale Jasper’s governance, risk, and compliance program for AI-native SaaS products, leading audits, risk and vendor programs, policy management, and AI governance. The role requires 8+ years of GRC experience, expertise in major security frameworks, cloud and AI fluency, and strong cross-functional communication.