
Product Security Engineer
BackOps AI7 days ago
Responsibilities
- Own product security across authentication, authorization, APIs, multi-tenant isolation, and related data models.
- Threat model the agent platform, define agent permissions and boundaries, and design controls for unsafe actions.
- Build and operate the secure development lifecycle, including design reviews, code review standards, and CI security scanning.
- Manage application vulnerabilities from discovery and prioritization through remediation and verification.
- Secure AI-assisted code, software dependencies, build pipelines, artifacts, and third-party integrations.
- Lead the engineering work for enterprise security reviews, penetration tests, coordinated vulnerability disclosure, and customer-hosted or on-premises deployments.
- Establish the product security function, practices, charter, and adoption culture as the company scales.
Requirements
- 5+ years of product or application security engineering experience, or equivalent hands-on software engineering experience in security.
- Strong coding skills in Python, Go, TypeScript, or a similar language, including the ability to review code and implement fixes.
- Deep experience with authentication, authorization, multi-tenant isolation, OAuth, OIDC, RBAC, token handling, and session handling.
- Strong web and API security knowledge across OWASP Top 10 vulnerability classes, including injection, SSRF, deserialization, and broken access control.
- Working familiarity with the OWASP Top 10 for Agentic Applications and the OWASP Top 10 for LLM Applications.
- Experience with threat modeling and with SAST, DAST, SCA, and secrets scanning in CI.
- Clear written and verbal communication with engineers, executives, and customers, plus sound risk judgment in an evolving environment.
- Preferred experience securing LLM or agentic systems, including prompt injection, insecure tool use, excessive agency, sandboxing, and untrusted model output.
- Preferred experience with SOC 2 Type I/II, ISO 27001, Vanta, Drata, enterprise security reviews, multi-tenant B2B SaaS, customer-hosted deployments, bug bounty or coordinated disclosure programs, and building a product security function.
Benefits
- Competitive salary and meaningful equity.
- Comprehensive health, dental, and vision coverage.
- 401(k) plan, disability insurance, and life insurance.
- Flexible time off.
- Daily meals in the office, regular team events, and offsites.
- Small-team environment with autonomy and direct access to founders and customers.