Position: Security Engineer – Engineering Security
Location: Seattle, WA (Preferred) / Sunnyvale, CA – Day 1 Onsite
Experience: 8+ Years
Mandatory Skills : The key focus areas include ERD security and privacy reviews, threat modeling, and third-party AI Agent security testing
Role Overview
We are looking for Security Engineers to support Engineering Security initiatives across security and privacy reviews, threat modeling, and third-party AI Agent security testing.
The selected engineers will work closely with engineering, security, privacy, and third-party teams to identify security risks, conduct hands-on assessments, and provide actionable remediation guidance.
Key Responsibilities
The selected resources will provide immediate execution capacity across ERD reviews, Threat Modeling, and third-party AI Agent security testing. Core responsibilities include:
- Conduct security and privacy design reviews of services, applications, APIs, engineering proposals, and AI integrations; evaluate architecture, data flows, access controls, trust boundaries, and proposed safeguards.
- Perform threat modeling for critical services and AI agents, identifying attack surfaces, threat scenarios, potential attack paths, mitigations, and residual risk.
- Assess third-party AI agents through hands-on adversarial security testing, including prompt injection, tool misuse, data access, permissions, external integrations, excessive agency, and sensitive-data exposure.
- Document actionable findings, risk assessments, supporting evidence, and practical remediation guidance; partner with engineering and security teams through remediation and validation.
- Support repeatable security assessment processes, including review checklists, threat models, test cases, reporting templates, and AI-assisted/automation workflows where appropriate.
Minimum Qualifications
- 8+ years of professional experience in security engineering, application security, product security, offensive security, systems architecture, or a related technical security field.
- Demonstrated experience reviewing complex technical designs and identifying security risks in applications, APIs, cloud services, microservices, or distributed systems.
- Strong knowledge of threat modeling, vulnerability classification, risk modeling, authentication/authorization, least privilege, and data protection principles.
- Hands-on experience with security testing, vulnerability investigation, penetration/adversarial testing, or validating security controls.
- Ability to communicate technical findings clearly and collaborate directly with engineering, security, privacy, and third-party stakeholders.
- Preferred qualifications include experience assessing AI/LLM agents, prompt injection and unsafe tool use, privacy design reviews, cloud environments, and security automation using Python, Go, Bash, or similar languages.
Good to Have
- Demonstrated hands-on penetration testing and vulnerability assessment experience across applications, APIs, cloud infrastructure, and networks, including identifying and validating real-world attack paths and providing actionable remediation guidance.