Software Engineer, Trust & Safety
Build and operate trust and safety systems that detect and mitigate abuse at internet scale. The role combines security engineering, large-scale data analysis, and applied LLM techniques, requiring 5+ years of relevant experience and strong Python and JavaScript/TypeScript skills.
About the job
Responsibilities
- Analyze threat actor behavior and evolving abuse patterns across large, heterogeneous datasets to inform detection logic, policy decisions, and scalable mitigations.
- Research, prototype, and implement LLM-driven techniques for abuse detection, classification, and prevention.
- Design and develop production-ready systems that detect and disrupt abusive behavior across the platform.
- Build, maintain, and fine-tune internal tools, datasets, and evaluation pipelines for trust and safety workflows.
- Collaborate with security, product, and infrastructure teams to bring research ideas into stable, scalable production systems.
Requirements
- 5+ years of experience in abuse prevention, trust and safety, or security engineering.
- Strong programming skills in JavaScript/TypeScript and Python.
- Hands-on experience with LLMs, including prompt engineering, evaluation, and fine-tuning.
- Solid understanding of cloud infrastructure, including AWS.
- Strong understanding of real-world threat actor behavior and abuse tactics.
- Experience owning systems end-to-end, from research through production deployment and iteration.
Compensation and Benefits
- San Francisco base pay range: $196,000 - $294,000.
- Competitive compensation package, including equity.
- Inclusive healthcare package.
- Mentorship and professional development opportunities.
- Flexible time off.
- Company-provided equipment and work-from-home budget.
Skills
JavaScript, TypeScript, Python, LLMs, Prompt Engineering, Fine-Tuning, AWS, Cloud Infrastructure, Threat Detection, Abuse Prevention, Security Engineering, Data Analysis
Similar jobs
Security Engineering jobsThe Red Team Specialist evaluates AI models for cyber capabilities, safeguard failures, and agentic-system abuse risks. The role combines hands-on security testing, automated evaluation infrastructure, risk assessment, and cross-functional communication.
Leads and develops a security incident response team while driving automation, AI-assisted workflows, operational maturity, and response strategy. The role requires 5+ years of incident response experience, people leadership, technical depth, and calm management of high-severity incidents.
Own and operate Decagon’s privacy and GRC programs, including regulatory compliance, data governance, customer security engagements, audits, and cross-functional privacy initiatives. The role requires 5+ years of GRC experience, strong communication and project management skills, and familiarity with enterprise security controls.
The analyst develops and evaluates cyber product policies, enforcement guidance, controlled-access frameworks, and launch-review inputs for AI systems. The role requires strong policy writing, cybersecurity or platform-enforcement familiarity, technical security literacy, and cross-functional communication.
Manages Decagon’s governance, risk, and compliance program, including enterprise certifications, audit evidence, vendor risk, customer security assessments, and RFP responses. Requires 3–5 years of GRC experience, strong communication and project management skills, and familiarity with technical security controls and privacy regulations.