Staff+ Application Security Engineer
Core
Building security into the software development lifecycle for AI/ML products and internal tools, focusing on threat modeling, secure design, and vulnerability management.
Role type
Staff+ Application Security Engineer (AI/ML focus)
Builds
Security tooling, detection capabilities, and automated systems for secure code review and vulnerability remediation.
Domain
AI/ML security, cloud infrastructure, and software development lifecycle
Deliverable
production ML models | product features | infrastructure
Required skills
Threat modeling, secure design reviews, vulnerability management, bug bounty program management, secure coding practices, cloud security (Kubernetes, Docker, AWS/GCP), offensive security techniques, AI/ML security risks (prompt injection, data poisoning), security tool development
Preferred skills
Experience with microservices architectures, red team exercises, building security applications, distilling complex security concepts
Technologies
Python, Rust, Go, Java, Kubernetes, Docker, AWS, GCP
Responsibilities
Lead shift-left security efforts, conduct secure design reviews and threat modeling, develop tooling to scale security code reviews, manage vulnerability management program, oversee bug bounty program, collaborate with engineers to instill security best practices, develop security policies and conduct training
Seniority
Staff+, hands-on IC with strategic influence