Senior Security Engineer, Incident Response
Leads product security incident response for Snowflake’s AI and agentic products, developing detection, containment, remediation, and automation capabilities. Requires 5+ years in security, incident command experience, cloud expertise, and knowledge of AI/ML attack surfaces.
About the job
Responsibilities
- Lead incident response for product-level security events, focusing on AI-specific threats such as prompt injection, model abuse, agent hijacking, and data exfiltration through AI workloads.
- Integrate incident response into AI product pipelines across Cortex AI, Cortex Agents, Snowflake Intelligence, and AI-powered developer experiences.
- Define detection, containment, and remediation playbooks for LLM misuse, adversarial inputs, and AI-assisted attacks.
- Ensure Cortex and agentic architectures meet incident-response readiness requirements.
- Represent incident response across cloud engineering, AI platform, corporate security, and customer-facing teams.
- Secure AI-native codebases across multi-cloud environments, including containerized inference services, RAG pipelines, vector stores, and agent orchestration layers.
- Guide secure architecture for AI features and customer-facing AI capabilities.
- Build and manage response capabilities across model-serving endpoints, Cortex Search indexes, and Snowpark ML pipelines.
- Develop automation and tooling to accelerate detection and response for product security incidents.
Requirements
- 5+ years of experience in information security, incident response, security engineering, or product/application security.
- Experience serving as incident commander for product-focused security incidents.
- Experience building or leading an application or security engineering program, with a perspective on securing AI/ML systems.
- Experience with threat modeling and security testing across AI attack surfaces, including prompt injection, indirect injection, model inversion, embedding extraction, and AI dependency supply-chain attacks.
- Familiarity with data governance and security challenges involving LLMs, RAG architectures, and agentic systems.
- Working knowledge of AWS, Azure, and GCP, plus SaaS and AI platform threats.
- SQL proficiency and experience building automation with programming languages, preferably Python.
- Strong communication skills and ability to translate security risks into actionable product guidance.
- Bachelor's degree in Computer Science or a related field, or equivalent experience.
Nice-to-haves
- Experience securing AI/ML infrastructure, including model serving, vector databases, embedding pipelines, API gateways, and LLM-integrated applications.
- Experience building agentic incident-response capabilities, including skills, agents, and pipelines.
- Understanding of attacker TTPs, adversarial ML, agent manipulation, and LLM jailbreaking.
- Familiarity with CI/CD and secure release lifecycle patterns for AI feature pipelines.
- GCIA, GCIH, GCSA, GDAT, CISSP, GISP, AWS, Azure, or GCP certifications.
Skills
Incident Response, Ai Security, Threat Modeling, Security Testing, Prompt Injection, Llm Security, RAG, AWS, Azure, GCP, SQL, Python, Kubernetes, Vector Databases, CI/CD
Similar jobs
Security Engineering jobsLeads product security incident response for Snowflake’s AI products and infrastructure, developing detection, containment, and remediation capabilities for LLM and agentic threats. Requires 5+ years in security, incident command experience, cloud-native expertise, and strong knowledge of AI attack surfaces.
Leads security risk identification, prioritization, and remediation across an infrastructure organization while building a security program and advising technical leaders. Requires a bachelor’s degree, 8+ years of software or infrastructure engineering experience, and substantial security experience.
Own and scale Starburst’s application and product security program through secure-by-default engineering, automated vulnerability management, threat modeling, and autonomous offensive testing. The role requires 5–7 years of security-focused experience, strong software supply chain expertise, and the ability to engage enterprise customers and lead engineers.
The Senior Security Engineer will secure Jasper’s AI systems, cloud infrastructure, software supply chain, and compliance workflows while building automation and security standards for a growing program. The role requires 8+ years of security engineering experience and hands-on expertise across AI, cloud, or GRC security.
Own and scale Jasper’s governance, risk, and compliance program for AI-native SaaS products, leading audits, risk and vendor programs, policy management, and AI governance. The role requires 8+ years of GRC experience, expertise in major security frameworks, cloud and AI fluency, and strong cross-functional communication.