Product Security Engineer

Posted yesterday

Apply Now

Resume Score

Check how well your resume matches this job before you apply.

Sign in to check score

About the role

  • Product Security Engineer securing Cohere’s enterprise AI products and foundation models. Reviewing architecture, threat modeling capabilities, and testing vulnerabilities across production systems.

Responsibilities

  • Lead security reviews of architecture, code, and security-sensitive changes
  • Evaluate risks in AI-powered products, including prompt injection, unsafe tool use, identity and delegation failures, excessive agency, data exposure, tenant isolation, and sandbox escapes
  • Threat model new capabilities by identifying trust boundaries, abuse cases, and high-impact failure modes
  • Translate findings into practical, prioritized mitigations
  • Investigate suspected vulnerabilities and develop proofs of concept
  • Assess exploitability and impact and partner with engineers through remediation
  • Develop secure defaults, approved patterns, reusable controls, review requirements, and automated checks
  • Pair with engineers and document practical security guidance
  • Help product teams develop durable security expertise
  • Explain technical findings, business impact, and remediation options to engineers, product leaders, and executives

Requirements

  • Strong software engineering fundamentals and ability to independently understand, test, and contribute fixes to production codebases
  • Proficiency in at least one of Python, Go, or TypeScript
  • Experience leading security reviews or threat models for complex production systems
  • Understanding of injection, authorization flaws, IDOR, SSRF, unsafe deserialization, race conditions, cryptographic misuse, and software supply-chain risks
  • Understanding of web applications, APIs, OAuth/OIDC, cloud platforms, containers, Kubernetes, and CI/CD systems
  • Ability to reason about untrusted input, authorization, isolation, identity, delegation, and data boundaries
  • Experience driving security improvements involving multiple engineering teams
  • Clear communication with technical and non-technical audiences
  • Experience with SAST, DAST, SCA, custom linters, or policy-as-code (nice to have)
  • Experience securing multi-tenant SaaS, enterprise software, or systems processing sensitive customer data (nice to have)
  • Offensive security experience through penetration testing, red teaming, or security research (nice to have)
  • Experience with vulnerability disclosure or bug bounty programs (nice to have)
  • Open-source security contributions, published research, conference talks, or credited vulnerability discoveries (nice to have)

Benefits

  • A weekly lunch stipend of $75/£75 or equivalent in your local currency for lunch
  • Full health and dental benefits, including a separate budget for mental health
  • RRSP matching, 401K, Pension Scheme
  • 100% Parental Leave top-up for up to 6 months, for either parent
  • Annual enrichment benefits: arts & culture, fitness/wellness, quality time, and a workspace improvement credit
  • Education & learning stipend for conferences, courses, and coaching
  • 6 weeks of paid vacation (30 working days)
  • Budget for traveling to other offices if you are remote, plus an annual company offsite
  • Co-working benefit for those not near an office
  • $500 home office stipend
  • Daily lunch program, snacks, and regular community and social events for those in the office

Job type

Full Time

Experience level

Mid levelSenior

Salary

CA$260,000 - CA$385,000 per year

Degree requirement

No Education Requirement

Tech skills

CloudKubernetesPythonTypeScriptGo

Location requirements

RemoteCanada

Report this job

Found something wrong with the page? Please let us know by submitting a report below.