
Security Engineer, Product Security
Job description
About the role
Join the Product Security team to protect the integrity of our AI and machine learning software ecosystem. You will drive security initiatives, perform deep code analysis, and define the technical strategy for safeguarding our infrastructure and product offerings. In this capacity, you will act as a subject matter expert responsible for identifying, mitigating, and preventing security risks across the entire product lifecycle. The role requires a proactive mindset to anticipate threats before they materialize and to embed security into every engineering decision. You will partner closely with cross-functional teams to ensure that security is not an afterthought but a foundational component of our development process. This position is critical for maintaining customer trust and ensuring that our AI platforms remain resilient against evolving adversarial tactics. You will own the end-to-end security posture for specific products, translating complex threats into actionable plans for engineering execution.
Key facts
What you'll do
- Build and maintain security tooling for the AI and machine learning software stack using infrastructure as code methodologies.
- Conduct thorough code reviews to detect and fix vulnerabilities in production services and internal tools.
- Assess product security through service and RFC reviews to ensure alignment with internal security policies.
- Integrate security protocols into CI/CD pipelines to automate compliance and reduce manual overhead.
- Execute SAST and DAST to uncover production code flaws and validate the effectiveness of existing controls.
- Manage infrastructure security using terraform orchestration to provision and monitor secure cloud resources.
- Advise engineering teams on long-term privacy and security architecture to support scalable product initiatives.
- Communicate technical security risks and exploitability to various stakeholders through clear and concise reporting.
- Shape the team security strategy and promote best practices by leading security champions across multiple engineering teams.
- Perform threat modeling exercises to identify potential attack vectors and prioritize remediation efforts accordingly.
- Collaborate with incident response teams to investigate security events and contribute to post-incident review processes.
- Mentor junior engineers on secure coding practices and threat awareness within the context of daily development activities.
- Track and document security metrics to measure the effectiveness of implemented controls and improvements over time.
- Ensure that all security activities comply with regulatory requirements and industry standards relevant to AI and data platforms.
Requirements
- Proven experience as a Security Engineer in a product-focused role with a track record of delivering measurable security outcomes.
- Ability to lead multi-month security projects independently from start to finish while managing competing priorities and deadlines.
- Production experience securing and operating AWS environments including identity, compute, and data services.
- Proficiency in Python, TypeScript, NodeJS, and Kubernetes to develop and review secure implementations.
- Deep understanding of modern Javascript application design including client-side and server-side architectures.
- Practical experience with SAST and DAST methodologies and the tools used to execute these testing strategies.
- Familiarity with terraform orchestration for provisioning cloud infrastructure and managing security configurations.
- Strong problem-solving skills with the ability to diagnose root causes without supervision in complex distributed systems.
- Excellent communication skills for technical and non-technical audiences to convey risk implications and remediation strategies.
- Demonstrated ability to work autonomously in a fast-paced environment with minimal direct oversight.
- Understanding of secure software development lifecycle practices and how they integrate with agile engineering workflows.
- Willingness to stay current with emerging threats, attack techniques, and defensive technologies relevant to AI systems.
- Commitment to following established security policies, procedures, and best practices across all engineering teams.
- Capability to obtain and maintain necessary security clearances if required for specific internal projects or client engagements.
Nice to have
- Relevant security certifications such as CISSP, CEH, or OSCP.
Practical notes
Compensation includes base salary, equity, and benefits such as health, dental, vision, retirement plans, learning stipends, and PTO. Candidates who have applied for this role previously must wait 90 days before reapplying. For disability-related accommodations during the hiring process, contact accommodations@scale.com.