Staff Product Security Engineer defining security architecture for FirstPrinciples’ AI scientific-discovery platform. Securing agents, code execution, cloud infrastructure, models, data, and SaaS systems.
Responsibilities
Define security architecture for Theo's SaaS application, APIs, cloud infrastructure, model-serving systems, agent runtimes, data platforms, research environments, and deployment pipelines
Build authentication and authorization for users, services, and AI agents, including scoped credentials, delegated permissions, least-privilege access, tenant isolation, and auditable actions
Design hardened execution environments for agent-generated and user-provided code with isolation, resource limits, filesystem and network controls, provenance, monitoring, and escape testing
Lead threat modelling and secure design across Engineering, Research, Product, and Infrastructure from architecture through production
Defend against AI- and agent-specific threats including prompt injection, unsafe tool use, confused-deputy behavior, poisoning, exfiltration, model extraction, privilege escalation, and resource abuse
Build secure-by-default services, libraries, policies, test harnesses, and platform controls for identity, secrets, encryption, policy enforcement, auditability, abuse prevention, and vulnerability management
Integrate SAST, DAST, dependency, container, infrastructure-as-code, secret, and software supply-chain scanning into development and release workflows
Conduct penetration tests, red-team and purple-team exercises, architecture attacks, and abuse-case testing
Assess vulnerabilities, coordinate remediation with engineers, validate fixes, and eliminate recurring weaknesses
Protect model weights, training and evaluation data, datasets, embeddings, registries, research artifacts, GPU infrastructure, and software supply chains
Define telemetry, alerting, containment, and forensic capabilities for incidents involving users, services, agents, models, and data
Translate SOC 2 and customer security requirements into technical controls and support FedRAMP and NIST SP 800-53 readiness
Automate evidence collection and control validation
Mentor engineers, establish reusable patterns, document architectural decisions, and communicate risks to technical teams and leadership
Within the first year, establish clear risk-based security architecture, explicit controls and adversarial coverage, secure-by-default workflows, integrated testing, remediation ownership, and a technical path toward FedRAMP readiness
Requirements
7+ years of experience in product security, application security, cloud security, offensive security, or security-focused software engineering
Strong software engineering ability in at least one production language such as Python, Go, Rust, or TypeScript
Deep experience securing modern cloud and SaaS systems, including web applications, APIs, distributed services, databases, containers, Kubernetes, CI/CD, and infrastructure as code
Strong knowledge of authentication, authorization, IAM, tenant isolation, secrets management, encryption, network boundaries, logging, and secure software supply chains
Hands-on experience with threat modelling, architecture review, secure code review, vulnerability analysis, penetration testing, and remediation
Attacker-informed mindset developed through authorized red teaming, white-hat research, bug bounties, consulting, internal product-security work, or similar experience
History of delivering durable fixes through architecture changes, code contributions, shared security systems, or elimination of vulnerability classes
Judgment to balance security, product velocity, usability, and business risk
Ability to influence critical decisions across teams without formal authority
Clear written and verbal communication, intellectual honesty, high agency, and comfort with emerging threat models and architecture
Bonus: security experience with LLM applications, agentic systems, RAG, tool use, MCP integrations, code-generating systems, or multi-agent orchestration
Product Security Engineer using frontier AI to discover vulnerabilities and red - team AI systems at Coinbase. Building offensive security tooling and automating vulnerability response workflows.
Desjardins Red Team advisor conducting adversary simulations and offensive cybersecurity operations. Developing stealth tools, attack chains and tradecraft to strengthen cyber defence.
Expert Security Engineer building anti - cheat systems for Activision’s Call of Duty franchise. Strengthening game security, detection, performance, and fair play across studios.
Expert systèmes, réseaux et sécurité déployant et administrant les solutions de cybersécurité d’I - TRACING. Maintien des infrastructures critiques, gestion des incidents et automatisation des opérations à Montréal.
TD bank security lead overseeing audits, technology controls, and operational compliance for Business Banking platforms. Automating audit response and managing security risk remediation.
Senior security professional overseeing Canadian government contract security, controlled goods, audits, and clearances. Supporting Honeywell’s automation, aerospace, energy, and industrial solutions.
Senior Information Security Manager leading security operations, application security, and AI security. Protecting Benevity’s cloud - native platform that helps companies and employees take social action.
Senior information security manager leading operations, application, cloud, and AI security. Securing Benevity’s technology platform for corporate social - impact programs.
Conseiller en solution de sécurité chez Exposant 3, firme de conseil en TI et transformation numérique. Analyse des risques, durcissement des environnements et automatisation PowerShell.