Software Engineer - Platform Security
Job description
About the role
Join the Platform Security team at SpaceXAI to develop advanced security solutions for our Kubernetes infrastructure and AI-driven systems. You will design and implement AI-powered security tools, proactively address vulnerabilities, and promote secure engineering practices throughout the organization. This role is for someone who values innovation, writes clean code, and thrives in a fast-paced environment. You will partner closely with cross-functional teams to ensure security is built into every layer of our platform. Your work will directly influence the security posture of AI applications and infrastructure at scale. This is an opportunity to own complex security challenges from design through production deployment. You will be expected to bring creativity and rigor to identifying and resolving security threats before they impact the business. The ideal candidate will balance independent execution with strong collaboration across engineering and product teams.
Key facts
What you'll do
- Design and build AI-driven security tools and agents using Grok to identify, analyze, and mitigate vulnerabilities in platform infrastructure and customer applications.
- Proactively identify security problems and own their end-to-end design and implementation from discovery through resolution.
- Collaborate as a security champion and drive technical decisions across the organization to elevate security standards.
- Develop scalable backend architectures that form the foundation of secure systems and services.
- Implement and maintain security testing frameworks to automate vulnerability detection and compliance validation.
- Leverage Docker and Kubernetes to deploy, configure, and secure containerized applications in production environments.
- Manage software supply chain risks by utilizing SBOM management and dependency scanning tools effectively.
- Conduct in-depth security analysis using Burp Suite and OWASP ZAP for application security testing.
- Apply SAST and DAST methodologies to identify code-level and runtime security issues.
- Translate complex security requirements into practical implementation plans that align with engineering velocity.
- Mentor and enable other engineers to adopt secure coding practices and threat modeling techniques.
- Investigate security incidents, perform root cause analysis, and implement preventative controls.
- Optimize security toolchains to improve detection accuracy and reduce false positives.
- Contribute to open source security projects and internal tools that enhance the security ecosystem.
Requirements
- 3 or more years of experience in fast-paced, high-impact environments, such as startups or tech companies.
- Expertise in Python, Rust, or Go, with strong problem-solving skills and a focus on clean, efficient code.
- Proven experience building tools or systems from scratch, with an emphasis on scalable solutions.
- Proficiency in designing scalable backend architectures for secure systems.
- Familiarity with security testing frameworks.
- Experience with Docker and Kubernetes for deploying and securing containerized applications.
- Knowledge of software supply chain tools, including SBOM management and dependency scanning.
- Strong understanding of security fundamentals, including authentication, authorization, encryption, and network security.
- Ability to read, write, and review code in at least one systems-level programming language.
- Experience with cloud platforms and infrastructure as code practices is expected.
- Track record of identifying and resolving security issues independently.
- Commitment to staying current with evolving security threats and mitigation strategies.
- Willingness to work within a technically rigorous and rapidly evolving environment.
Nice to have
- Experience developing AI-driven security tools or integrating AI into security workflows.
- Familiarity with Kubernetes-based environments and securing cloud-native infrastructure.
- Demonstrated ability to drive technical decisions and influence security practices across teams.
- Certifications like CISA, CRISC, CGEIT, Security+, CASP+, or similar.
- Strong collaboration skills, with experience working in dynamic, cross-functional teams.
- Background in threat modeling, risk assessment, or security architecture design.
- Experience contributing to security standards, policies, or best practices within an engineering organization.
- Familiarity with incident response processes and security observability tools.
Practical notes
The salary range for this position is $100,000 to $258,000 USD. The total compensation package includes equity, comprehensive medical, vision, and dental coverage, access to a 401(k) retirement plan, short and long-term disability insurance, life insurance, and various other discounts and perks.