Skip to content

Senior Infrastructure Security Engineer

190k – 290kUnited StatesSecurity EngineeringRemote9+ YOE
Summary

Senior security engineer focused on securing AI/agentic infrastructure, LLM/RAG systems, identity for non-human workloads, and cloud/K8s platforms. Requires 9+ years experience and strong scripting skills.

About the role

Responsibilities

  • Design, deploy, and operate security controls for Dropbox’s AI and agentic infrastructure, including model gateways, inference services, vector stores, retrieval systems, and supporting cloud and Kubernetes platforms.
  • Implement least-privilege and secure-execution patterns for AI agents, including per-tool authorization, sandboxing, human-in-the-loop approvals for high-impact actions, and separation of policy validation from execution.
  • Lead security implementation for AI tool and agent connectivity layers, including MCP gateway deployments, with controls for OAuth-based authorization, scope minimization, token audience validation, origin validation, replay protection, and secure isolation between trusted and untrusted tool domains.
  • Deploy, build, and/or operate security infrastructure solutions to help scale and raise the security bar for Dropbox’s on-prem and cloud infrastructure.
  • Automate security controls using scripting to eliminate redundant work and minimize need for human involvement.
  • Collaborate with cross functional teams and lead security initiatives to influence product decisions and enhance security posture.

Requirements

  • 9+ years of Security experience or related industry experience, demonstrating impactful contributions to security strategies.
  • Bachelor's degree in Computer Science, Information Security, or related field, or equivalent experience, with coding proficiency.
  • Experience securing LLM, RAG, or agentic AI systems in production, with hands-on implementation of controls for prompt injection, sensitive-data disclosure, excessive agency, data or model poisoning, and AI supply-chain risk.
  • Experience designing identity and authorization for non-human workloads and agents using technologies such as SPIFFE/SPIRE, OAuth 2.1 or OIDC, AWS IRSA, Google Workload Identity Federation, Azure managed identities, or equivalent patterns.
  • Integrate adversarial testing and release gates for AI systems into CI/CD, including regression coverage for prompt injection, tool abuse, memory poisoning, approval bypass, and multi-agent escalation scenarios.
  • Solid knowledge of Linux fundamentals including system administration, security, networking, scripting, and troubleshooting.
  • Proficiency using one or more scripting or high-level languages to automate tasks, manipulate data, or build small systems e.g. Bash, Python, Go, Rust, Ruby, NodeJS, C/C++, Java.

Preferred Qualifications

  • Experience securing MCP-based systems or similar AI agent and tool protocols.
  • Experience with multi-agent security controls such as trust boundaries, signed inter-agent messaging, and circuit breakers.
  • Familiarity with NIST AI RMF, NIST SP 800-218A, MITRE ATLAS, CSA AICM, and OWASP LLM and agentic security guidance.
  • Experience with security tools such as Teleport, CrowdStrike, Proofpoint, IPS/IDS, SIEM or SOAR.
  • Certifications such as CISSP, CISM, or equivalent.
Skills
LinuxPythonGoRustBashSPIFFE/SPIREOAuth 2.1OIDCAWS IRSAGoogle Workload Identity FederationAzure Managed IdentitiesKubernetesCI/CDSIEMSOAR
Similar roles at this salary range
All Security Engineering jobs →
DuckDuckGo

Senior Privacy Engineer

Lead privacy engineering projects protecting user data across search, browser, and AI features. Own major privacy components, participate in audits, and mentor engineers using Go, Node.js, Python, or Perl.

179k – 179kUnited StatesSecurity EngineeringRemote5+ YOEGoPerl
Doppel

Product Security Engineer

Product Security Engineer embedding into engineering workflows to conduct architecture reviews, threat modeling, and penetration testing coordination while serving as GCP security SME. Requires 5-7 years experience and strong GCP and Python skills.

175k – 200kUnited StatesSecurity EngineeringRemote5+ YOEGCPIAM
Instacart

Senior Product Security Engineer II

Senior security engineer focused on offensive security testing, penetration testing, and scaling security practices across Instacart's product suite. Requires 7+ years in security engineering or pentesting with experience in mobile, cloud, or AI security.

192k – 243kUnited StatesSecurity EngineeringRemote7+ YOEAI SecurityCloud Security
Crusoe

Staff Software Engineer, Security

Staff Security Software Engineer designing and building scalable security infrastructure, identity systems, and compliance automation platforms. Requires 8+ years software engineering experience with deep Kubernetes, Go/Rust, and cloud platform expertise.

215k – 260kSan Francisco, CASecurity EngineeringOn-site8+ YOEGoGCP
Crusoe

Senior Software Engineer, Security

Design, build, and deploy scalable security services, PKI, and secrets management platforms. Implement automation to eliminate manual security risk remediation across enterprise infrastructure.

175k – 210kSan Francisco, CASecurity EngineeringOn-site5+ YOEGoAWS