30 days ago
Base Salary
$176k - $253k/yr
Responsibilities
- Lead incident response for product-level security events involving prompt injection, model abuse, agent hijacking, and AI-workload data exfiltration.
- Integrate incident-response requirements into Cortex features, Snowflake Intelligence, and AI-powered developer experiences from design through deployment.
- Define detection, containment, and remediation playbooks for LLM misuse, adversarial inputs, and AI-assisted attacks.
- Address security and incident-response technical debt across Cortex and agentic architectures.
- Represent the incident-response team to cloud engineering, AI platform, corporate security, and customer-facing business units.
- Secure container-based inference services, RAG pipelines, vector stores, and agent orchestration layers across multi-cloud environments.
- Advise AI and security engineering teams on secure architecture for high-impact and customer-facing AI capabilities.
- Design and manage response capabilities across model-serving endpoints, Cortex Search indexes, and Snowpark ML pipelines.
- Build data-driven tooling and automation to accelerate detection and response for product security incidents.
- Drive security outcomes for customers using Snowflake’s data and AI workloads.
Requirements
- At least 5 years of experience in information security, incident response, security engineering, or product/application security is preferred.
- Direct experience serving as incident commander for product-focused security incidents is required.
- Experience leading or building an application or security engineering program and securing AI/ML systems is required.
- Experience with threat modeling and security testing for AI attack surfaces, including prompt injection, indirect injection, model inversion, embedding extraction, and AI dependency supply-chain attacks, is required.
- Familiarity with data governance and security challenges involving LLMs, RAG architectures, and agentic systems is required.
- Working knowledge of AWS, Azure, and GCP cloud-native environments is required.
- SQL proficiency and experience building automation with common programming languages, preferably Python, are required.
- A bachelor’s degree in Computer Science or a related field, or equivalent experience, is required.
- Preferred qualifications include experience securing AI/ML infrastructure, model serving, vector databases, embedding pipelines, API gateways, and LLM-integrated applications.
- Preferred qualifications include experience building agentic incident-response capabilities and understanding current attacker TTPs and AI-specific techniques.
- Familiarity with CI/CD and secure release lifecycle patterns is preferred.
- Preferred certifications include GCIA, GCIH, GCSA, GDAT, CISSP/GISP, and AWS, Azure, or GCP certifications.
About Snowflake
Snowflake builds a cloud-native data platform used by enterprises to store, integrate, share, and analyze data across AWS, Azure, and Google Cloud. Its core products span data warehousing, data lakes, data engineering, and governed data sharing, sold via consumption-based subscriptions. Founded in 2012 and publicly traded on the NYSE (SNOW) following a 2020 IPO, Snowflake supports analytics and data application workloads across industries.
