Obsidian Security

AI Security Engineer

Obsidian Security
Apply
3 months ago
Palo Alto, CA, USAMid Level
H1B sponsor

Responsibilities

  • Develop expertise in authentication, requested scopes, and risk concentration across ChatGPT Enterprise, Copilot, Gemini, Claude, Glean, and agentic frameworks
  • Research emerging AI attack techniques such as prompt injection, tool and agent misuse, RAG poisoning, and over-permissioned integrations
  • Build threat models covering identity, data access, non-human identities, and integration risk
  • Translate security research into detections and posture checks
  • Prototype and ship end-to-end product features using AI and SaaS telemetry
  • Build and improve efficient, cost-effective data pipelines

Requirements

  • At least 3 years of security engineering experience as a builder with clear ownership of shipped work
  • Strong understanding of identity and access control concepts
  • Hands-on experience with dbt and a columnar warehouse or query engine such as ClickHouse, Snowflake, BigQuery, or Databricks
  • Ability to communicate clearly across engineers, product managers, and customer security teams
  • Preferred: knowledge of SaaS platform APIs, event schemas, permissions, and authentication flows across Google Workspace, Microsoft 365, Salesforce, and Okta
  • Preferred: knowledge of AI and SaaS security, including OWASP LLM Top 10, MITRE ATLAS, prompt injection, agent and tool-use risks, OAuth abuse, and identity models

Benefits

  • Competitive compensation with equity and 401k
  • Comprehensive healthcare with dental and vision coverage
  • Flexible paid time off and paid holiday time off
  • 12 weeks of new parent or family leave
  • Personal and professional development resources

Tech Stack

ClickHouseDatabricksdbtGoogle BigQueryGoogle CloudSnowflake

Categories

Obsidian Security

About Obsidian Security

201-500 employees

Obsidian Security builds a SaaS security platform for enterprises to discover and govern third-party app and AI integrations, manage OAuth/API permissions, and detect and respond to identity and SaaS threats. It sells subscriptions to large regulated organizations; named customers include Snowflake, T-Mobile, and Algolia. Founded in 2017 and headquartered in Palo Alto, the privately held company focuses on Microsoft 365, Salesforce, and other major business apps.

Contact me