Senior Security Engineer, AI Incident Response
Job description
About the role
You will lead the design and execution of Snowflake's product-integrated incident response strategy for AI and LLM security. In this role, you will own the end-to-end response lifecycle for product-level security events, from detection and containment to remediation and post-incident improvement. You will act as the incident commander for critical AI incidents, coordinating across engineering, security, and customer-facing teams to protect Snowflake's AI product surface. You will translate evolving AI threat landscapes into actionable playbooks that enable rapid, data-driven responses at scale. Your work will directly shape how Snowflake and its customers defend against prompt injection, model abuse, agent hijacking, and data exfiltration through AI workloads. You will partner closely with product teams to embed security requirements into AI features from design through deployment, ensuring IR readiness is built in, not bolted on. Your leadership will drive meaningful security outcomes for enterprises that trust Snowflake with their most sensitive data and AI workloads.
Key facts
What you'll do
- Lead incident response for product-level security events, with deep focus on AI-specific threat vectors including prompt injection, model abuse, agent hijacking, and data exfiltration through AI workloads.
- Integrate incident response into AI product pipelines, working directly with teams shipping Cortex features, Snowflake Intelligence, and AI-powered developer experiences to embed security requirements from design through deployment.
- Develop and codify Snowflake's AI abuse response strategy, defining detection, containment, and remediation playbooks for LLM misuse, adversarial inputs, and AI-assisted attacks targeting Snowflake customers.
- Address technical debt across the AI product stack, ensuring that new Cortex and agentic architectures meet incident response readiness requirements from the ground up.
- Represent the incident response team to cloud engineering, AI platform teams, corporate security, and customer-facing business units to align on priorities and controls.
- Secure modern AI-native codebases operating across multi-cloud environments, including container-based inference services, RAG pipelines, vector stores, and agent orchestration layers.
- Partner with world-class AI and security engineering teams, providing expert guidance on secure architecture for high-impact AI features and customer-facing AI capabilities.
- Design and manage response capabilities built into Snowflake's AI operational infrastructure, from model serving endpoints to Cortex Search indexes and Snowpark ML pipelines.
- Lead with data, code, and automation to build tooling that accelerates detection and response for product security incidents at Snowflake scale.
- Drive meaningful security outcomes for the customers and enterprises trusting Snowflake with their most sensitive data and AI workloads.
Requirements
- 5+ years of experience in information security, primarily in incident response, security engineering, or product/application security (preferred).
- Direct experience serving as incident commander for product-focused security incidents.
- Experience leading or actively building an application or security engineering program, with a clear point of view on securing AI/ML systems.
- Experience with threat modeling and security testing across AI attack surfaces, including prompt injection, indirect injection, model inversion, embedding extraction, and supply chain attacks on AI dependencies.
- Familiarity with the unique data governance and security challenges introduced by LLMs, RAG architectures, and agentic systems.
- Working knowledge of cloud-native environments, including AWS, Azure, and GCP, and the threat landscape specific to SaaS and AI platforms.
- SQL proficiency, plus experience building automation and tools with common programming languages, with Python preferred.
- Strong communication skills, with the ability to translate security risk into actionable guidance for product teams.
- Empathy for developer experience, helping AI engineers ship securely rather than slowing them down.
- Bachelor's degree in Computer Science or a related field, or equivalent experience.
Nice to have
- Experience securing AI/ML infrastructure, including model serving, vector databases, embedding pipelines, API gateways, and LLM-integrated application architectures.
- Experience building agentic incident response capabilities, including skills, agents, and pipelines.
- Understanding of current attacker TTPs, including emerging AI-specific techniques such as adversarial ML, agent manipulation, and LLM jailbreaking in enterprise contexts.
- Familiarity with CI/CD and secure release lifecycle patterns, with an emphasis on building security into AI feature pipelines.
Practical notes
- Engagement is full_time based in Menlo Park, California, US.
- Candidates must be authorized to work in the United States without sponsorship now or at any time during the employment period.
- Snowflake is an equal opportunity employer and values diversity in its workforce.
- This role is focused on product security incident response for AI workloads within Snowflake's AI and agentic product portfolio.
- The successful candidate will operate at the intersection of security, AI, and product engineering, influencing both strategy and execution.
- This position requires collaboration across globally distributed teams and alignment with enterprise security standards.
- The candidate should be prepared to build and maintain security tooling that scales with Snowflake's rapid product innovation.