CareerPlanSign in

Staff Product Security Engineer - AI Systems

Ontario, Canada - Remote🌐 Remote💼 Full-time🗓 2026-09-01 → 2026-09-29

Core

Define and build the security architecture for Theo, an AI research platform combining models, agentic workflows, code execution, and multi-tenant SaaS infrastructure.

Role type

Staff Product Security Engineer (AI Systems)

Builds

Secure-by-default services, libraries, policies, test harnesses, and platform controls for identity, secrets, encryption, policy enforcement, auditability, and vulnerability management.

Domain

AI/ML security, Cloud Security, SaaS Security, Agentic Systems

Required skills

Product security, application security, cloud security, offensive security, secure software engineering, threat modelling, secure code review, penetration testing, vulnerability remediation, architecture review, attacker-informed mindset, influence without authority

Preferred skills

LLM application security, agentic systems security, RAG security, tool use security, MCP integrations, secure sandbox design, delegated authorization systems, machine identity management, fine-grained policy enforcement, model training/inference security, GPU/Kubernetes infrastructure security, SOC 2/FedRAMP/NIST implementation, vulnerability research, bug bounty experience

Technologies

Python, Go, Rust, TypeScript, Kubernetes, CI/CD, Infrastructure as Code, SAST, DAST, SBOM, artifact provenance, automated security regression testing

Responsibilities

Define security architecture for SaaS applications, APIs, cloud infrastructure, model-serving systems, agent runtimes, and deployment pipelines; Secure agent identity and authority including scoped credentials and tenant isolation; Design hardened execution environments for agent-generated code; Lead threat modelling and secure design reviews; Address AI-specific threats like prompt injection, goal injection, and model exfiltration; Build security-critical software and integrate security scanning into workflows; Conduct adversarial testing including red-team and purple-team exercises; Own vulnerabilities through direct remediation and architectural changes; Protect AI assets including model weights and datasets; Engineer compliance into the product; Raise engineering security capability through mentorship and pattern establishment

Sourced via ashby · Listed on CareerPlan, which tracks 849,000+ jobs from 20+ sources.