Staff Product Security Engineer - AI Systems
New
F
FirstPrinciples IncArtificial Intelligence
Working across Canada, the US, the UK, and expanding globally.Full-TimeStaff
Salary not disclosed
Apply NowOpens the employer's application page
Job Details
- Experience
- 7+ years
- Required Skills
- PythonKubernetesTypeScriptGoRustCI/CD
Requirements
- 7+ years of experience in product security, application security, cloud security, offensive security, or security-focused software engineering.
- Strong software engineering ability in at least one production language such as Python, Go, Rust, or TypeScript.
- Deep experience securing modern cloud and SaaS systems, including APIs, distributed services, containers, Kubernetes, and CI/CD.
- Strong knowledge of authentication, authorization, IAM, tenant isolation, secrets management, and encryption.
- Hands-on experience with threat modelling, secure code review, vulnerability analysis, and penetration testing.
- An attacker-informed mindset developed through red teaming, white-hat research, or bug bounties.
- Proven history of moving beyond findings to implement durable architectural fixes.
- Ability to influence critical decisions across teams without relying on formal authority.
- Clear written and verbal communication skills.
- Experience working in environments with emerging threat models and architectures.
Responsibilities
- Define the security architecture for Theo and its surrounding cloud platform.
- Build robust authentication and authorization for users, services, and AI agents.
- Design hardened execution environments for agent-generated and user-provided code.
- Lead threat modelling and secure design processes across Engineering and Research teams.
- Defend against AI- and agent-specific threats like prompt injection and data exfiltration.
- Build security-critical software and services to enforce identity, encryption, and auditability.
- Integrate automated security testing into development and release workflows.
- Conduct penetration tests and adversarial red-team exercises.
- Protect AI and scientific assets, including model weights and training datasets.
- Engineer compliance controls for SOC 2, FedRAMP, and NIST SP 800-53.
View Full Description & ApplyYou'll be redirected to the employer's site