Base Salary
$176k - $253k/yr
Responsibilities
- Lead incident response for product-level security events, focusing on prompt injection, model abuse, agent hijacking, and AI-related data exfiltration.
- Integrate incident-response requirements into Cortex features, Snowflake Intelligence, and AI-powered developer experiences from design through deployment.
- Develop detection, containment, and remediation playbooks for LLM misuse, adversarial inputs, and AI-assisted attacks.
- Address security technical debt and ensure Cortex and agentic architectures meet incident-response readiness requirements.
- Represent the incident-response team to cloud engineering, AI platform, corporate security, and customer-facing business units.
- Secure container-based inference services, RAG pipelines, vector stores, and agent orchestration layers across multi-cloud environments.
- Provide secure-architecture guidance for high-impact and customer-facing AI capabilities.
- Design and manage response capabilities across model-serving endpoints, Cortex Search indexes, and Snowpark ML pipelines.
- Build tooling and automation to accelerate detection and response for product security incidents at Snowflake scale.
Requirements
- 5+ years of experience in information security, primarily in incident response, security engineering, or product/application security.
- Direct experience serving as incident commander for product-focused security incidents.
- Experience leading or building an application or security engineering program with a perspective on securing AI/ML systems.
- Experience with threat modeling and security testing for AI attack surfaces, including prompt injection, indirect injection, model inversion, embedding extraction, and AI dependency supply-chain attacks.
- Familiarity with data governance and security challenges involving LLMs, RAG architectures, and agentic systems.
- Working knowledge of AWS, Azure, and GCP cloud-native environments and SaaS and AI platform threats.
- SQL proficiency and experience building automation and tools with common programming languages, preferably Python.
- Bachelor’s degree in Computer Science or a related field, or equivalent experience.
- Preferred experience includes securing AI/ML infrastructure, model serving, vector databases, embedding pipelines, API gateways, and LLM-integrated applications.
- Preferred experience includes building agentic incident-response capabilities and understanding attacker TTPs such as adversarial ML, agent manipulation, and LLM jailbreaking.
- Familiarity with CI/CD and secure release lifecycle patterns is preferred.
- Preferred certifications include GCIA, GCIH, GCSA, GDAT, CISSP/GISP, or AWS, Azure, or GCP cloud certifications.
About Snowflake
**Snowflake is proud to be the Official Data Collaboration Provider for LA28 and Team USA.** Snowflake delivers the AI Data Cloud — a global network where thousands of organizations mobilize data with near-unlimited scale, concurrency, and performance. Inside the AI Data Cloud, organizations unite their siloed data, easily discover and securely share governed data, and execute diverse analytic workloads. Wherever data or users live, Snowflake delivers a single and seamless experience across multiple public clouds. Snowflake’s platform is the engine that powers and provides access to the AI Data Cloud, creating a solution for data warehousing, data lakes, data engineering, data science, data application development, and data sharing. Join Snowflake customers, partners, and data providers already taking their businesses to new frontiers in the AI Data Cloud.