Staff Product Security Engineer – AI Systems

Posted 2 days ago

Apply Now

Resume Score

Check how well your resume matches this job before you apply.

Sign in to check score

About the role

  • Staff Product Security Engineer defining security architecture for FirstPrinciples’ AI scientific-discovery platform. Securing agents, code execution, cloud infrastructure, models, data, and SaaS systems.

Responsibilities

  • Define security architecture for Theo's SaaS application, APIs, cloud infrastructure, model-serving systems, agent runtimes, data platforms, research environments, and deployment pipelines
  • Build authentication and authorization for users, services, and AI agents, including scoped credentials, delegated permissions, least-privilege access, tenant isolation, and auditable actions
  • Design hardened execution environments for agent-generated and user-provided code with isolation, resource limits, filesystem and network controls, provenance, monitoring, and escape testing
  • Lead threat modelling and secure design across Engineering, Research, Product, and Infrastructure from architecture through production
  • Defend against AI- and agent-specific threats including prompt injection, unsafe tool use, confused-deputy behavior, poisoning, exfiltration, model extraction, privilege escalation, and resource abuse
  • Build secure-by-default services, libraries, policies, test harnesses, and platform controls for identity, secrets, encryption, policy enforcement, auditability, abuse prevention, and vulnerability management
  • Integrate SAST, DAST, dependency, container, infrastructure-as-code, secret, and software supply-chain scanning into development and release workflows
  • Establish security reviews, release controls, SBOMs, artifact provenance, and automated security regression testing
  • Conduct penetration tests, red-team and purple-team exercises, architecture attacks, and abuse-case testing
  • Assess vulnerabilities, coordinate remediation with engineers, validate fixes, and eliminate recurring weaknesses
  • Protect model weights, training and evaluation data, datasets, embeddings, registries, research artifacts, GPU infrastructure, and software supply chains
  • Define telemetry, alerting, containment, and forensic capabilities for incidents involving users, services, agents, models, and data
  • Translate SOC 2 and customer security requirements into technical controls and support FedRAMP and NIST SP 800-53 readiness
  • Automate evidence collection and control validation
  • Mentor engineers, establish reusable patterns, document architectural decisions, and communicate risks to technical teams and leadership
  • Within the first year, establish clear risk-based security architecture, explicit controls and adversarial coverage, secure-by-default workflows, integrated testing, remediation ownership, and a technical path toward FedRAMP readiness

Requirements

  • 7+ years of experience in product security, application security, cloud security, offensive security, or security-focused software engineering
  • Strong software engineering ability in at least one production language such as Python, Go, Rust, or TypeScript
  • Deep experience securing modern cloud and SaaS systems, including web applications, APIs, distributed services, databases, containers, Kubernetes, CI/CD, and infrastructure as code
  • Strong knowledge of authentication, authorization, IAM, tenant isolation, secrets management, encryption, network boundaries, logging, and secure software supply chains
  • Hands-on experience with threat modelling, architecture review, secure code review, vulnerability analysis, penetration testing, and remediation
  • Attacker-informed mindset developed through authorized red teaming, white-hat research, bug bounties, consulting, internal product-security work, or similar experience
  • History of delivering durable fixes through architecture changes, code contributions, shared security systems, or elimination of vulnerability classes
  • Judgment to balance security, product velocity, usability, and business risk
  • Ability to influence critical decisions across teams without formal authority
  • Clear written and verbal communication, intellectual honesty, high agency, and comfort with emerging threat models and architecture
  • Bonus: security experience with LLM applications, agentic systems, RAG, tool use, MCP integrations, code-generating systems, or multi-agent orchestration
  • Bonus: experience designing secure sandboxes, delegated authorization systems, machine identities, or fine-grained policy enforcement
  • Bonus: experience securing model training, evaluation, inference, model registries, datasets, embeddings, or GPU and Kubernetes infrastructure
  • Bonus: experience implementing technical controls for SOC 2 Type II, FedRAMP, or NIST SP 800-53
  • Bonus: published vulnerability research, CVEs, meaningful bug-bounty findings, open-source security tools, or respected security-community participation
  • Bonus: deep Linux/Unix, TCP/IP, DNS, routing, firewall, proxy, VPN, AWS PrivateLink, VPC endpoint, private subnet, and controlled ingress/egress expertise
  • Bonus: experience establishing product security architecture in a high-growth startup, frontier technology company, or research environment
  • Resume and brief description of a security architecture, product-security system, or authorized offensive-security project required

Benefits

  • Remote-first work environment
  • Opportunity to shape foundational security architecture for AI scientific systems
  • Substantial influence over architecture, engineering practices, and security roadmap
  • Mentorship and capability-building opportunities
  • Opportunity to work with AI, scientific discovery, cloud infrastructure, and adversarial security
  • Global team collaboration across Canada, the US, and the UK

Job type

Full Time

Experience level

Lead

Salary

Not specified

Degree requirement

No Education Requirement

Tech skills

AWSCloudDNSKubernetesLinuxPythonRustTCP/IPTypeScriptUnixGo

Location requirements

RemoteCanada

Report this job

Found something wrong with the page? Please let us know by submitting a report below.