Skip to content
NooksNooks

Security Engineer

Second Security Engineer at Nooks.ai, securing an AI-native sales platform and its AI agents. Own threat modeling, secure SDLC, cloud hardening, compliance (SOC 2), and novel AI security challenges (guardrails, prompt injection). Requires 4-5+ years in infosec with strong app/cloud security fundamentals; startup experience preferred.

About the job

Responsibilities

  • Own security reviews and threat modeling for new and existing product surfaces.
  • Build and improve core security processes (secure SDLC, detection & response).
  • Harden cloud and application infrastructure and drive remediation of high-priority risks.
  • Help define how we secure AI agents and govern their use — guardrails, data exposure, prompt-injection and abuse risks.
  • Support enterprise customer trust: security questionnaires, compliance (SOC 2), and customer-facing security needs.
  • Partner closely with product and infra engineering to embed security into how we ship.

Requirements

  • 4-5+ years of hands-on information security experience.
  • Experience at a startup or early-stage company; comfort with ambiguity, autonomy, and high ownership.
  • Strong fundamentals in application and/or cloud security (AWS/GCP).
  • Pragmatic judgment — able to prioritize risk and do more with less.
  • Clear communication and a collaborative, low-ego style.

Nice-to-Haves

  • Experience securing AI agents / LLM systems or governing AI agent use within an organization.
  • Enterprise compliance experience (SOC 2, ISO 27001).

Skills

Application Security, Cloud Security, AWS, GCP, Threat Modeling, Secure Sdlc, Detection And Response, SOC 2, Ai Security, Llm Security, Prompt Injection

OpenAI

OpenAI

San Francisco, CA
Red Team Specialist - Cyber
$198k+/yrHybridSecurity Engineering

The Red Team Specialist evaluates AI models for cyber capabilities, safeguard failures, and agentic-system abuse risks. The role combines hands-on security testing, automated evaluation infrastructure, risk assessment, and cross-functional communication.

Vercel

Vercel

San Francisco, CA
Software Engineer, Trust & Safety
$196k+/yrHybrid5+ YOESecurity Engineering

Build and operate trust and safety systems that detect and mitigate abuse at internet scale. The role combines security engineering, large-scale data analysis, and applied LLM techniques, requiring 5+ years of relevant experience and strong Python and JavaScript/TypeScript skills.

1Password

1Password

United States
Manager, Security Incident Response
$192k+/yrRemote5+ YOESecurity Engineering

Leads and develops a security incident response team while driving automation, AI-assisted workflows, operational maturity, and response strategy. The role requires 5+ years of incident response experience, people leadership, technical depth, and calm management of high-severity incidents.

Decagon

Decagon

San Francisco, CA

Governance, Risk, and Compliance Manager - Privacy
$190k+/yrOn-site5+ YOESecurity Engineering

Own and operate Decagon’s privacy and GRC programs, including regulatory compliance, data governance, customer security engagements, audits, and cross-functional privacy initiatives. The role requires 5+ years of GRC experience, strong communication and project management skills, and familiarity with enterprise security controls.

Anthropic

Anthropic

San Francisco, CA
Safeguards Policy Analyst, Cyber Harms
$190k+/yrHybridSecurity Engineering

The analyst develops and evaluates cyber product policies, enforcement guidance, controlled-access frameworks, and launch-review inputs for AI systems. The role requires strong policy writing, cybersecurity or platform-enforcement familiarity, technical security literacy, and cross-functional communication.