5 months ago
Responsibilities
- Own secure development practices, including AuthN/AuthZ, secrets management, input handling, secure code review, CI/CD checks, and pre-deployment controls.
- Conduct threat modeling and translate identified risks into concrete controls, architecture reviews, and security documentation.
- Define application-layer security models for agents, including tool scoping, permission boundaries, trust boundaries, credential handling, response validation, and user-context protection.
- Build reusable secure-by-default agent development patterns, review checklists, code-level guardrails, and automated security tooling.
- Define data protection standards and safeguards for PHI, PII, government records, AI pipelines, agent outputs, access controls, output filtering, and audit logging.
- Partner with product, ML, platform, and delivery teams to embed security into products shipped to regulated customer environments.
- Use AI to accelerate threat modeling, security reviews, code analysis, and internal tooling.
Requirements
- 5+ years of experience in application security or product security with hands-on production-system experience at scale.
- Strong application security fundamentals, including OWASP Top 10, AuthN/AuthZ, secure SDLC, secrets management, secure integration patterns, and cryptography basics.
- Understanding of agentic AI security at the product layer, including agent scoping, authorization, and risk review.
- Experience protecting sensitive data through access controls, audit logging, and controls against exposure through integrations and AI-generated outputs.
- Ability to build and ship security tooling and collaborate directly with engineering and delivery teams in regulated environments.
- Bonus: experience with agent security, LLM application security, or authorization and guardrail systems for agentic pipelines.
- Bonus: familiarity with FedRAMP, HIPAA, SOC 2, or ISO 27001.
- Bonus: proficiency in Python, Go, or TypeScript for security tooling and automation.
- Bonus: experience with SAST/DAST tooling or automated security checks in developer workflows at scale.
Benefits
- Competitive salary plus equity
- Daily lunches
- Commuter benefits
- 401(k)
- Medical, Dental, and Vision
- Unlimited PTO
Tech Stack
Categories
About Brain Co.
We're building an AI platform and applications for the world's most important institutions. Learn more at https://brain.co/
