Staff Product Security Engineer - AI Systems

New
F
FirstPrinciples IncArtificial Intelligence
Working across Canada, the US, the UK, and expanding globally.Full-TimeStaff
Salary not disclosed
Apply NowOpens the employer's application page

Job Details

Experience
7+ years
Required Skills
PythonKubernetesTypeScriptGoRustCI/CD

Requirements

  • 7+ years of experience in product security, application security, cloud security, offensive security, or security-focused software engineering.
  • Strong software engineering ability in at least one production language such as Python, Go, Rust, or TypeScript.
  • Deep experience securing modern cloud and SaaS systems, including APIs, distributed services, containers, Kubernetes, and CI/CD.
  • Strong knowledge of authentication, authorization, IAM, tenant isolation, secrets management, and encryption.
  • Hands-on experience with threat modelling, secure code review, vulnerability analysis, and penetration testing.
  • An attacker-informed mindset developed through red teaming, white-hat research, or bug bounties.
  • Proven history of moving beyond findings to implement durable architectural fixes.
  • Ability to influence critical decisions across teams without relying on formal authority.
  • Clear written and verbal communication skills.
  • Experience working in environments with emerging threat models and architectures.

Responsibilities

  • Define the security architecture for Theo and its surrounding cloud platform.
  • Build robust authentication and authorization for users, services, and AI agents.
  • Design hardened execution environments for agent-generated and user-provided code.
  • Lead threat modelling and secure design processes across Engineering and Research teams.
  • Defend against AI- and agent-specific threats like prompt injection and data exfiltration.
  • Build security-critical software and services to enforce identity, encryption, and auditability.
  • Integrate automated security testing into development and release workflows.
  • Conduct penetration tests and adversarial red-team exercises.
  • Protect AI and scientific assets, including model weights and training datasets.
  • Engineer compliance controls for SOC 2, FedRAMP, and NIST SP 800-53.
View Full Description & ApplyYou'll be redirected to the employer's site
View details
Apply Now