Security Engineer
Location: Seattle, WA β Preferred / Sunnyvale, CA β Local Candidates Preferred
Employment Type: W2 Only
Only w2 profiles no c2c
Role Overview
We are looking for experienced Security Engineers to support Engineering Security initiatives focused on security and privacy reviews, threat modeling, and third-party AI Agent security testing.
The selected candidate will work closely with Engineering, Security, Privacy, and third-party teams to identify security risks, perform hands-on assessments, and provide actionable remediation guidance.
Key Responsibilities
Conduct security and privacy design reviews of services, applications, APIs, engineering proposals, and AI integrations.
Evaluate architecture, data flows, access controls, trust boundaries, and security safeguards.
Perform threat modeling for critical services and AI agents, identifying attack surfaces, threat scenarios, attack paths, mitigations, and residual risks.
Conduct hands-on security testing of third-party AI agents, including:
Document security findings, risk assessments, supporting evidence, and practical remediation recommendations.
Partner with Engineering and Security teams through remediation and validation.
Develop repeatable security assessment processes, including review checklists, threat models, test cases, reporting templates, and automation workflows.
Minimum Qualifications
3+ years of professional experience in Security Engineering, Application Security, Product Security, Offensive Security, Systems Architecture, or a related technical security field.
Experience reviewing complex technical designs and identifying security risks across applications, APIs, cloud services, microservices, or distributed systems.
Strong knowledge of:
Hands-on experience with security testing, vulnerability investigation, penetration testing, adversarial testing, or security-control validation.
Strong communication skills with the ability to explain technical security findings to Engineering, Security, Privacy, and third-party stakeholders.
Preferred / Good to Have
Experience assessing AI/LLM agents and AI security risks.
Hands-on knowledge of prompt injection, unsafe tool use, excessive agency, and AI security testing.
Experience with privacy and security design reviews.
Cloud security experience across AWS, Azure, or Google Cloud Platform.
Experience with security automation using Python, Go, Bash, or similar languages.
Hands-on penetration testing and vulnerability assessment across applications, APIs, cloud infrastructure, and networks.
Experience identifying and validating real-world attack paths and providing actionable remediation guidance.
Note: Candidates must be able to work on W2.
Local candidates in Seattle, WA or Sunnyvale, CA are strongly preferred.