Software Engineer, Platform Security
$200k - $330k • San Francisco • FullTime
Posted 3mo ago
About the job
Decagon is seeking a Software Engineer, Platform Security to lead the application security strategy and implementation for their conversational AI platform. This role involves partnering with engineering teams to embed security directly into AI-powered applications, ensuring protection against threats while maintaining performance and reliability. The position offers a unique opportunity to apply deep application security expertise to AI systems and influence security practices within a rapidly growing engineering organization.
Responsibilities
- Design and implement application security controls across the AI agent platform, including secure coding practices, threat modeling, and vulnerability management.
- Collaborate with product engineering teams to integrate security throughout the software development lifecycle.
- Establish application security testing programs (SAST, DAST, IAST) tailored for AI applications.
- Lead security code reviews and architecture assessments for new features, focusing on AI model integration and customer data handling.
- Build security tooling and automation to help developers quickly identify and remediate vulnerabilities.
- Respond to security incidents involving application vulnerabilities and coordinate remediation efforts.
Requirements
- 3-5 years of hands-on application security engineering experience.
- Expertise in secure software development practices, including threat modeling, secure code review, and vulnerability assessment.
- Strong software engineering background with the ability to review code in multiple languages and frameworks used in AI/ML applications.
- Experience implementing application security testing tools and integrating security into CI/CD pipelines.
- Knowledge of OWASP Top 10, common application vulnerabilities, and modern application security frameworks.
- Proven track record of working with engineering teams to remediate security findings while balancing security and business requirements.
- Experience securing AI/ML applications, including prompt injection, model extraction, and adversarial input protections.
- Background with large-scale, multi-tenant SaaS applications handling sensitive customer data.
- Familiarity with Google Cloud application security services and container security best practices.
- Knowledge of enterprise compliance requirements (SOC 2, ISO 27001, GDPR) from an application security perspective.
- Experience with modern security tools like Semgrep, CodeQL, Cursor Bug Bot, XBOW, or similar.
Benefits
- Equity
- Medical, Dental, and Vision benefits for you and your family
- Life Insurance and Disability Benefits
- Retirement Plan (e.g., 401K, pension)
- Parental Leave
- Fertility and family building benefits through Carrot
- Monthly stipend to support wellness, lifestyle, and work-life balance
- Daily lunches and snacks in the office