Job Description
Leverage specialized security expertise to identify and resolve complex security issues, recommending best practices and determining new approaches that have an impact on broader security operations, while aligning security strategies with business priorities Partner across teams and key stakeholders to drive security initiatives, leading and solutioning complex projects and programs to strengthen overall security posture. Apply advanced analytical skills and sound judgment to solve security challenges, considering diverse perspectives and innovative solutions. Stay current with industry trends and emerging technologies, understanding their security implications to the company's context. Directly contribute to improvements within the security domain and occasionally beyond, ensuring decisions lead to meaningful enhancements in security practices. Leverage relationships across teams, both within and outside of security, to influence initiatives and integrate feedback into security processes. Lead the development and execution of Product Security's technical roadmap for AI security controls and assurance, partnering with Security Architecture to translate requirements into scalable engineering capabilities. Design, implement, and operate controls for AI-assisted software development, including security review of AI-generated code, security context and constraints for coding agents, automated testing, and risk-based enforcement. Conduct and lead security reviews of AI-enabled applications and their models, agents, retrieval systems, data flows, and external tool integrations. Create controls for agent identity, least privilege, tool access, execution isolation, human approval, and interruption of unsafe behavior. Design and help implement security controls for AI models, agents, toolsets, datasets, and pipelines. Develop runtime monitoring, auditability, detection, containment, and incident-response requirements for AI systems, including visibility into agent actions, tool calls, and sensitive-data access. Build and scale AI-driven capabilities for vulnerability discovery, validation, prioritization, and remediation across teams and engineering workflows. Partner with AI platform and cloud engineering teams to integrate security across AI infrastructure, platforms, and workloads. Help establish security criteria for evaluating, onboarding, integrating, and periodically reassessing third-party models, AI services, APIs, and developer tools. Develop methods and metrics for evaluating AI security risk, control effectiveness, remediation performance, and adoption across teams. Serve as a technical escalation point for complex AI security issues and lead architectural reviews following significant incidents or control failures. Mentor security and engineering professionals, deliver targeted technical guidance, and help teams apply AI security controls across diverse technology stacks. Your work will vary across hands-on engineering, technical leadership, and cross-functional program delivery. Reviewing an AI architecture, threat model, or agent workflow and identifying material security risks. Designing, prototyping, or integrating an AI security control into a product, shared platform, or engineering workflow. Evaluating results from AI security scanners, adversarial tests, and runtime monitoring to determine required engineering action. Partnering with developers and platform teams to resolve complex design or implementation issues. Analyzing control coverage, effectiveness, adoption, and incident findings to determine program priorities. Mentoring engineers and leading technical decisions that span multiple teams or organizational boundaries. 5+ years relevant experience and a Bachelor's degree OR Any equivalent combination of education and experience. 5+ years of experience in software engineering, application security, product security, or cybersecurity, including leadership of complex security initiatives spanning multiple teams or technology platforms. Deep knowledge of application security vulnerabilities, secure software development practices, and technical controls used to identify, prevent, and remediate software risk. Hands-on experience securing AI systems. Strong software-engineering experience building and operating production security tooling, automation, platform services, or developer-facing capabilities. Track record of partnering with developers to implement robust security controls. Strong written and verbal communication skills, with the ability to influence technical and senior stakeholder audiences. Experience designing and operating security controls across cloud environments, CI/CD systems, and diverse application and infrastructure stacks. Experience mentoring and developing engineers. Hands-on familiarity with application security tools (SAST, DAST, SCA, WAF, Burp Suite). Strong programming experience in at least one language such as Ruby, Java, Python, JavaScript, or Swift. Knowledge of Kubernetes, Terraform, and version control systems such as Git. Hands-on experience with at least one major cloud vendor (AWS, Azure, GCP). Strong understanding of authentication and authorization protocols (OAuth 2.0, SAML). This is a hands-on individual contributor role with cross-organizational scope. You will help set technical direction, lead delivery, and mentor engineers while remaining directly involved in architecture reviews, control design, implementation, and technical problem-solving.