10 hours ago
San Jose, CA, USAMid Level / Senior
H1B sponsor
Base Salary
$150k - $300k/yr
Responsibilities
- Threat-model new features and services, focusing on prompt injection, tool misuse, data exfiltration, and cross-tenant access in agent and LLM systems.
- Review designs and code for backend services, APIs, and mobile apps, and fix vulnerabilities directly when appropriate.
- Secure authentication, authorization, session handling, OAuth integrations, and multi-tenant systems.
- Build and tune SAST, dependency, and secrets scanning in CI.
- Triage and remediate findings from penetration tests and the vulnerability disclosure program.
- Partner with engineering to embed security through secure defaults, paved roads, and reusable libraries.
Requirements
- 4–8 years of hands-on application or product security engineering experience.
- Strong software engineering skills and the ability to read, write, and ship production code; Go is strongly preferred, while Python, TypeScript, Swift, and Kotlin are valuable.
- Deep knowledge of web and API vulnerabilities, including OWASP Top 10, SSRF, IDOR/BOLA, authorization flaws, and injection.
- Hands-on experience with OAuth 2.0, OIDC, session management, and securing multi-tenant systems.
- Experience conducting secure code reviews and threat modeling in a fast-moving engineering organization.
- Experience converting scanner and runtime findings into fixes using tools such as Wiz Code, Wiz Cloud, and Datadog SIEM or equivalent SAST/SCA, CNAPP, and SIEM tools.
- Curiosity about LLM and agent security.
- Preferred qualifications include mobile application security, LLM or agent threat modeling, prompt-injection defenses, AI red teaming, bug bounty work, CVEs, or open-source security contributions.
Benefits
- Full-time position with a US base salary range of $150,000–$300,000 annually.
- Additional compensation components and benefits may be included depending on the role.
