
Staff Security Engineer
Posted 3 days ago

Posted 3 days ago
This is a fully remote position, open to applicants in United States.
• Take ownership and lead all Security Engineering initiatives at Jellyfish.
• Establish and drive a strategic security roadmap that aligns with executive business goals.
• Design and enforce scalable, resilient security architectures across infrastructure, platform, and product ecosystems.
• Define, implement, and oversee the company's Secure Development Lifecycle (SDLC).
• Create secure SDLC practices for both internal AI tools and customer-facing AI features.
• Lead threat modeling for AI and machine learning, along with ongoing risk assessments.
• Mitigate risks related to prompt injection, data poisoning, and the leakage of sensitive data.
• Develop automated workflows for remediation, vulnerability management, and software composition analysis solutions.
• Mentor engineers and provide guidance to executive leadership regarding security posture.
• Foster a culture of security and inclusion across the company.
• Direct responses to critical security incidents.
• Oversee threat modeling and strategize penetration testing and bug bounty programs.
• Build security features and produce high-quality code.
• Collaborate with engineering and data science teams.
• Travel occasionally as required.
• Extensive and proven experience in owning, building, and scaling application security programs within a SaaS or dynamic startup environment.
• In-depth technical knowledge in software engineering, including proficiency in Python, JavaScript/TypeScript, Rust, or C/C++.
• Architectural-level comprehension of reliability, safety, and security.
• Profound understanding of security challenges related to Artificial Intelligence and Large Language Models (LLMs).
• Hands-on experience in securing internal AI infrastructure and customer-facing AI applications.
• Ability to balance AI product innovation with security, compliance, and data privacy standards.
• Proven capability to drive cross-functional consensus and influence engineering leadership.
• Experience executing large-scale performance, testing, and security initiatives.
• Strong business acumen.
• Recognized expertise in computer security, with experience disseminating knowledge through technical presentations and engineering-wide education.
• Ability to work independently within a distributed team.
• Must be eligible to work in the U.S. for any employer.
• Preferred to be located in the EST or CST time zone.
• Expert-level skills in Python, Django, Postgres, AWS, Terraform, Circle CI/GitLab/GitHub Actions, Semgrep, or LLVM (bonus).
• Contributions to open-source security, standardization, or industry working groups (bonus).
• Experience enhancing collaboration between security and engineering teams (bonus).
• Previous security leadership experience in a high-growth startup (bonus).
• Must be authorized to work for any employer in the U.S.; visa sponsorship is not available.
• Equity offered.
• Opportunities/requirements for occasional travel.
• A diverse and inclusive workplace.
• Participation in a voluntary diversity survey; participation does not impact the job application.
Cloudiax
BLUVIT GmbH
Eli Lilly and Company
S + S Regeltechnik GmbH
Get handpicked remote jobs straight to your inbox weekly.