Product Security Engineer
AirtableUSA2w ago
Job description
About the role
Airtable is on the lookout for a Product Security Engineer to strengthen the security framework of its expanding platform, particularly as it integrates AI and large language model (LLM) functionalities. This position will involve working closely with a dedicated team focused on safeguarding the application layer of Airtable's offerings, ensuring that security is embedded in every aspect of product development.
Key facts
What you'll do
- Develop self-service security tools and establish standard practices that facilitate secure coding for engineering teams, ensuring that security is a priority from the outset.
- Implement automated defenses to counteract common security vulnerabilities, while conducting thorough reviews of complex logic and data protection, especially in relation to multi-tenancy and access control mechanisms.
- Collaborate with product and engineering teams to provide early-stage design feedback, contribute to threat assessments for new features, and deliver clear, actionable security recommendations.
- Research emerging threats and best practices in security, with a particular emphasis on AI and LLM safety, and devise controls to safeguard these functionalities.
- Manage and enhance the company's strategy for external security testing and bug bounty initiatives, treating vulnerability remediation as a challenge for engineering teams to tackle.
- Play a key role in shaping the long-term vision, metrics, and roadmaps for the security department, ensuring alignment with overall business objectives.
- For candidates at the Senior or Staff level: Lead threat modeling exercises for significant product launches, set secure coding standards, and mentor fellow engineers to elevate the overall security proficiency within the team.
- Actively participate in incident response activities, helping to identify and mitigate security incidents as they arise.
- Engage in continuous learning and professional development to stay updated on the latest security trends and technologies.
- Foster a culture of security awareness across the organization, encouraging best practices among all employees.
Requirements
- At least 4 years of experience in product security or application security, with a proven track record of deploying production code. This position is not suitable for entry-level applicants.
- A strong educational background in computer science or a related field, coupled with the ability to write clean, maintainable code.
- In-depth knowledge of JavaScript or TypeScript, Node.js, and modern web application frameworks, along with an understanding of their security implications.
- Hands-on experience in securing LLM integrations and recognizing risks such as prompt injection and data leakage.
- Proficiency in both writing and reviewing code, viewing security as an engineering challenge that can be addressed through software solutions.
- Excellent communication skills, capable of explaining complex security risks to non-technical stakeholders, and adept at collaborating across functions to balance security needs with development timelines.
- Ability to thrive in a fast-paced environment, managing ambiguity, and continuously learning about new threats and technologies while contributing to the security strategy.
Nice to have
- Familiarity with conducting security reviews of AI/LLM integrations, enhancing the security posture of these advanced technologies.
- Experience in leading security training sessions or workshops for engineering teams.
- Knowledge of compliance standards and frameworks relevant to product security.
Skills & tools
- Proficient in JavaScript/TypeScript
- Experienced with Node.js
- Familiar with modern web application frameworks
Practical notes
- The base salary range for positions located in San Francisco, Mountain View, Seattle, New York, and Los Angeles is between $187,000 and $260,000 USD.
- Total compensation includes benefits, restricted stock units, and potential performance-based incentives.
- Detailed information regarding benefits can be found on the Life at Airtable page.
- Airtable is committed to being an equal opportunity employer and values diversity in its workforce.
- Candidates requiring accommodations due to disabilities or medical conditions can find relevant information through the Accommodations Request Form.
- All official communications from Airtable will originate from an @airtable.com email address.