Staff Product Security Engineer – AI Systems

Posted Aug 27

This is a fully remote position, open to applicants in Canada.

📋 Description

• Define the security architecture for Theo's SaaS application, APIs, cloud infrastructure, model-serving systems, agent runtimes, data platforms, research environments, and deployment pipelines.

• Develop authentication and authorization mechanisms for users, services, and AI agents, including scoped credentials, delegated permissions, least-privilege access, tenant isolation, and auditable actions.

• Design secure execution environments for agent-generated and user-provided code, ensuring isolation, resource limits, filesystem and network controls, provenance, monitoring, and escape testing.

• Lead threat modeling and secure design initiatives across Engineering, Research, Product, and Infrastructure from architecture to production.

• Safeguard against AI- and agent-specific threats, including prompt injection, unsafe tool usage, confused-deputy behavior, poisoning, exfiltration, model extraction, privilege escalation, and resource abuse.

• Create secure-by-default services, libraries, policies, test harnesses, and platform controls for identity, secrets, encryption, policy enforcement, auditability, abuse prevention, and vulnerability management.

• Integrate SAST, DAST, dependency, container, infrastructure-as-code, secret, and software supply-chain scanning into development and release workflows.

• Establish security reviews, release controls, SBOMs, artifact provenance, and automated security regression testing.

• Conduct penetration tests, red-team and purple-team exercises, architecture attacks, and abuse-case testing.

• Evaluate vulnerabilities, coordinate remediation with engineers, validate fixes, and eliminate recurring weaknesses.

• Protect model weights, training and evaluation data, datasets, embeddings, registries, research artifacts, GPU infrastructure, and software supply chains.

• Define telemetry, alerting, containment, and forensic capabilities for incidents involving users, services, agents, models, and data.

• Translate SOC 2 and customer security requirements into technical controls and support FedRAMP and NIST SP 800-53 readiness.

• Automate evidence collection and control validation.

• Mentor engineers, establish reusable patterns, document architectural decisions, and communicate risks to technical teams and leadership.

• Within the first year, establish a clear risk-based security architecture, explicit controls and adversarial coverage, secure-by-default workflows, integrated testing, remediation ownership, and a technical path toward FedRAMP readiness.


⛳️ Requirements

• 7+ years of experience in product security, application security, cloud security, offensive security, or security-focused software engineering.

• Strong software engineering skills in at least one production language, such as Python, Go, Rust, or TypeScript.

• Extensive experience in securing modern cloud and SaaS systems, including web applications, APIs, distributed services, databases, containers, Kubernetes, CI/CD, and infrastructure as code.

• Comprehensive knowledge of authentication, authorization, IAM, tenant isolation, secrets management, encryption, network boundaries, logging, and secure software supply chains.

• Practical experience with threat modeling, architecture review, secure code review, vulnerability analysis, penetration testing, and remediation.

• Attacker-informed mindset shaped through authorized red teaming, white-hat research, bug bounties, consulting, internal product-security work, or similar experiences.

• Proven track record of delivering durable fixes through architecture changes, code contributions, shared security systems, or elimination of vulnerability classes.

• Sound judgment to balance security, product velocity, usability, and business risk.

• Ability to influence critical decisions across teams without formal authority.

• Excellent written and verbal communication skills, intellectual honesty, high agency, and comfort with emerging threat models and architecture.

• Bonus: Security experience with LLM applications, agentic systems, RAG, tool use, MCP integrations, code-generating systems, or multi-agent orchestration.

• Bonus: Experience designing secure sandboxes, delegated authorization systems, machine identities, or fine-grained policy enforcement.

• Bonus: Experience securing model training, evaluation, inference, model registries, datasets, embeddings, or GPU and Kubernetes infrastructure.

• Bonus: Experience implementing technical controls for SOC 2 Type II, FedRAMP, or NIST SP 800-53.

• Bonus: Published vulnerability research, CVEs, meaningful bug-bounty findings, open-source security tools, or respected security-community participation.

• Bonus: In-depth knowledge of Linux/Unix, TCP/IP, DNS, routing, firewalls, proxies, VPN, AWS PrivateLink, VPC endpoints, private subnets, and controlled ingress/egress.

• Bonus: Experience establishing product security architecture in a high-growth startup, frontier technology company, or research environment.

• Resume and a brief description of a security architecture, product-security system, or authorized offensive-security project are required.


🏝️ Benefits

• Remote-first work environment.

• Opportunity to shape foundational security architecture for AI scientific systems.

• Significant influence over architecture, engineering practices, and security roadmap.

• Mentorship and capability-building opportunities.

• Opportunity to work with AI, scientific discovery, cloud infrastructure, and adversarial security.

• Global team collaboration across Canada, the US, and the UK.

People also viewed

Robots & Pencils8 hours ago

Staff Security Engineer

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$56 – $77/hour
ApplyView job
Latitude IT Solutions | SDVOSB9 hours ago

Security Engineer

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$102k – $118k/year
ApplyView job
Latitude IT Solutions | SDVOSB9 hours ago

Senior Security Engineer

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$119k – $137k/year
ApplyView job
11:11 SYSTEMS19 hours ago

Security Engineer

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
11:11 SYSTEMS20 hours ago

Security Engineer

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
11:11 SYSTEMS21 hours ago

Security Engineer

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers