Staff Product Security Engineer
Leads advanced penetration testing, red team operations, and AI/ML security research to secure applications, infrastructure, and distributed AI systems including LLMs and Kubernetes environments. Requires 8-10 years offensive security experience and strong software engineering in Go/Python/Rust.
About the job
What You’ll Be Working On
- Performing advanced manual penetration testing across complex applications, infrastructure, Kubernetes environments, and distributed microservice ecosystems
- Leading offensive security initiatives including red team operations, adversary simulation, and security research
- Securing AI/ML systems end-to-end, including LLM pipelines, vector databases, RAG architectures, and agentic workflows
- Identifying and researching novel attack surfaces unique to LLMs and autonomous systems, contributing to internal and external AI security research
- Influencing secure system design across the SDLC, embedding security into CI/CD pipelines, container images, and deployment workflows
- Integrating and operationalizing security tooling (SAST, DAST, SCA, container scanning) and driving remediation of complex application-layer vulnerabilities
- Building internal security guardrails such as hardened base images, reusable libraries, and policy-as-code frameworks
- Developing production-grade security tooling and leading cross-functional security programs from design through deployment
What You’ll Bring to the Team
- 8-10 years of deep hands-on experience in offensive security, including manual penetration testing, red team operations, and adversary simulation
- Familiarity with modern C2 frameworks (e.g., Cobalt Strike, Sliver, Havoc), exploit development, and security research
- Strong expertise across the AI/ML stack, including MLOps, inference architectures, vector databases, RAG, and agentic frameworks (e.g., ReAct, Reflexion)
- Experience building, deploying, and securing LLM pipelines and AI workflows in Kubernetes and/or bare-metal environments
- Strong software engineering foundations with experience shipping production code in Go, Python, or Rust
- Hands-on experience securing Kubernetes, containers, VMs, and CI/CD environments
- Deep understanding of application security vulnerabilities, secure coding practices, and distributed system design
- Demonstrated ability to lead complex, cross-functional security initiatives end-to-end
- Strong communication skills with the ability to influence both engineering teams and executive stakeholders
Bonus Points
- Public contributions to offensive security or AI security research (talks, blogs, tooling, CVEs, etc.)
- Experience building internal red team or adversary simulation programs
- Background in high-performance computing, AI infrastructure, or cloud-native platform security
- Experience designing policy-as-code frameworks at scale
Benefits
- Competitive compensation
- Restricted Stock Units
- Paid time off & paid holidays
- Comprehensive health, dental & vision insurance
- Employer contributions to HSA account
- Paid parental leave
- Paid life insurance, short-term and long-term disability
- Professional development & tuition reimbursement
- Mental health & wellness support
- Commuter benefits (parking & transit)
- Cell phone stipend
- 401(k) Retirement plan with company match up to 4% of salary
Compensation Range: up to $250,000 - $285,000 + Bonus. Restricted Stock Units are included in all offers. Compensation to be determined by the applicant's knowledge, education, and abilities, as well as internal equity and alignment with market data.
Skills
Kubernetes, Penetration Testing, Red Team Operations, Cobalt Strike, LLMs, MLOps, RAG, Go, Python, Rust, CI/CD, SAST, DAST, Sca, Policy As Code
Similar jobs
Security Engineering jobsLeads the multi-year technical strategy and architecture for Coinbase’s identity and access management platform across hundreds of systems and engineering teams. Requires 12+ years of software engineering experience, deep IAM and workload identity expertise, production Go, and distributed-systems experience on AWS.
Handles complex customer-facing security engagements for regulated enterprises, including audits, questionnaires, contract terms, executive briefings, and trust documentation. Requires broad security expertise, strong writing, independent judgment, and 10+ years of security experience, including leadership experience preferred.
Own and scale IT general controls, access governance, segregation of duties, and audit readiness across enterprise applications. The role combines SOX expertise with AI-enabled continuous controls monitoring and requires 10+ years of controls, audit, or enterprise governance experience.
Staff Security Software Engineer leading identity and access strategy, architecture, and hands-on platform development across customer, employee, contractor, and agentic identities. Requires 10+ years of production software experience and deep expertise in identity and authorization systems.
Design and operate distributed, low-latency infrastructure that protects Reddit from DDoS attacks, bots, scraping, and other network threats. The role requires 7+ years of distributed-systems experience plus expertise in security, networking, and production operations.