Skip to content
DecagonDecagon

Security Engineer

Build and scale security foundations for Decagon's AI customer experience platform, implementing controls, tooling, detection pipelines, and partnering with engineering teams. Requires 3+ years security engineering with strong coding skills and cloud experience, ideally Google Cloud; onsite in San Francisco.

About the job

Responsibilities

  • Implement security controls across our agent platform, covering application security, infrastructure security
  • Build security tooling and automation, including automated remediation pipelines, detection systems, and testing frameworks integrated into CI/CD workflows
  • Partner with engineering teams to design and review authentication systems, secrets management, and access controls
  • Create detection pipelines that scale with millions of daily AI agent interactions
  • Contribute to security incidents affecting operations, supporting rapid resolution while maintaining service availability

Requirements

  • 3+ years of experience in security engineering, with strong software engineering fundamentals
  • Familiarity with application security concepts including authentication, authorization, vulnerability assessment, and secure development practices
  • Ability to write production-quality code; you can build the tools and automation the team needs, not just identify problems
  • Experience with cloud security fundamentals, ideally Google Cloud
  • Exposure to enterprise security requirements such as SOC 2, ISO 27001, or GDPR
  • Natural curiosity about new technologies and approaches to security problems

Nice-to-Haves

  • Experience building developer tools, security automation, or remediation pipelines
  • Background with static analysis tools (Semgrep, CodeQL) or vulnerability management platforms
  • Familiarity with securing AI/ML applications, including awareness of risks like prompt injection and adversarial inputs
  • Experience with infrastructure as code (Terraform) and modern cloud development practices
  • Comfortable working across the entire stack to solve problems

Compensation

$200K – $330K + Equity

Skills

GCP, Terraform, Semgrep, Codeql, CI/CD, SOC 2, ISO 27001, GDPR, Authentication, Authorization

OpenAI

OpenAI

San Francisco, CA
Red Team Specialist - Cyber
$198k+/yrHybridSecurity Engineering

The Red Team Specialist evaluates AI models for cyber capabilities, safeguard failures, and agentic-system abuse risks. The role combines hands-on security testing, automated evaluation infrastructure, risk assessment, and cross-functional communication.

Vercel

Vercel

San Francisco, CA
Software Engineer, Trust & Safety
$196k+/yrHybrid5+ YOESecurity Engineering

Build and operate trust and safety systems that detect and mitigate abuse at internet scale. The role combines security engineering, large-scale data analysis, and applied LLM techniques, requiring 5+ years of relevant experience and strong Python and JavaScript/TypeScript skills.

1Password

1Password

United States
Manager, Security Incident Response
$192k+/yrRemote5+ YOESecurity Engineering

Leads and develops a security incident response team while driving automation, AI-assisted workflows, operational maturity, and response strategy. The role requires 5+ years of incident response experience, people leadership, technical depth, and calm management of high-severity incidents.

Decagon

Decagon

San Francisco, CA

Governance, Risk, and Compliance Manager - Privacy
$190k+/yrOn-site5+ YOESecurity Engineering

Own and operate Decagon’s privacy and GRC programs, including regulatory compliance, data governance, customer security engagements, audits, and cross-functional privacy initiatives. The role requires 5+ years of GRC experience, strong communication and project management skills, and familiarity with enterprise security controls.

Anthropic

Anthropic

San Francisco, CA
Safeguards Policy Analyst, Cyber Harms
$190k+/yrHybridSecurity Engineering

The analyst develops and evaluates cyber product policies, enforcement guidance, controlled-access frameworks, and launch-review inputs for AI systems. The role requires strong policy writing, cybersecurity or platform-enforcement familiarity, technical security literacy, and cross-functional communication.