Skip to content
DecagonDecagon

Platform Engineer, Security

Lead application security strategy and implementation for Decagon's conversational AI platform. Partner with engineering teams to build security into AI-powered applications and establish testing programs.

About the job

Responsibilities

  • Design and implement application security controls across our AI agent platform, including secure coding practices, threat modeling, and vulnerability management
  • Collaborate closely with product engineering teams to integrate security throughout the software development lifecycle, from design, coding, PR, and deployment
  • Establish application security testing programs including static analysis (SAST), dynamic analysis (DAST), and interactive testing (IAST) tailored for AI applications
  • Lead security code reviews and architecture assessments for new features, with special focus on AI model integration points and customer data handling
  • Build security tooling and automation to enable developers to identify and remediate vulnerabilities quickly while maintaining development velocity
  • Respond to security incidents involving application vulnerabilities, coordinating remediation efforts and post-incident improvements

Requirements

  • 3-5 years of hands-on application security engineering experience
  • Expertise in secure software development practices, including threat modeling, secure code review, and vulnerability assessment
  • Strong software engineering background with ability to review code across multiple languages and frameworks commonly used in AI/ML applications
  • Experience implementing application security testing tools and integrating security into CI/CD pipelines
  • Knowledge of OWASP Top 10, common application vulnerabilities, and modern application security frameworks
  • Proven track record working with engineering teams to remediate security findings while balancing security and business requirements

Nice-to-Haves

  • Experience securing AI/ML applications, including prompt injection, model extraction, and adversarial input protections
  • Background with large-scale, multi-tenant SaaS applications handling sensitive customer data
  • Familiarity with Google Cloud application security services and container security best practices
  • Knowledge of enterprise compliance requirements (SOC 2, ISO 27001, GDPR) from an application security perspective
  • Experience with modern security tools like Semgrep, CodeQL, Cursor Bug Bot, XBOW, or similar

Skills

Application Security, Threat Modeling, Secure Code Review, SAST, DAST, Iast, Ci/Cd Security, Owasp Top 10, Vulnerability Management, Semgrep, Codeql, Google Cloud Security, Container Security

OpenAI

OpenAI

San Francisco, CA
Red Team Specialist - Cyber
$198k+/yrHybridSecurity Engineering

The Red Team Specialist evaluates AI models for cyber capabilities, safeguard failures, and agentic-system abuse risks. The role combines hands-on security testing, automated evaluation infrastructure, risk assessment, and cross-functional communication.

Vercel

Vercel

San Francisco, CA
Software Engineer, Trust & Safety
$196k+/yrHybrid5+ YOESecurity Engineering

Build and operate trust and safety systems that detect and mitigate abuse at internet scale. The role combines security engineering, large-scale data analysis, and applied LLM techniques, requiring 5+ years of relevant experience and strong Python and JavaScript/TypeScript skills.

1Password

1Password

United States
Manager, Security Incident Response
$192k+/yrRemote5+ YOESecurity Engineering

Leads and develops a security incident response team while driving automation, AI-assisted workflows, operational maturity, and response strategy. The role requires 5+ years of incident response experience, people leadership, technical depth, and calm management of high-severity incidents.

Decagon

Decagon

San Francisco, CA

Governance, Risk, and Compliance Manager - Privacy
$190k+/yrOn-site5+ YOESecurity Engineering

Own and operate Decagon’s privacy and GRC programs, including regulatory compliance, data governance, customer security engagements, audits, and cross-functional privacy initiatives. The role requires 5+ years of GRC experience, strong communication and project management skills, and familiarity with enterprise security controls.

Anthropic

Anthropic

San Francisco, CA
Safeguards Policy Analyst, Cyber Harms
$190k+/yrHybridSecurity Engineering

The analyst develops and evaluates cyber product policies, enforcement guidance, controlled-access frameworks, and launch-review inputs for AI systems. The role requires strong policy writing, cybersecurity or platform-enforcement familiarity, technical security literacy, and cross-functional communication.