Platform Engineer, Security
Lead application security strategy and implementation for Decagon's conversational AI platform. Partner with engineering teams to build security into AI-powered applications and establish testing programs.
About the job
Responsibilities
- Design and implement application security controls across our AI agent platform, including secure coding practices, threat modeling, and vulnerability management
- Collaborate closely with product engineering teams to integrate security throughout the software development lifecycle, from design, coding, PR, and deployment
- Establish application security testing programs including static analysis (SAST), dynamic analysis (DAST), and interactive testing (IAST) tailored for AI applications
- Lead security code reviews and architecture assessments for new features, with special focus on AI model integration points and customer data handling
- Build security tooling and automation to enable developers to identify and remediate vulnerabilities quickly while maintaining development velocity
- Respond to security incidents involving application vulnerabilities, coordinating remediation efforts and post-incident improvements
Requirements
- 3-5 years of hands-on application security engineering experience
- Expertise in secure software development practices, including threat modeling, secure code review, and vulnerability assessment
- Strong software engineering background with ability to review code across multiple languages and frameworks commonly used in AI/ML applications
- Experience implementing application security testing tools and integrating security into CI/CD pipelines
- Knowledge of OWASP Top 10, common application vulnerabilities, and modern application security frameworks
- Proven track record working with engineering teams to remediate security findings while balancing security and business requirements
Nice-to-Haves
- Experience securing AI/ML applications, including prompt injection, model extraction, and adversarial input protections
- Background with large-scale, multi-tenant SaaS applications handling sensitive customer data
- Familiarity with Google Cloud application security services and container security best practices
- Knowledge of enterprise compliance requirements (SOC 2, ISO 27001, GDPR) from an application security perspective
- Experience with modern security tools like Semgrep, CodeQL, Cursor Bug Bot, XBOW, or similar
Skills
Application Security, Threat Modeling, Secure Code Review, SAST, DAST, Iast, Ci/Cd Security, Owasp Top 10, Vulnerability Management, Semgrep, Codeql, Google Cloud Security, Container Security
Similar jobs
Security Engineering jobsThe Red Team Specialist evaluates AI models for cyber capabilities, safeguard failures, and agentic-system abuse risks. The role combines hands-on security testing, automated evaluation infrastructure, risk assessment, and cross-functional communication.
Build and operate trust and safety systems that detect and mitigate abuse at internet scale. The role combines security engineering, large-scale data analysis, and applied LLM techniques, requiring 5+ years of relevant experience and strong Python and JavaScript/TypeScript skills.
Leads and develops a security incident response team while driving automation, AI-assisted workflows, operational maturity, and response strategy. The role requires 5+ years of incident response experience, people leadership, technical depth, and calm management of high-severity incidents.
Own and operate Decagon’s privacy and GRC programs, including regulatory compliance, data governance, customer security engagements, audits, and cross-functional privacy initiatives. The role requires 5+ years of GRC experience, strong communication and project management skills, and familiarity with enterprise security controls.
The analyst develops and evaluates cyber product policies, enforcement guidance, controlled-access frameworks, and launch-review inputs for AI systems. The role requires strong policy writing, cybersecurity or platform-enforcement familiarity, technical security literacy, and cross-functional communication.