Skip to content
CoinbaseCoinbase

Product Security Engineer

Develop AI-augmented offensive security tooling, red-team internal AI systems, and automate vulnerability workflows. The role requires at least three years of application or offensive security experience, programming ability, and hands-on experience with LLM security.

About the job

Responsibilities

  • Build, deploy, and maintain custom security scanners using frontier AI models to detect vulnerabilities across the product surface.
  • Lead red-team efforts against internal AI systems, including jailbreak testing, prompt-injection analysis, and tool-abuse simulation.
  • Develop AI-driven automation for vulnerability triage, validation, and remediation workflows.
  • Partner with engineering teams to prioritize, remediate, and verify fixes for critical vulnerabilities found through AI-augmented and manual testing.
  • Mentor junior security engineers on integrating AI into offensive-security workflows.

Requirements

  • 3+ years of experience in application security, penetration testing, or offensive security, including building custom security tooling.
  • Hands-on experience using large language models or frontier models to automate security tasks, scale vulnerability research, or build security scanners.
  • Experience red-teaming AI-based systems, including prompt injection, jailbreak testing, and tool abuse.
  • Deep understanding of common vulnerability classes, including the OWASP Top 10 and SANS Top 25, with experience identifying and exploiting them in production environments.
  • Proficiency in at least one programming language, such as Python or Go, and experience writing production-grade security tooling.
  • Ability to use generative AI responsibly with human oversight and deliver measurable workflow improvements.

Compensation

  • Annual base salary: 154,000–154,000 CAD.
  • Additional compensation may include equity, bonus eligibility, and benefits.

Skills

Application Security, Penetration Testing, Offensive Security, Ai Security, LLMs, Prompt Injection, Jailbreak Testing, Owasp Top 10, Sans Top 25, Python, Go, Vulnerability Scanners, Red Teaming

Motive

Motive

Canada

Red Team Security Engineer
CA$146k+/yrRemote5+ YOESecurity Engineering

Conduct cloud-focused red team operations, adversary simulations, and offensive security assessments while validating detection coverage and driving remediation. Requires at least five years of offensive security experience and familiarity with attacker techniques, cloud environments, and MITRE ATT&CK.

Motive

Motive

Toronto, Canada

Security Engineer, Hardware/Device
CA$146k+/yrHybrid5+ YOESecurity Engineering

The Security Engineer will establish hardware and embedded security practices for connected devices, covering secure boot, firmware, manufacturing, architecture reviews, threat modeling, and lifecycle controls. The role requires at least five years of hardware security, product security design, and hands-on Python and C/C++ development experience.

Vanta

Vanta

Remote

Manager, Security Operations
$178k+/yrRemote5+ YOESecurity Engineering

Leads a global Security Operations team, setting detection, response, and security strategy while driving incident response and risk remediation. The role requires strong SaaS and cloud security experience, leadership ability, familiarity with major security standards, and responsible use of AI.

1Password

1Password

United States
Manager, Security Incident Response
$192k+/yrRemote5+ YOESecurity Engineering

Leads and develops a security incident response team while driving automation, AI-assisted workflows, operational maturity, and response strategy. The role requires 5+ years of incident response experience, people leadership, technical depth, and calm management of high-severity incidents.

Tailscale

Tailscale

United States
Security Infrastructure Engineer
CA$218k+/yrRemoteSecurity Engineering

This role builds and improves infrastructure security controls across cloud, operating system, Kubernetes, network, and CI/CD environments. It requires cloud security expertise, programming and Infrastructure as Code proficiency, threat-modeling experience, and the ability to lead infrastructure containment during security incidents.