
Senior Staff Security Engineer
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in New York.
• Establish a secure architectural strategy across product and enterprise environments, emphasizing application security and AI/ML system security.
• Lead reviews of threat models for intricate services and AI systems, which include LLM-integrated products, agentic workflows, and model supply chains.
• Define and enhance the organization’s strategy for AI security.
• Contribute production code for product features and internal security tools.
• Serve as a technical escalation point across AppSec, cloud, identity, CI/CD, and AI domains.
• Promote and expand security coding initiatives utilizing infrastructure as code, detection as code, and associated projects.
• Mentor senior and staff-level engineers.
• Represent security in cross-functional and executive architectural discussions.
• Participate in an on-call rotation for 24/7 incident escalation support.
• A minimum of 12 years of experience in security engineering or a related discipline.
• At least 6 years of practical software engineering experience.
• Strong skills in developing and reviewing code in Python, Java, or Go.
• Extensive knowledge in application security, including secure SDLC integration, SAST/DAST/IAST tools, manual code review, and API security.
• Proven experience in securing AI systems, encompassing LLM application security, prompt injection defenses, data governance, secure usage of agentic tools, and emerging AI-specific threats.
• Demonstrated expertise in implementing AWS security services and best practices at scale across multi-account environments.
• Practical experience managing WAF platforms, including the development of custom rules.
• Experience with infrastructure as code using Terraform or Ansible, including secure module patterns and policy-as-code guardrails.
• Familiarity with OAuth, SAML, and OpenID Connect, along with identity architecture design.
• Profound understanding of secure CI/CD pipeline design and supply chain protection.
• A proven track record of influencing organizational security strategy and roadmap.
• Relevant certifications such as OSCP, OSWE, OSCE, or CISSP.
• Competitive base salary plus bonus.
• Full-time employment status.
• Details regarding benefits can be found at https://benefitsatfanatics.com/.
• Remote work options available.
• Potential for participation in Launching into Better: LIVE cultural immersion for full-time, non-seasonal hires.
OCHIN, Inc.
Dynanet Corporation
Solutions for Information Design, Inc.
Fuze Health
Get handpicked remote jobs straight to your inbox weekly.