
Staff Product Security Engineer – AI Systems
Posted Aug 27

Posted Aug 27
This is a fully remote position, open to applicants in Canada.
• Define the security architecture for Theo's SaaS application, APIs, cloud infrastructure, model-serving systems, agent runtimes, data platforms, research environments, and deployment pipelines.
• Develop authentication and authorization mechanisms for users, services, and AI agents, including scoped credentials, delegated permissions, least-privilege access, tenant isolation, and auditable actions.
• Design secure execution environments for agent-generated and user-provided code, ensuring isolation, resource limits, filesystem and network controls, provenance, monitoring, and escape testing.
• Lead threat modeling and secure design initiatives across Engineering, Research, Product, and Infrastructure from architecture to production.
• Safeguard against AI- and agent-specific threats, including prompt injection, unsafe tool usage, confused-deputy behavior, poisoning, exfiltration, model extraction, privilege escalation, and resource abuse.
• Create secure-by-default services, libraries, policies, test harnesses, and platform controls for identity, secrets, encryption, policy enforcement, auditability, abuse prevention, and vulnerability management.
• Integrate SAST, DAST, dependency, container, infrastructure-as-code, secret, and software supply-chain scanning into development and release workflows.
• Establish security reviews, release controls, SBOMs, artifact provenance, and automated security regression testing.
• Conduct penetration tests, red-team and purple-team exercises, architecture attacks, and abuse-case testing.
• Evaluate vulnerabilities, coordinate remediation with engineers, validate fixes, and eliminate recurring weaknesses.
• Protect model weights, training and evaluation data, datasets, embeddings, registries, research artifacts, GPU infrastructure, and software supply chains.
• Define telemetry, alerting, containment, and forensic capabilities for incidents involving users, services, agents, models, and data.
• Translate SOC 2 and customer security requirements into technical controls and support FedRAMP and NIST SP 800-53 readiness.
• Automate evidence collection and control validation.
• Mentor engineers, establish reusable patterns, document architectural decisions, and communicate risks to technical teams and leadership.
• Within the first year, establish a clear risk-based security architecture, explicit controls and adversarial coverage, secure-by-default workflows, integrated testing, remediation ownership, and a technical path toward FedRAMP readiness.
• 7+ years of experience in product security, application security, cloud security, offensive security, or security-focused software engineering.
• Strong software engineering skills in at least one production language, such as Python, Go, Rust, or TypeScript.
• Extensive experience in securing modern cloud and SaaS systems, including web applications, APIs, distributed services, databases, containers, Kubernetes, CI/CD, and infrastructure as code.
• Comprehensive knowledge of authentication, authorization, IAM, tenant isolation, secrets management, encryption, network boundaries, logging, and secure software supply chains.
• Practical experience with threat modeling, architecture review, secure code review, vulnerability analysis, penetration testing, and remediation.
• Attacker-informed mindset shaped through authorized red teaming, white-hat research, bug bounties, consulting, internal product-security work, or similar experiences.
• Proven track record of delivering durable fixes through architecture changes, code contributions, shared security systems, or elimination of vulnerability classes.
• Sound judgment to balance security, product velocity, usability, and business risk.
• Ability to influence critical decisions across teams without formal authority.
• Excellent written and verbal communication skills, intellectual honesty, high agency, and comfort with emerging threat models and architecture.
• Bonus: Security experience with LLM applications, agentic systems, RAG, tool use, MCP integrations, code-generating systems, or multi-agent orchestration.
• Bonus: Experience designing secure sandboxes, delegated authorization systems, machine identities, or fine-grained policy enforcement.
• Bonus: Experience securing model training, evaluation, inference, model registries, datasets, embeddings, or GPU and Kubernetes infrastructure.
• Bonus: Experience implementing technical controls for SOC 2 Type II, FedRAMP, or NIST SP 800-53.
• Bonus: Published vulnerability research, CVEs, meaningful bug-bounty findings, open-source security tools, or respected security-community participation.
• Bonus: In-depth knowledge of Linux/Unix, TCP/IP, DNS, routing, firewalls, proxies, VPN, AWS PrivateLink, VPC endpoints, private subnets, and controlled ingress/egress.
• Bonus: Experience establishing product security architecture in a high-growth startup, frontier technology company, or research environment.
• Resume and a brief description of a security architecture, product-security system, or authorized offensive-security project are required.
• Remote-first work environment.
• Opportunity to shape foundational security architecture for AI scientific systems.
• Significant influence over architecture, engineering practices, and security roadmap.
• Mentorship and capability-building opportunities.
• Opportunity to work with AI, scientific discovery, cloud infrastructure, and adversarial security.
• Global team collaboration across Canada, the US, and the UK.
Robots & Pencils
Latitude IT Solutions | SDVOSB
Latitude IT Solutions | SDVOSB
11:11 SYSTEMS
Get handpicked remote jobs straight to your inbox weekly.