
Senior Security Engineer
Posted Jul 28

Posted Jul 28
This is a fully remote position, open to applicants in United States.
• Perform comprehensive security assessments of LiteLLM’s Python proxy, APIs, authentication systems, and enterprise functionalities.
• Discover and address vulnerabilities related to authentication, authorization, secrets management, tenant isolation, injection, and data exposure.
• Collaborate closely with engineers during the design, implementation, code review, and release phases—engaging with them throughout the process rather than only post-deployment.
• Integrate application security tools into the development lifecycle, encompassing SAST, DAST, dependency scanning, and secrets detection.
• Conduct internal red teaming and adversarial testing against LiteLLM’s APIs, proxy, and specific LLM attack vectors.
• Threat-model new products and architectural modifications prior to their production launch.
• Develop secure coding standards and provide training to engineers on prevalent vulnerabilities and defensive strategies.
• Fortify LiteLLM’s Docker images, PyPI packages, GitHub Actions workflows, and release infrastructure.
• Identify dependency confusion, poisoned packages, compromised dependencies, exposed secrets, and unsafe build methodologies.
• Implement SBOMs, signed builds, provenance checks, and practices for reproducible builds.
• Create secure-by-default configurations for both cloud and self-hosted deployments, focusing on authentication, IAM, secrets management, and key rotation.
• Assess cloud infrastructure, network boundaries, access controls, and production deployment strategies.
• Enhance identity verification, device security, SaaS, and internal access controls for employees.
• Develop monitoring and anomaly detection systems for suspicious API, model, authentication, and routing activities.
• Lead efforts in security incident response, vulnerability assessment, remediation, post-mortems, and stakeholder communication.
• Establish formal processes for vulnerability intake, CVE triage, disclosure, and remediation.
• Maintain threat models as LiteLLM’s product offerings and architecture progress.
• A proficient security generalist capable of working across application security, IT, CI/CD, cloud infrastructure, and the software supply chain.
• Extensive application security knowledge, including the manual auditing of production Python code and collaborating with engineers to resolve vulnerabilities.
• Strong grasp of authentication, authorization, tenant isolation, SSRF, injection, deserialization, secrets management, and prevalent web and API vulnerabilities.
• Experience in using and configuring tools like Semgrep, Bandit, CodeQL, Burp Suite, and other SAST or DAST tools.
• Previous tenure at an early-stage security startup during its formative 0→1 phase.
• Experience in securing containers, GitHub Actions, build pipelines, packages, and software dependencies.
• Familiarity with SBOMs, Sigstore, Cosign, Snyk, Grype, Trivy, or similar tools.
• Strong understanding of OAuth2, JWT, mTLS, IAM, and high-throughput API authentication.
• Familiarity with prompt injection, LLM data exfiltration, tool misuse, and the OWASP Top 10 for LLM Applications.
• Experience in incident response, CVSS scoring, vulnerability management, CVE triage, and coordinated disclosure.
• Participation in CTFs during academic years or independently engaging in vulnerability research, reverse engineering, bug bounties, or security projects.
• A genuine passion for security beyond your professional role—regularly exploring new attack techniques, developing security projects, or contributing to the security community.
• Bachelor’s or Master’s degree in Computer Science or a related discipline, or equivalent practical experience.
• Competitive salary along with health, dental, and vision benefits.
Legacy Community Health
NeoGuardian
Fresh Consulting
CrowdStrike
Get handpicked remote jobs straight to your inbox weekly.