Remotery

Senior Security Engineer

Posted Jul 28

This is a fully remote position, open to applicants in United States.

đź“‹ Description

• Perform comprehensive security assessments of LiteLLM’s Python proxy, APIs, authentication systems, and enterprise functionalities.

• Discover and address vulnerabilities related to authentication, authorization, secrets management, tenant isolation, injection, and data exposure.

• Collaborate closely with engineers during the design, implementation, code review, and release phases—engaging with them throughout the process rather than only post-deployment.

• Integrate application security tools into the development lifecycle, encompassing SAST, DAST, dependency scanning, and secrets detection.

• Conduct internal red teaming and adversarial testing against LiteLLM’s APIs, proxy, and specific LLM attack vectors.

• Threat-model new products and architectural modifications prior to their production launch.

• Develop secure coding standards and provide training to engineers on prevalent vulnerabilities and defensive strategies.

• Fortify LiteLLM’s Docker images, PyPI packages, GitHub Actions workflows, and release infrastructure.

• Identify dependency confusion, poisoned packages, compromised dependencies, exposed secrets, and unsafe build methodologies.

• Implement SBOMs, signed builds, provenance checks, and practices for reproducible builds.

• Create secure-by-default configurations for both cloud and self-hosted deployments, focusing on authentication, IAM, secrets management, and key rotation.

• Assess cloud infrastructure, network boundaries, access controls, and production deployment strategies.

• Enhance identity verification, device security, SaaS, and internal access controls for employees.

• Develop monitoring and anomaly detection systems for suspicious API, model, authentication, and routing activities.

• Lead efforts in security incident response, vulnerability assessment, remediation, post-mortems, and stakeholder communication.

• Establish formal processes for vulnerability intake, CVE triage, disclosure, and remediation.

• Maintain threat models as LiteLLM’s product offerings and architecture progress.


⛳️ Requirements

• A proficient security generalist capable of working across application security, IT, CI/CD, cloud infrastructure, and the software supply chain.

• Extensive application security knowledge, including the manual auditing of production Python code and collaborating with engineers to resolve vulnerabilities.

• Strong grasp of authentication, authorization, tenant isolation, SSRF, injection, deserialization, secrets management, and prevalent web and API vulnerabilities.

• Experience in using and configuring tools like Semgrep, Bandit, CodeQL, Burp Suite, and other SAST or DAST tools.

• Previous tenure at an early-stage security startup during its formative 0→1 phase.

• Experience in securing containers, GitHub Actions, build pipelines, packages, and software dependencies.

• Familiarity with SBOMs, Sigstore, Cosign, Snyk, Grype, Trivy, or similar tools.

• Strong understanding of OAuth2, JWT, mTLS, IAM, and high-throughput API authentication.

• Familiarity with prompt injection, LLM data exfiltration, tool misuse, and the OWASP Top 10 for LLM Applications.

• Experience in incident response, CVSS scoring, vulnerability management, CVE triage, and coordinated disclosure.

• Participation in CTFs during academic years or independently engaging in vulnerability research, reverse engineering, bug bounties, or security projects.

• A genuine passion for security beyond your professional role—regularly exploring new attack techniques, developing security projects, or contributing to the security community.

• Bachelor’s or Master’s degree in Computer Science or a related discipline, or equivalent practical experience.


🏝️ Benefits

• Competitive salary along with health, dental, and vision benefits.

People also viewed

Legacy Community Health1 day ago

IT Security Engineer

US flagTexas OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
NeoGuardian1 day ago

Cyber Security Engineer I – Blue Team

BR flagBrazil OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Fresh Consulting1 day ago

Staff Software Engineer – Security, Cryptography

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
CrowdStrike1 day ago

Staff AI Security Scientist

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$235k – $350k/year
ApplyView job
CrowdStrike1 day ago

Security Advisor, Falcon Complete

AU flagAustralia OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Supply Chimp1 day ago

Cybersecurity Specialist

PH flagPhilippines OnlyFull-timeCybersecurity / Security EngineerPHP 62.5k/month
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers