BackOps AI

Product Security Engineer

BackOps AI
Apply
7 days ago

Responsibilities

  • Own product security across authentication, authorization, APIs, multi-tenant isolation, and related data models.
  • Threat model the agent platform, define agent permissions and boundaries, and design controls for unsafe actions.
  • Build and operate the secure development lifecycle, including design reviews, code review standards, and CI security scanning.
  • Manage application vulnerabilities from discovery and prioritization through remediation and verification.
  • Secure AI-assisted code, software dependencies, build pipelines, artifacts, and third-party integrations.
  • Lead the engineering work for enterprise security reviews, penetration tests, coordinated vulnerability disclosure, and customer-hosted or on-premises deployments.
  • Establish the product security function, practices, charter, and adoption culture as the company scales.

Requirements

  • 5+ years of product or application security engineering experience, or equivalent hands-on software engineering experience in security.
  • Strong coding skills in Python, Go, TypeScript, or a similar language, including the ability to review code and implement fixes.
  • Deep experience with authentication, authorization, multi-tenant isolation, OAuth, OIDC, RBAC, token handling, and session handling.
  • Strong web and API security knowledge across OWASP Top 10 vulnerability classes, including injection, SSRF, deserialization, and broken access control.
  • Working familiarity with the OWASP Top 10 for Agentic Applications and the OWASP Top 10 for LLM Applications.
  • Experience with threat modeling and with SAST, DAST, SCA, and secrets scanning in CI.
  • Clear written and verbal communication with engineers, executives, and customers, plus sound risk judgment in an evolving environment.
  • Preferred experience securing LLM or agentic systems, including prompt injection, insecure tool use, excessive agency, sandboxing, and untrusted model output.
  • Preferred experience with SOC 2 Type I/II, ISO 27001, Vanta, Drata, enterprise security reviews, multi-tenant B2B SaaS, customer-hosted deployments, bug bounty or coordinated disclosure programs, and building a product security function.

Benefits

  • Competitive salary and meaningful equity.
  • Comprehensive health, dental, and vision coverage.
  • 401(k) plan, disability insurance, and life insurance.
  • Flexible time off.
  • Daily meals in the office, regular team events, and offsites.
  • Small-team environment with autonomy and direct access to founders and customers.

Categories

BackOps AI

About BackOps AI

11-50 employees
Contact me