
Staff Security Engineer
Posted 3 days ago

Posted 3 days ago
This is a fully remote position, open to applicants in United States.
• Ensure the security of AI-enabled products, internal applications, APIs, services, and platforms throughout their entire lifecycle.
• Oversee threat modeling, security architecture evaluations, and risk assessments for LLM applications, RAG pipelines, agentic workflows, MCP servers, model providers, third-party AI tools, plugins, automations, and AI-assisted development.
• Establish and execute secure AI engineering patterns, guardrails, standards, and reference architectures.
• Enhance AWS-native infrastructure and CI/CD environments, focusing on infrastructure-as-code, containerized workloads, secrets management, workload identity, deployment pipelines, and software supply chain controls.
• Collaborate with security operations, detection engineering, incident response, and vulnerability management teams to bolster AI-related detection, observability, telemetry, and response capabilities.
• Assess AI applications, SaaS platforms, model providers, MCPs, agents, developer tools, and third-party technologies for security, privacy, access, data exposure, logging, contractual, and operational risks.
• Create security guidance, training, and enablement resources for engineering and business teams.
• Spearhead cross-functional security-by-design initiatives, transforming security objectives into technical requirements, influencing architectural decisions, and managing broader security projects and critical incident response activities.
• Bachelor’s degree in Computer Science, Cybersecurity, Engineering, Information Systems, or a related technical field; an equivalent combination of education and relevant experience; or equivalent relevant experience.
• Over 8 years of experience in full-stack security, product security, application security, cloud security, DevSecOps, infrastructure security, or software engineering with substantial security responsibilities.
• At least 5 years of proven experience working with AI, machine learning, LLM, GenAI, or AI-enabled application environments.
• Proficient in conducting security architecture reviews, threat modeling, secure design evaluations, code or configuration reviews, and risk assessments.
• Experience in evaluating and securing third-party SaaS platforms, AI tools, model providers, developer tools, APIs, integrations, and vendor-managed services.
• Proven ability to collaborate across security operations, detection engineering, incident response, GRC, privacy, infrastructure, and product engineering teams.
• Extensive hands-on experience in securing cloud-native environments, preferably AWS, encompassing IAM, networking, logging, monitoring, secrets management, workload identity, infrastructure-as-code, and secure deployment practices.
• Strong comprehension of CI/CD pipelines, source control, build systems, artifact management, deployment automation, container security, software delivery workflows, and software supply chain risk.
• Familiarity with AI-specific security risks, including prompt injection, insecure tool usage, excessive agency, data leakage, RAG security risks, plugin and MCP vulnerabilities, insecure agent permissions, model extraction, model misuse, and AI supply chain issues.
• Capability to convert AI and cloud security risks into engineering requirements, controls, standards, detections, and operational procedures.
• Excellent written and verbal communication skills.
• Ability to work autonomously, prioritize competing risks, and lead complex cross-functional security initiatives.
• Medical, dental, and vision insurance.
• Life insurance and supplemental income plans for employees and their dependents.
• Subscription to the Headspace app.
• Monthly wellness allowance.
• 401(k) plan with company matching.
• One-time $2,000 payment for home office equipment and furniture.
• Fully provisioned MacBook Pro.
• Four weeks of paid time off (PTO) in the first year.
• Twelve weeks of fully paid parental leave for both birthing and non-birthing parents.
• Up to $5,000 annually for professional learning, continuing education, and career development.
• LinkedIn Learning subscriptions.
• Coaching opportunities available through BetterUp.
• Remote-first work arrangement.
• Occasional travel may be requested or encouraged, but is not mandatory.
• Core meeting hours are from 9 AM to 2 PM Pacific time.
Sony Interactive Entertainment
Squads
Neo4j
PingWind Inc. (SDVOSB)
Get handpicked remote jobs straight to your inbox weekly.