The Role:We're looking for a Security Engineer to join our AI Platform Security team. It is a high-ownership, low-oversight role for an application/product security generalist who has already done the work and is ready to set direction rather than follow it. You'll own security outcomes for a portfolio of products, define how security reviews and standards operate across the organization, and build the tooling and programs that let a lean team cover a large surface area.
We are a lean, high-trust team. You'll make real risk calls, push back on engineering leadership when the data supports it, and be accountable for the areas you own while helping to shape how this team operates as it scales.
What You'll Do:- Own end-to-end security for an assigned portfolio of products: design reviews, threat modeling, risk acceptance, and driving high-severity findings to closure
- Set technical direction for your program areas: define the review bar, standards, checklists, and intake processes other engineers follow
- Lead vulnerability management and the bug bounty program: complex triage, escalation, researcher relations, SLA ownership, and program evolution
- Design and build security automation and internal tooling that removes manual toil and scales coverage beyond headcount
- Drive shift-left adoption across the SDLC through pipeline gates, guardrails, paved-path patterns, and developer enablement
- Lead the team's AI/LLM security practice: assessment methodology, testing approach, and applied frameworks for agentic and model-backed features
- Communicate risk and program health to engineering and executive leadership through metrics, reporting, and clear written narratives
Who We're Looking For:- Experience in security engineering, application security, offensive security, or a closely related technical discipline
- Deep, demonstrated knowledge of vulnerability classes and exploitation: injection, authentication and session flaws, access control, deserialization, SSRF, and their real-world variants
- Ability to read, review, and write code in at least one language (Python, JavaScript/TypeScript, Go, or Java), and to reason about unfamiliar codebases quickly
- Track record of owning a security program area independently and driving cross-functional remediation without formal authority
- Experience threat modeling non-trivial systems and translating findings into decisions engineering teams will actually act on
- Excellent written communication. You will produce standards, risk narratives, executive reporting, and researcher-facing correspondence
- Comfort operating with ambiguity and building structure where none exists yet
Preferred: - Experience running or substantially maturing a bug bounty or vulnerability disclosure program
- Hands-on depth with security tooling such as Snyk, Burp Suite, DAST, or SAST platforms, including tuning and integration rather than just usage
- Demonstrated ability to build security automation or internal tooling used by others
- Applied understanding of AI/LLM security risks: prompt injection, insecure tool use, context and data leakage, model supply chain
- Prior mentorship, tech lead, or team lead experience
- Bug bounty participation as a researcher, published research, or CVE credit