Skip to content
StackAIStackAISan Francisco, CA

Product Security Engineer

Hands-on Product Security Engineer owning encryption, key management, data protection, and secure-by-default practices for StackAI's no-code AI workflow platform. Requires 4+ years building security-critical production systems with deep cryptography and secure architecture experience.

248k – 282k/yr
Hybrid4+ YOESecurity Engineering

About the role

What you'll do

  • Own encryption and signing: Take ownership of our KMS, key management, BYOK, envelope encryption, and signing pipeline across both cloud and on-prem deployments—operating, hardening, and evolving them as the platform scales.
  • Protect the most sensitive customer data: Extend our PHI/PII scrubbing and strengthen the data-protection foundations that regulated enterprises already rely on.
  • Secure the storage layer: Own encryption at rest and tenant isolation.
  • Keep security the default in how we ship: Maintain and expand the secure-by-default templates and reference implementations embedded in our SDLC—the ones engineers actually want to adopt.
  • Threat-model the platform: Lead threat modeling on the seams between systems (the execution engine, connector trust boundaries, and multi-tenant isolation), using modern, AI-assisted threat-modeling tooling.
  • Raise the bar on tooling: Push our scanning further on coverage, signal, and CI enforcement, so critical findings never reach production.
  • Be the technical point of contact for security standards: Translate audit, compliance, and incident-response requirements into real implementation in our codebase.

What we're looking for

  • 4+ years building security-critical systems in production, with significant time spent implementing, not only reviewing or assessing.
  • Practical depth in cryptography and key management: encryption, KMS, secrets handling, and signing in real systems.
  • Secure architecture judgment: you can design and reason about secure systems and hold your own as a technical peer with senior engineers.
  • Multi-tenant SaaS isolation experience, including the data-isolation guarantees regulated customers require.
  • Strong secure-coding skills in our stack: Python on the backend, TypeScript/Node.js on the product surfaces.
  • Comfortable wiring security checks and gates into CI/CD so security is enforced automatically in the pipeline.

Security engineering is broad. If you're strong on most of this and excited to grow into the rest, we'd like to hear from you, even if you don't check every box.

Bonus points

  • Cloud and API security fundamentals on GCP, Azure, or AWS.
  • Securing on-prem, self-hosted, or air-gapped deployments.
  • Experience in regulated domains (healthcare/PHI, finance, etc.).
  • Familiarity with AI/LLM platform security: agent execution, connector trust boundaries, prompt and tool-call risk.
  • Startup or growth-stage experience.

Skills

Cryptographykey managementkmsencryptionbyokmulti-tenant isolationPythonTypeScriptNode.jsCI/CDThreat ModelingGCPAWSAzure
Perplexity

Offensive Security Engineer

PerplexitySan Francisco, CA +1

Offensive Security Engineer conducts red team operations, penetration testing, and AI/ML attack simulations on cloud infrastructure, applications, and pipelines. Requires 5+ years experience in offensive security, expertise in cloud/web/K8s security, and custom tooling in Python/Go.

250k – 350k/yr
Hybrid5+ YOESecurity Engineering
Anthropic

Safeguards Enforcement Analyst, Account Takeover & Credential Abuse

AnthropicSan Francisco, CA +2

Safeguards Enforcement Analyst focused on account takeover and credential abuse. Investigate compromise incidents, design remediation workflows, partner with engineering on detection, enforce AI usage policies, and develop scalable enforcement programs for platform safety.

245k – 285k/yr
HybridSecurity Engineering
Anthropic

Third Party Risk Analyst, Security GRC

AnthropicSan Francisco, CA

Own and manage Anthropic's highest-risk and mission-critical third-party vendor portfolios within Security GRC. Conduct risk assessments, drive remediation and treatment plans, tune an LLM-based risk agent, and ensure business continuity for critical compute and data vendors.

255k – 270k/yr
Hybrid5+ YOESecurity Engineering
Ramp

Security Engineer, Product

RampNew York, NY +1

Builds security primitives, platform mitigations, and leads vulnerability remediation for Ramp's financial platform. Partners with engineers for secure-by-design solutions. Requires 5+ years software experience, 2+ years in security/infrastructure.

258k – 355k/yr
Hybrid5+ YOESecurity Engineering
Scale AI

Security Engineer, Detection & Response

Scale AINew York, NY +3

Senior Security Engineer focused on building detection systems, incident response automation, and maturing telemetry pipelines across cloud environments. Requires 5+ years in detection engineering or security operations and production-grade coding skills.

238k – 297k/yr
On-site5+ YOESecurity Engineering