
Product Security Engineer (AI & Platform Security) – Taiwan
Obsidian Security7 hours ago
Taipei, TaiwanSenior
Responsibilities
- Build security features into products, backend services, and cloud infrastructure, including authentication, authorization, service-to-service identity, tenant isolation, secrets management, and audit logging.
- Protect customer data across collection, processing, storage, and presentation through encryption, key management, access control, tenant isolation, and retention controls.
- Design and secure cloud-native services on AWS and GCP, including IAM, networking, storage, Kubernetes, managed services, secure defaults, and infrastructure-as-code.
- Conduct security architecture and design reviews for products, services, APIs, data pipelines, infrastructure components, and AI or agent systems.
- Secure AI and agent workflows by implementing least-privilege tool access, input and output controls, and data-leakage protections.
- Strengthen development pipelines with automated dependency scanning, static analysis, and container scanning.
- Lead CVE management, including exposure analysis, risk assessment, prioritization, remediation, testing, deployment, and validation.
- Conduct code reviews and mentor engineers on secure development practices.
Requirements
- Experience in product security or a related discipline, with a record of shipping security improvements as code.
- Deep knowledge of secure software development and common application security risks.
- Strong software engineering skills in Python, Go, Java, Kotlin, TypeScript, or comparable languages.
- Hands-on experience developing and securing applications on AWS and/or GCP.
- Experience securing cloud-native SaaS products, distributed systems, APIs, and microservices, including sensitive data protection end to end.
- Practical CVE management experience across dependencies and infrastructure.
- Strong English communication skills and the ability to collaborate across regions and time zones.
- Preferred qualifications include experience securing AI or LLM applications and agent systems, cybersecurity or identity security product experience, software supply chain security knowledge, familiarity with OWASP, CVSS, and NIST, SOC 2 or ISO 27001 compliance experience, penetration testing or vulnerability research experience, and Mandarin proficiency.
Benefits
- Competitive compensation with equity and 401k for US-based employees.
- Comprehensive healthcare with dental and vision coverage for US-based employees.
- Flexible paid time off and paid holiday time off.
- 12 weeks of new parent or family leave.
- Personal and professional development resources.
- International benefits information is available separately for the Taiwan-based role.
Tech Stack
Categories
About Obsidian Security
Obsidian Security builds a SaaS security platform for enterprises to discover and govern third-party app and AI integrations, manage OAuth/API permissions, and detect and respond to identity and SaaS threats. It sells subscriptions to large regulated organizations; named customers include Snowflake, T-Mobile, and Algolia. Founded in 2017 and headquartered in Palo Alto, the privately held company focuses on Microsoft 365, Salesforce, and other major business apps.