Product Security Engineer
AirtableUSA6d ago
SecurityEngineeringremotecurated-jd
Job description
Product Security Engineer at Airtable
About the role
Airtable is seeking a Product Security Engineer to enhance the security of its growing platform, especially as it incorporates AI and LLM features. You will be part of the team dedicated to protecting the application layer of Airtable's services.
Key facts
What you'll do
- Build self-service security tools and standard practices that simplify secure code development for engineering teams.
- Implement automated defenses against common security weaknesses and conduct in-depth reviews of complex logic and data protection, particularly concerning multi-tenancy and access control.
- Collaborate with product and engineering groups to provide early design feedback, contribute to threat assessments for new features, and offer clear, actionable security guidance.
- Investigate new threats and security best practices, with a focus on AI and LLM safety, and develop controls to secure these functionalities.
- Oversee and refine the company's approach to external security testing and bug bounty programs, managing vulnerability remediation as an engineering challenge.
- Contribute to the long-term strategy, metrics, and roadmaps for the security department.
- For Senior/Staff level candidates: Lead threat modeling for major product releases, establish secure coding standards, and mentor other engineers to improve overall security expertise.
Requirements
- A minimum of 4 years of experience in product security or application security, including experience with shipping production code. This role is not for entry-level candidates.
- A solid foundation in computer science or a related discipline, with the ability to write well-structured and maintainable code.
- Extensive familiarity with JavaScript or TypeScript, Node.js, and contemporary web application frameworks, including an understanding of their security implications.
- Practical experience in securing LLM integrations and identifying risks such as prompt injection or data leakage.
- Proficiency in writing and reviewing code, approaching security as an engineering problem solvable through software.
- Skill in communicating complex security risks to non-technical audiences and a talent for cross-functional collaboration to balance security with development speed.
- Comfort working in a dynamic environment, managing uncertainty, continuously learning about new threats and technologies, and contributing to security strategy.
Nice to have
- Experience with security reviews of AI/LLM integrations.
Skills & tools
- JavaScript/TypeScript
- Node.js
- Modern web application frameworks
Practical notes
- Base salary range for San Francisco, Mountain View, Seattle, New York, and Los Angeles locations is $187,000 - $260,000 USD.
- Total compensation includes benefits, restricted stock units, and potential incentive compensation.
- Information on benefits can be found at Life at Airtable.
- Airtable is an equal opportunity employer and welcomes diversity.
- Information regarding accommodations for candidates with disabilities or medical conditions can be found via an Accommodations Request Form.
- All official Airtable communications will use an @airtable.com email address.