ThoughtSpot

Senior Security Engineer

ThoughtSpot • $120K — $145K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5-7 years of experience in security engineering or related field
  • Strong understanding of various vulnerability classes and exploitation methods
  • Proficient in at least one programming language (e.g., Python, JavaScript, Go)
  • Proven track record of independently managing security program areas
  • Experience in threat modeling and actionable risk translation for engineering teams
  • Excellent written communication skills for standards and reporting
  • Ability to navigate ambiguity and create order

Responsibilities

  • Own the full security lifecycle for assigned products including design and threat modeling
  • Set the technical standards and review processes for the security program
  • Lead vulnerability management and oversee the bug bounty program
  • Develop security automation and tools to enhance operational efficiency
  • Promote early security integration within the software development lifecycle
  • Establish security practices for AI/LLM technologies including risk assessment
  • Report on program health and risks to engineering and executive teams

Benefits

  • Flexible work environment with a high-trust culture
  • Opportunity to influence direction rather than just follow it
  • Engagement with cutting-edge AI security practices
  • Autonomy in decision-making and project ownership
  • Diverse and lean team structure promoting collaboration
Full Job Description
The Role:

We're looking for a Security Engineer to join our AI Platform Security team. It is a high-ownership, low-oversight role for an application/product security generalist who has already done the work and is ready to set direction rather than follow it. You'll own security outcomes for a portfolio of products, define how security reviews and standards operate across the organization, and build the tooling and programs that let a lean team cover a large surface area.

We are a lean, high-trust team. You'll make real risk calls, push back on engineering leadership when the data supports it, and be accountable for the areas you own while helping to shape how this team operates as it scales.

What You'll Do:
  • Own end-to-end security for an assigned portfolio of products: design reviews, threat modeling, risk acceptance, and driving high-severity findings to closure
  • Set technical direction for your program areas: define the review bar, standards, checklists, and intake processes other engineers follow
  • Lead vulnerability management and the bug bounty program: complex triage, escalation, researcher relations, SLA ownership, and program evolution
  • Design and build security automation and internal tooling that removes manual toil and scales coverage beyond headcount
  • Drive shift-left adoption across the SDLC through pipeline gates, guardrails, paved-path patterns, and developer enablement
  • Lead the team's AI/LLM security practice: assessment methodology, testing approach, and applied frameworks for agentic and model-backed features
  • Communicate risk and program health to engineering and executive leadership through metrics, reporting, and clear written narratives


Who We're Looking For:

  • Experience in security engineering, application security, offensive security, or a closely related technical discipline
  • Deep, demonstrated knowledge of vulnerability classes and exploitation: injection, authentication and session flaws, access control, deserialization, SSRF, and their real-world variants
  • Ability to read, review, and write code in at least one language (Python, JavaScript/TypeScript, Go, or Java), and to reason about unfamiliar codebases quickly
  • Track record of owning a security program area independently and driving cross-functional remediation without formal authority
  • Experience threat modeling non-trivial systems and translating findings into decisions engineering teams will actually act on
  • Excellent written communication. You will produce standards, risk narratives, executive reporting, and researcher-facing correspondence
  • Comfort operating with ambiguity and building structure where none exists yet


Preferred:

  • Experience running or substantially maturing a bug bounty or vulnerability disclosure program
  • Hands-on depth with security tooling such as Snyk, Burp Suite, DAST, or SAST platforms, including tuning and integration rather than just usage
  • Demonstrated ability to build security automation or internal tooling used by others
  • Applied understanding of AI/LLM security risks: prompt injection, insecure tool use, context and data leakage, model supply chain
  • Prior mentorship, tech lead, or team lead experience
  • Bug bounty participation as a researcher, published research, or CVE credit

About ThoughtSpot

ThoughtSpot is a business intelligence and big data analytics platform that helps businesses make better decisions by providing them with insights from their data. The company was founded in 2012 by a group of former Google engineers and has since grown to become a leader in the industry. ThoughtSpot's platform is designed to be easy to use and allows users to search and analyze their data in real-time, without the need for complex queries or programming skills. The company has received numerous awards and recognition for its innovative technology and has been named a Gartner Cool Vendor in Analytics and Business Intelligence.
Learn more about ThoughtSpot
Size
1,000 employees
Industry
Founded
2012

Similar Jobs

More Jobs at ThoughtSpot

More Information Technology Jobs

Find similar Senior Security Engineer jobs: