Conduct original research on AI security, privacy, and threat modeling for frontier intelligence systems. Translate advances into practical defenses, publish at top venues, and partner with engineering to ship hardened features. Requires PhD and publications in security conferences.
220k – 405k/yr
On-siteSecurity Engineering
About the role
Responsibilities
Develop threat models for emerging attack surfaces in AI-native products, including browser, search, and autonomous agents.
Identify and analyze security and privacy threats across AI systems, infrastructure, and user-facing products.
Develop novel defenses, mitigations, and detection mechanisms for security and privacy in AI-native products.
Build security evaluation frameworks, benchmarks, and datasets to measure the effectiveness of different defense mechanisms.
Partner with Perplexity’s Security Engineering team to translate state of the art research into shipped security features and hardened system architectures.
Collaborate with top-tier academic and industry researchers in SII's external research network.
Publish findings at premier venues and contribute to the broader security research community.
Qualifications
Hold a PhD (or equivalent research experience) in Computer Science, Computer Engineering, or a related field, with a primary focus on security and/or privacy.
Experience publishing at top security conferences (IEEE S&P, USENIX Security, ACM CCS, NDSS) demonstrating original, impactful research contributions.
Deep expertise in one or more of: security of agentic systems, systems security, web and applications security, program analysis, and software security.
Proficiency in Python (bonus points for TypeScript, Go, and/or Rust).
Ability to operate with high independence, willing to dive in and take ownership, and comfortable in a fast-paced environment where research directly informs product.
Clear and concise communication, translating complex attack narratives into actionable insights for engineering and leadership.
Skills
ai securityThreat Modelingsystems securityweb securityprogram analysissoftware securityPythonTypeScriptGoRustbenchmarkingai privacy
Staff Corporate Security Engineer building and governing security for enterprise SaaS integrations, API data flows, and eDiscovery/legal hold programs at a rapidly scaling AI company. Requires strong security engineering and software development skills (Python/Go, IaC) plus experience with corporate IT systems and litigation readiness.
220k – 330k/yrHybrid7+ YOESecurity Engineering
Staff Security Engineer
Pomelo CareSan Francisco, CA +1
Staff Security Engineer who owns security problems end-to-end by identifying real risks, building direct controls, secure-by-default libraries, guardrails, and tooling. Requires 7+ years software engineering experience plus deep security expertise in threat modeling, auth, OWASP, cloud, and supply chain security. Healthcare/HIPAA/HITRUST and GCP experience preferred.
220k – 260k/yrRemote7+ YOESecurity Engineering
Staff Engineer, Security
Grow TherapyNew York, NY +2
Lead security engineering as the most senior hands-on engineer, shaping multi-year roadmap and building secure-by-default infrastructure including auth, data security, and vulnerability management.
220k – 240k/yrRemote7+ YOESecurity Engineering
Staff Software Engineer - Security
SkydioSan Mateo, CA
As a Staff Software Engineer - Security, you will design, review, and build systems to secure Skydio's cloud and corporate environments. You will partner with cross-functional teams on architectural decisions and build internal security tooling, playing a key role in protecting commercial, government, and DoD customers.
220k – 270k/yrHybrid7+ YOESecurity Engineering
Staff Software Engineer, Product Security
HarveySan Francisco, CA +1
Staff Software Engineer builds security into AI platform, owns product security roadmap, reviews critical code like authentication/access control, leads cross-functional initiatives, and mentors engineers on secure practices. Requires 8+ years in product/application/offensive security with proven vulnerability remediation track record.