Назад
3 дня назад

Senior Product Security Engineer (AI)

260 000 - 385 000CAD
Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
France/UK/US +3 еще
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Product Security Engineer (AI): Securing enterprise AI products through architecture and code reviews, threat modeling, hands-on vulnerability testing, and scalable security guardrails with an accent on agentic systems, authorization, isolation, and untrusted input. Focus on investigating prompt injection, unsafe tool use, data exposure, tenant-boundary failures, sandbox escapes, and translating complex findings into practical engineering fixes.

Location: Remote in Canada

Salary: CAD 260,000–385,000 per year plus equity for Canada; US compensation ranges from USD 180,000–275,000 or USD 215,000–325,000 depending on state.

Company

Cohere is a security-first enterprise AI company building foundation models and end-to-end AI products for business workflows.

What you will do

  • Lead security reviews of architecture, production code, and security-sensitive changes.
  • Evaluate AI-product risks including prompt injection, unsafe tool use, identity and delegation failures, excessive agency, data exposure, tenant isolation, and sandbox escapes.
  • Threat model new capabilities, identify trust boundaries and abuse cases, and define prioritized mitigations.
  • Investigate vulnerabilities, develop proofs of concept, assess exploitability, and partner with engineers on remediation.
  • Build secure defaults, reusable controls, review requirements, and automated checks.
  • Pair with engineers and communicate technical findings, business impact, and remediation options to technical and executive audiences.

Requirements

  • Strong software engineering fundamentals and the ability to understand, test, and contribute fixes to production codebases.
  • Proficiency in at least one of Python, Go, or TypeScript.
  • Experience leading security reviews or threat models for complex production systems and delivering meaningful risk improvements.
  • Knowledge of vulnerability classes including injection, authorization flaws, IDOR, SSRF, unsafe deserialization, race conditions, cryptographic misuse, and supply-chain risks.
  • Understanding of web applications, APIs, OAuth/OIDC, cloud platforms, containers, Kubernetes, and CI/CD systems.
  • Must be based in Canada for the remote role.

Nice to have

  • Experience with SAST, DAST, SCA, custom linters, or policy-as-code.
  • Experience securing multi-tenant SaaS, enterprise software, or systems handling sensitive customer data.
  • Penetration testing, red teaming, security research, vulnerability disclosure, or bug bounty experience.
  • Open-source security contributions, published research, conference talks, or credited vulnerability discoveries.

Culture & Benefits

  • Remote-friendly work environment with coworking support for employees away from an office.
  • Six weeks of paid vacation and an annual company offsite, with travel support for remote employees visiting other offices.
  • Health and dental benefits, mental-health support, pension or retirement matching, and parental-leave top-up for up to six months.
  • Annual benefits covering arts and culture, fitness and wellness, quality time, and workspace improvements.
  • Education and learning stipend, weekly lunch stipend, and a $500 home-office setup stipend.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →