Dropbox

Senior Infrastructure Security Engineer

Dropbox$214K — $289K *
US-AnywhereRemote in United States
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 9+ years of security experience or equivalent in a related field, showcasing significant contributions to security strategies.
  • Bachelor's degree in Computer Science, Information Security, or related field, or equivalent experience, with coding proficiency.
  • Hands-on experience securing AI systems in production, particularly in relation to prompt injection and sensitive-data disclosure.
  • Familiarity with identity and authorization frameworks for non-human agents, including technologies like SPIFFE/SPIRE and OAuth.
  • Proficient in integrating adversarial testing into CI/CD for AI systems to ensure security compliance.
  • Strong foundational knowledge of Linux for administration and security tasks.
  • Ability to script in languages like Bash, Python, or Go to automate processes.

Responsibilities

  • Design, deploy, and operate security controls for Dropbox’s AI infrastructure.
  • Implement secure-execution patterns for AI agents with stringent authorization measures.
  • Lead security implementation for AI tool connectivity layers, focusing on OAuth and validation controls.
  • Deploy and operate security infrastructure solutions across Dropbox’s cloud and on-prem systems.
  • Automate security controls to improve efficiency and reduce manual tasks.
  • Collaborate with cross-functional teams to drive security initiatives and influence product decisions.

Benefits

  • Engagement in an innovative, collaborative environment that promotes security growth.
  • Opportunity to work on high-impact security projects.
  • Access to resources that enhance professional development within the company.
Full Job Description
Role Description

As a Security Engineer, you'll safeguard our digital ecosystem alongside a diverse team of professionals dedicated to protecting our products and users. Trusted by millions, our mission is to integrate security seamlessly into Dropbox, empowering confident collaboration. Join us in owning a range of security projects, fostering innovation and growth in a collaborative environment.

Our Engineering Career Framework is viewable by anyone outside the company and describes what's expected for our engineers at each of our career levels. Check out our blog post on this topic and more here.

Responsibilities
  • Design, deploy, and operate security controls for Dropbox's AI and agentic infrastructure, including model gateways, inference services, vector stores, retrieval systems, and supporting cloud and Kubernetes platforms.
  • Implement least-privilege and secure-execution patterns for AI agents, including per-tool authorization, sandboxing, human-in-the-loop approvals for high-impact actions, and separation of policy validation from execution.
  • Lead security implementation for AI tool and agent connectivity layers, including MCP gateway deployments, with controls for OAuth-based authorization, scope minimization, token audience validation, origin validation, replay protection, and secure isolation between trusted and untrusted tool domains.
  • Deploy, build, and/or operate security infrastructure solutions to help scale and raise the security bar for Dropbox's on-prem and cloud infrastructure.
  • Automate security controls using scripting to eliminate redundant work and minimize need for human involvement.
  • Collaborate with cross functional teams and lead security initiatives to influence product decisions and enhance security posture.

Many teams at Dropbox run Services with on-call rotations, which entails being available for calls during both core and non-core business hours. If a team has an on-call rotation, all engineers on the team are expected to participate in the rotation as part of their employment. Applicants are encouraged to ask for more details of the rotations to which the applicant is applying.
Requirements
  • 9+ years of Security experience or related industry experience, demonstrating impactful contributions to security strategies.
  • Bachelor's degree in Computer Science, Information Security, or related field, or equivalent experience, with coding proficiency.
  • Experience securing LLM, RAG, or agentic AI systems in production, with hands-on implementation of controls for prompt injection, sensitive-data disclosure, excessive agency, data or model poisoning, and AI supply-chain risk.
  • Experience designing identity and authorization for non-human workloads and agents using technologies such as SPIFFE/SPIRE, OAuth 2.1 or OIDC, AWS IRSA, Google Workload Identity Federation, Azure managed identities, or equivalent patterns.
  • Integrate adversarial testing and release gates for AI systems into CI/CD, including regression coverage for prompt injection, tool abuse, memory poisoning, approval bypass, and multi-agent escalation scenarios.
  • Solid knowledge of Linux fundamentals including system administration, security, networking, scripting, and troubleshooting.
  • Proficiency using one or more scripting or high-level languages to automate tasks, manipulate data, or build small systems e.g. Bash, Python, Go, Rust, Ruby, NodeJS, C/C++, Java.
Preferred Qualifications
  • Experience securing MCP-based systems or similar AI agent and tool protocols.
  • Experience with multi-agent security controls such as trust boundaries, signed inter-agent messaging, and circuit breakers.
  • Familiarity with NIST AI RMF, NIST SP 800-218A, MITRE ATLAS, CSA AICM, and OWASP LLM and agentic security guidance.
  • Experience with security tools such as Teleport, CrowdStrike, Proofpoint, IPS/IDS, SIEM or SOAR.
  • Certifications such as CISSP, CISM, or equivalent.
Compensation

US Zone 1

This role is not available in Zone 1

US Zone 2

$214,200-$289,800 USD

US Zone 3

$190,400-$257,600 USD

About Dropbox

Dropbox is a publicly traded cloud storage and file sharing services company headquartered in San Francisco, California. Founded in 2007, Dropbox provides cloud storage, file synchronization, personal cloud, and client software. The company's cloud storage allows users to store and share files, photos, and videos. Dropbox has over 700 million registered users across 180 countries. The company has additional offices in New York City, Dublin, London, Paris, Sydney, and Tokyo.
Learn more about Dropbox
Size
2,667 employees
Market Cap
$8 billion
Industry
Net Income
-$256.3 million
Founded
2007
5 Year Trend
+20.6%
Revenue
$1.9 billion
NASDAQ

Similar Jobs

More Jobs at Dropbox

More Information Technology Jobs

Find similar Senior Infrastructure Security Engineer jobs: