Staff Product Security Engineer
$250k - $285k • San Francisco, CA - US • FullTime
Posted 1y ago
Remote Work Policy
On-site
Employment Type
FullTime
Categories
Applied AI Engineer
About the job
Crusoe is seeking a Staff Product Security Engineer with deep AI/ML security expertise to enhance the company's security posture across applications, infrastructure, and distributed AI systems. This is a highly technical role focused on advanced penetration testing, AI/ML attack surface research, and developing secure-by-design guardrails for engineering teams. The role operates at the intersection of offensive security, AI systems, and production engineering, with end-to-end ownership of security outcomes and influence over system design across the organization.
Responsibilities
- Perform advanced manual penetration testing across complex applications, infrastructure, Kubernetes, and distributed microservices.
- Lead offensive security initiatives, including red team operations, adversary simulation, and security research.
- Secure AI/ML systems end-to-end, covering LLM pipelines, vector databases, RAG architectures, and agentic workflows.
- Identify and research novel attack surfaces unique to LLMs and autonomous systems.
- Influence secure system design throughout the SDLC, embedding security into CI/CD pipelines, container images, and deployment workflows.
- Integrate and operationalize security tooling (SAST, DAST, SCA, container scanning) and drive remediation of application-layer vulnerabilities.
- Build internal security guardrails like hardened base images, reusable libraries, and policy-as-code frameworks.
- Develop production-grade security tooling and lead cross-functional security programs from design to deployment.
Requirements
- 8-10 years of deep hands-on experience in offensive security, including manual penetration testing, red team operations, and adversary simulation.
- Familiarity with modern C2 frameworks (e.g., Cobalt Strike, Sliver, Havoc), exploit development, and security research.
- Strong expertise across the AI/ML stack, including MLOps, inference architectures, vector databases, RAG, and agentic frameworks (e.g., ReAct, Reflexion).
- Experience building, deploying, and securing LLM pipelines and AI workflows in Kubernetes and/or bare-metal environments.
- Strong software engineering foundations with experience shipping production code in Go, Python, or Rust.
- Hands-on experience securing Kubernetes, containers, VMs, and CI/CD environments.
- Deep understanding of application security vulnerabilities, secure coding practices, and distributed system design.
- Demonstrated ability to lead complex, cross-functional security initiatives end-to-end.
- Strong communication skills with the ability to influence engineering teams and executive stakeholders.
Benefits
- Competitive compensation
- Restricted Stock Units
- Paid time off & paid holidays
- Comprehensive health, dental & vision insurance
- Employer contributions to HSA account
- Paid parental leave
- Paid life insurance, short-term and long-term disability
- Professional development & tuition reimbursement
- Mental health & wellness support
- Commuter benefits (parking & transit)
- Cell phone stipend
- 401(k) Retirement plan with company match up to 4% of salary
- Volunteer time off