Base Salary
$176k - $253k/yr
Responsibilities
- Lead incident response for product-level security events, focusing on prompt injection, model abuse, agent hijacking, and data exfiltration through AI workloads.
- Integrate incident response and security requirements into Cortex features, Snowflake Intelligence, and AI-powered developer experiences from design through deployment.
- Develop detection, containment, and remediation playbooks for LLM misuse, adversarial inputs, and AI-assisted attacks.
- Address security technical debt and ensure Cortex and agentic architectures meet incident-response readiness requirements.
- Represent the incident-response team to cloud engineering, AI platform, corporate security, and customer-facing business units.
- Secure container-based inference services, RAG pipelines, vector stores, and agent orchestration layers across multi-cloud environments.
- Advise AI and security engineering teams on secure architecture for high-impact and customer-facing AI capabilities.
- Design and manage response capabilities across model-serving endpoints, Cortex Search indexes, and Snowpark ML pipelines.
- Build data-driven tooling and automation to accelerate detection and response for product security incidents at Snowflake scale.
Requirements
- 5+ years of experience in information security, primarily in incident response, security engineering, or product/application security.
- Direct experience serving as incident commander for product-focused security incidents.
- Experience leading or actively building an application or security engineering program, with a clear perspective on securing AI/ML systems.
- Experience with threat modeling and security testing across AI attack surfaces, including prompt injection, indirect injection, model inversion, embedding extraction, and supply chain attacks on AI dependencies.
- Familiarity with data governance and security challenges associated with LLMs, RAG architectures, and agentic systems.
- Working knowledge of AWS, Azure, and GCP and the threat landscape for SaaS and AI platforms.
- SQL proficiency and experience building automation and tools with common programming languages, preferably Python.
- Strong communication skills and the ability to translate security risk into actionable guidance for product teams.
- Experience securing AI/ML infrastructure such as model serving, vector databases, embedding pipelines, API gateways, and LLM-integrated applications is preferred.
- Experience building agentic incident-response capabilities and understanding of current attacker TTPs and emerging AI-specific techniques are preferred.
- Familiarity with CI/CD and secure release lifecycle patterns is preferred.
- Preferred certifications include GCIA, GCIH, GCSA, GDAT, CISSP/GISP, or AWS, Azure, or GCP cloud certifications.
- Bachelor's degree in Computer Science or a related field, or equivalent experience.
Benefits
- The role is based at Snowflake and U.S. salary and benefits information is provided through the Snowflake Careers Site.
About Snowflake
**Snowflake is proud to be the Official Data Collaboration Provider for LA28 and Team USA.** Snowflake delivers the AI Data Cloud — a global network where thousands of organizations mobilize data with near-unlimited scale, concurrency, and performance. Inside the AI Data Cloud, organizations unite their siloed data, easily discover and securely share governed data, and execute diverse analytic workloads. Wherever data or users live, Snowflake delivers a single and seamless experience across multiple public clouds. Snowflake’s platform is the engine that powers and provides access to the AI Data Cloud, creating a solution for data warehousing, data lakes, data engineering, data science, data application development, and data sharing. Join Snowflake customers, partners, and data providers already taking their businesses to new frontiers in the AI Data Cloud.