Senior Security Engineer
The Senior Security Engineer will secure Jasper’s AI systems, cloud infrastructure, software supply chain, and compliance workflows while building automation and security standards for a growing program. The role requires 8+ years of security engineering experience and hands-on expertise across AI, cloud, or GRC security.
About the job
Responsibilities
- Lead security design, implementation, and controls for AI infrastructure and AI-powered internal workflows.
- Build guardrails governing how AI systems access, process, and handle sensitive data.
- Own threat modeling for AI-specific risks and design controls for validating, logging, and auditing AI outputs.
- Build security tooling and automated checks for safe adoption of AI capabilities.
- Partner with Engineering, GRC, Product, IT, Legal, and other stakeholders to shape the security program and translate requirements into practical engineering solutions.
- Automate evidence collection, control monitoring, and compliance workflows using GRC platforms such as Vanta or similar tools.
- Strengthen GCP and AWS infrastructure security, including IAM, network segmentation, secrets management, and secure-by-default infrastructure patterns.
- Own GitHub security controls, including branch protection, required reviews, secret scanning, dependency and software composition analysis policies, and CI/CD pipeline security.
- Operate and tune Wiz or comparable CSPM/CNAPP tooling to identify and remediate cloud misconfigurations and vulnerabilities.
- Use AI tools for code review, triage, detection engineering, and documentation, and help teams use them safely.
Requirements
- 8+ years of security engineering experience.
- Hands-on experience in at least two of AI/ML security, cloud infrastructure security, or GRC compliance engineering.
- Practical experience securing LLM applications, agents, or ML pipelines, including prompt injection, data leakage, model abuse, and insecure tool use.
- Strong security principles, vulnerability knowledge, and judgment under ambiguity.
- Experience building security programs, processes, or standards from scratch.
- Strong working knowledge of GCP and AWS security services and IAM models.
- Experience with GitHub security controls, Actions/CI security, and secure software supply chain practices.
- Hands-on experience with Wiz or a comparable CSPM/CNAPP platform.
- Ability to build automation and tooling using scripting, APIs, and infrastructure-as-code.
- Strong cross-functional communication skills with technical and non-technical stakeholders.
- Working understanding of AI concepts including LLMs, agents, copilots, tokens, context windows, RAG, and data governance.
Nice to Have
- Experience building or securing AI agent frameworks, tool-calling systems, or internal AI platforms.
- Experience supporting SOC 2, ISO 27001, or similar compliance frameworks and using GRC platforms such as Vanta or Drata.
- Detection engineering or internal security tooling experience.
- Experience as an early or first specialized hire on a small security team.
- Experience with AI infrastructure platforms such as Modal or CoreWeave.
Compensation and Benefits
- Base salary range: $174,250–$205,000.
- Health, dental, and vision coverage from the first day.
- 401(k) program with up to 2% company matching.
- Equity grant participation.
- Flexible paid time off.
- Annual FlexExperience budget of $900.
- Annual FlexWellness budget of $1,800.
- Home office setup budget.
- Annual learning and development stipend.
- 16 weeks of paid parental leave.
Skills
Ai Security, Llm Security, Threat Modeling, GCP, AWS, IAM, GitHub Actions, Secret Scanning, Software Composition Analysis, Wiz, Cspm, Infrastructure As Code, GRC, Vanta, Detection Engineering
Similar jobs
Security Engineering jobsOwn and scale Jasper’s governance, risk, and compliance program for AI-native SaaS products, leading audits, risk and vendor programs, policy management, and AI governance. The role requires 8+ years of GRC experience, expertise in major security frameworks, cloud and AI fluency, and strong cross-functional communication.
Leads engineering for Wiz’s FedRAMP CR26 initiative, translating federal compliance requirements into scalable compliance-as-code, automation, and evidence-generation solutions. Requires 6+ years in security, DevOps, or systems engineering and deep experience with NIST, FedRAMP, and government cloud environments.
Own and scale Starburst’s application and product security program through secure-by-default engineering, automated vulnerability management, threat modeling, and autonomous offensive testing. The role requires 5–7 years of security-focused experience, strong software supply chain expertise, and the ability to engage enterprise customers and lead engineers.
Leads product security incident response for Snowflake’s AI and agentic products, developing detection, containment, remediation, and automation capabilities. Requires 5+ years in security, incident command experience, cloud expertise, and knowledge of AI/ML attack surfaces.
Leads product security incident response for Snowflake’s AI products and infrastructure, developing detection, containment, and remediation capabilities for LLM and agentic threats. Requires 5+ years in security, incident command experience, cloud-native expertise, and strong knowledge of AI attack surfaces.