13 hours ago
Base Salary
$235k - $305k/yr
Responsibilities
- Partner with engineering and product teams to embed security throughout the lifecycle of AI-enabled products, applications, APIs, services, and platforms.
- Lead threat modeling, security architecture reviews, secure design reviews, and risk assessments for LLM applications, RAG pipelines, agentic workflows, MCP servers, model providers, plugins, and third-party AI tools.
- Define and implement secure AI engineering patterns, guardrails, standards, and reference architectures covering identity, data protection, prompt and context handling, tool permissions, logging, monitoring, abuse prevention, and incident readiness.
- Strengthen AWS-native infrastructure and CI/CD environments through infrastructure-as-code, containerized workload security, secrets management, workload identity, deployment controls, and software supply chain protections.
- Partner with security operations, detection engineering, incident response, and vulnerability management teams to improve AI-related detection, observability, telemetry, and response.
- Evaluate third-party SaaS platforms, AI tools, model providers, developer tools, APIs, integrations, and vendor-managed services for security, privacy, access, data exposure, contractual, and operational risks.
- Develop security guidance, training, and enablement materials and lead cross-functional security-by-design initiatives.
- Translate security objectives into technical requirements, influence architecture decisions, and lead broader security projects and critical incident response efforts.
Requirements
- Bachelor’s degree in Computer Science, Cybersecurity, Engineering, Information Systems, or a related technical field, or equivalent relevant experience.
- 8+ years of experience in full-stack security, product security, application security, cloud security, DevSecOps, infrastructure security, or software engineering with significant security responsibilities.
- 5+ years of experience working with AI, machine learning, LLM, GenAI, or AI-enabled application environments.
- Experience conducting security architecture reviews, threat modeling, secure design reviews, code or configuration reviews, and risk assessments for modern applications, APIs, platforms, and distributed systems.
- Experience evaluating and securing third-party SaaS platforms, AI tools, model providers, developer tools, APIs, integrations, and vendor-managed services.
- Experience partnering across security operations, detection engineering, incident response, GRC, privacy, infrastructure, and product engineering teams.
- Hands-on experience securing cloud-native environments, preferably AWS, including IAM, networking, logging, monitoring, secrets management, workload identity, infrastructure-as-code, and secure deployment practices.
- Understanding of CI/CD pipelines, source control, build systems, artifact management, deployment automation, container security, software delivery workflows, and software supply chain risk.
- Working knowledge of AI security risks including prompt injection, insecure tool use, excessive agency, data leakage, RAG security risks, model and provider trust boundaries, plugin and MCP risks, insecure agent permissions, model extraction, model abuse, and AI supply chain concerns.
- Ability to translate AI and cloud security risks into engineering requirements, compensating controls, standards, detections, and operational procedures.
- Strong written and verbal communication skills and the ability to influence decisions and drive remediation across technical and business teams.
- Ability to work independently, prioritize competing risks, and lead complex cross-functional initiatives from concept through execution.
- Preferred qualifications include experience securing agentic AI systems, MCP servers, AI agents, tool-calling workflows, internal copilots, LLM gateways, AI assistants, or AI-enabled developer tools.
- Preferred qualifications include experience with AWS AI/ML and GenAI services, RAG architectures, vector databases, embedding pipelines, DLP integrations, AI usage monitoring, detection engineering, SIEM/SOAR, cloud security posture management, vulnerability management, or endpoint security.
- Preferred programming experience includes Python, TypeScript, JavaScript, Go, Java, or similar languages; preferred cloud-native experience includes Kubernetes, Docker, Terraform, GitHub Actions, GitLab CI/CD, or Jenkins.
- Familiarity with OWASP Top 10 for LLM Applications, MITRE ATLAS, NIST AI Risk Management Framework, CIS benchmarks, SOC 2, ISO 27001, or cloud security reference architectures is preferred.
- Relevant certifications such as AWS Certified Security – Specialty, CISSP, CSSLP, CCSP, GIAC, or OSCP are preferred.
Benefits
- Medical, dental, vision, life insurance, and supplemental income plans for employees and dependents.
- Headspace subscription, monthly wellness allowance, and a 401(k) plan with company match.
- Remote-first work from anywhere in the U.S., excluding U.S. territories; occasional travel is generally not required.
- One-time $2,000 payment for home office equipment and furniture, plus a fully provisioned MacBook Pro.
- Four weeks of PTO accrued in the first year and twelve weeks of fully paid parental leave for new parents.
- Up to $5,000 annually for professional learning, continuing education, and career development, plus LinkedIn Learning and BetterUp access.
- Core collaboration hours are 9 AM–2 PM Pacific time; Bay Area and Providence employees may use local offices as desired.
Tech Stack
Categories
About Quanata
Quanata builds insurance technology that uses telematics, behavioral data, and AI to predict and prevent risk and to power context-based insurance products. It develops and supports a flexible, full-stack digital insurance platform and risk-focused acquisition capabilities for State Farm and HiRoad. Headquartered in San Francisco, Quanata is privately held and wholly owned and funded by State Farm.
