Source Job

US

  • Conduct offensive security research on agentic AI systems, identifying vulnerabilities like prompt injection and privilege escalation.
  • Build reusable security tooling and perform manual code reviews to strengthen product security across the SDL.
  • Represent Okta externally through research publications, conference talks, and mentor engineers on AI security.

Application Security Python Go Threat Modeling OAuth 2.0

17 jobs similar to Staff Product Security Engineer

Jobs ranked by similarity.

  • Embed inside 4-5 strategic enterprise customers as their dedicated technical partner for agent identity, writing production code and owning technical outcomes from prototype to production.
  • Architect and deploy Okta's agent security stack including Cross-App Access, Fine-Grained Authorization, MCP Gateway, and agent client registration into customer infrastructure.
  • Engage senior leadership, brief CISOs and CIOs, and align architecture decisions to frameworks like OWASP Top 10 for Agentic Applications and NIST AI RMF.

Okta secures access for 20,000 organizations and billions of users. We are a global community united by a drive to innovate, with an Equal Opportunity Employer culture.

US Canada

  • Define security architecture and build controls for AI platforms, training and inference workflows, and agentic systems.
  • Design reusable security patterns for identity, authorization, and runtime controls to constrain execution and data exposure.
  • Lead hands-on security reviews and influence security architecture through practical design changes and reusable controls.

Cerebras Systems builds the world's largest AI chip, 56 times larger than GPUs, delivering industry-leading training and inference speeds. With dozens of model releases and rapid growth, they have a non-corporate work culture that respects individual beliefs.

Latin America

  • Design and implement guardrails for agentic AI systems, including tool access controls and step-level validation.
  • Build runtime security controls like interceptors, policy enforcement, and kill-switches for AI behavior.
  • Implement non-human identity access controls, observability, and threat modeling for AI-driven activity.

Backblaze is the object storage leader in the open cloud movement, offering cloud storage built to unlock budgets and unburden administrators. Founded in 2007, the company has over $100m in revenue and manages over three billion gigabytes of data for 500K+ customers across 175+ countries, with a culture of innovation and inclusion.

Europe

  • Responsible for the foundational security posture of our organization.
  • Architect and build preventative guardrails and mitigate new risks introduced by first and third-party AI agents in our Enterprise.
  • Develop and set the long term roadmap for agentic AI identity and posture management, ensuring cohesive strategies for reducing risk from agentic AI use.

Twilio is shaping the future of communications, delivering innovative solutions to hundreds of thousands of businesses and empowering millions of developers worldwide to craft personalized customer experiences. Our dedication to remote-first work, and strong culture of connection and global inclusion means that no matter your location, you’re part of a vibrant team with diverse experiences making a global impact each day.

US Unlimited PTO 18w maternity 12w paternity

  • Own the managed AI platform posture end-to-end, anticipating changes and governing usage across the organization.
  • Build financial visibility with token tracking dashboards, anomaly detection, and ROI reporting for leadership.
  • Harden AI security posture by mitigating prompt injection risks and ensuring no sensitive data flows into AI prompts.

Chainguard is the trusted source for open source, delivering hardened, secure builds of open source software and AI agents. They are venture-backed by leading investors and count Fortune 500 enterprises like Anduril, Canva, and OpenAI as customers.

  • Define, implement, and maintain the AI security strategy across Deel's infrastructure and product ecosystem.
  • Lead security assessments and threat modeling for AI/ML models, LLM integrations, and agentic AI systems.
  • Evaluate and deploy AI Security Posture Management (AISPM) and AI Detection & Response (AIDR) solutions.

Deel is the all-in-one payroll and HR platform for global teams with a vision to unlock global opportunity. They are among the largest globally distributed companies with a team of 7,000 spanning more than 100 countries with a connected and dynamic culture.

Europe

  • Champion and implement security best practices and automated tooling across Spotify's infrastructure and platforms.
  • Partner closely with teams to integrate security throughout the software development lifecycle from design to deployment.
  • Conduct threat modeling, security reviews, and risk assessments for both AI and non-AI systems.

Spotify is the world's most popular audio streaming subscription service, unlocking the potential of human creativity by giving artists the opportunity to live off their art. With over 700 million users, the company values curiosity, collaboration, and a willingness to both teach and learn from others.

Global

  • Design and operationalize AI security architecture, guardrails, and secure-by-design patterns across the enterprise.
  • Engineer security controls for AI-enabled applications, internal AI agents, model hosting, RAG architectures, and training pipelines.
  • Implement data security controls with Microsoft Purview, focusing on AI-driven data access, classification, and protection.

J.S. Held is a global consulting firm that combines technical, scientific, financial, and strategic expertise to advise clients on value realization and risk mitigation. The firm provides a comprehensive suite of services and has a high-energy, collaborative environment that rewards hard work.

United States

  • Build and evolve the agent harness and orchestration that turns an LLM into a reliable autonomous pentester.
  • Design tools and validation layers to keep the agent reliable, with structured outputs and production-safety.
  • Own and grow evaluation infrastructure to measure and drive agent improvements.

Horizon3.ai is a fast-growing remote cybersecurity company that provides autonomous penetration testing through its NodeZero platform. The company fosters a culture of respect, collaboration, and ownership, with a team of former cyber operators and engineers.

United States

  • Perform penetration testing and design reviews to identify vulnerabilities and insecure designs.
  • Maintain and build internal tools to automate security efforts, including SAST and DAST testing.
  • Identify vulnerabilities, demonstrate business impact, and articulate risk to drive prioritization.

Brex is the intelligent finance platform that enables companies to spend smarter and move faster in over 200 markets. With tens of thousands of customers including DoorDash, Coinbase, and Zoom, Brex fosters a diverse and inclusive team culture where collaboration with some of the brightest minds in the industry is key.

US 4w PTO 12w maternity 12w paternity

  • Partner with Product and Engineering teams to integrate security into application design and development, leading threat modeling and secure code reviews.
  • Develop and implement automated security guardrails across the SDLC, investigate and prioritize application security findings.
  • Promote secure coding practices through training and coaching, and create security standards and procedures that scale across teams.

Quanata is an insurance technology innovation company that engineers advanced risk prediction and prevention solutions and builds a full-stack, flexible, digital & increasingly AI-native insurance platform. We are a remote-first company wholly owned and funded by State Farm, with a culture that prioritizes inclusivity and positive collaboration.

US Unlimited PTO

  • Design and build the AI security control plane to enable safe adoption of AI across the enterprise.
  • Partner with engineering and security teams to modernize the SDLC for an AI-enabled world.
  • Drive technical leadership by translating emerging AI risks into actionable engineering strategies.

Granicus provides cloud-based solutions for government communications, website design, meeting management, and digital services. With over 5,500 government agency clients, 300 million citizen subscribers, and a remote-first culture, it has been consistently recognized on the GovTech 100 list.

US Unlimited PTO

  • Engineer security infrastructure across AWS and Kubernetes including telemetry pipelines, cryptographic lifecycle, and compliance automation.
  • Build and maintain agentic AI workflows using tools like Claude Code and MCP integrations to automate security engineering tasks.
  • Embed security controls into deployment pipelines and develop threat models that inform architecture decisions.

Lumin Digital creates cutting-edge digital banking solutions for credit unions and banks as a 100% cloud-native company. Their culture is built on trust, respect, and boldness in a fully remote environment.

US Europe

  • Serve as a core safety partner embedded across product and research teams, providing Trust & Safety engineering support for all launches from early design through post-launch monitoring.
  • Build and maintain safety infrastructure ensuring Runway's models have a positive impact as they reach millions of users.
  • Design, execute, and continuously improve red teaming systems to proactively surface harmful outputs before production.

Runway builds AI to simulate the world through merging art and science, focusing on world models for general-purpose simulation. The team consists of creative, open-minded, caring, and ambitious people determined to change the world.

Global Unlimited PTO

  • Conduct threat modelling reviews of Technical Design Documents (TDDs) and provide actionable security recommendations early in the design process.
  • Perform application security assessments, including penetration testing, vulnerability assessments, and proof-of-concept development.
  • Investigate, triage, and respond to Bug Bounty program submissions, validating findings and driving timely remediation with engineering teams.

MoonPay is a unified payments platform for digital currency. Trusted by over 30 million customers and over 500 ecosystem partners, the company is committed to building a fairer, more open financial system with a culture of accountability and inclusivity.

Canada

  • Embed secure-by-design principles across cloud, SaaS, and AI-driven systems.
  • Lead threat modeling sessions and security design reviews for applications, APIs, and microservices.
  • Define security standards, mentor engineers, and drive organization-wide risk reduction programs.

Jobgether uses an AI-powered matching process to connect candidates with hiring companies quickly and objectively. They are a remote-first, globally distributed company with an inclusive engineering culture.

US

  • Write behavioral specs, architectural constraints, and feature requirements that agents implement against.
  • Build and maintain harness infrastructure including structural tests, linting rules, and CI gates.
  • Design validation systems where agents write the tests and you verify features work from the user's perspective.

Bolo.ai builds generative AI systems for the energy industry, making daily work faster, safer, and better for heavy industry workers. We have Fortune 500 contracts, production deployments, and growing enterprise demand, and we're scaling with a small, senior-leaning engineering team.