Security engineer, application security
Remote • New York City, NY • FullTime
Posted 2mo ago
Remote Work Policy
Fully remote
Employment Type
FullTime
Categories
Applied AI Engineer
About the job
As a security engineer at WRITER, you will build the foundational security for the AI systems that power major enterprises. You will operate at the intersection of application security, AI infrastructure, and developer enablement, collaborating with engineering teams to integrate security into the development lifecycle. This role involves defining enterprise AI application security, from threat modeling LLM architectures to creating automated security controls. You will address unique challenges in securing AI agents, protecting training data pipelines, and designing controls for novel AI systems, aiming to enable secure innovation rather than hinder it.
Responsibilities
- Integrate security into the AI platform by conducting threat modeling, designing secure architectures, and ensuring security considerations influence product decisions.
- Manage and enhance the application security program, including SAST/DAST scanning in CI/CD, security code reviews, and building automation for vulnerability detection.
- Collaborate with engineering teams to establish secure coding standards and create reusable security patterns.
- Design and recommend security features and products to protect customer environments.
- Leverage AI agents to improve security team velocity and proactively minimize risk.
- Conduct security assessments and penetration testing of applications, AI services, and APIs, and coordinate remediation efforts.
- Implement security controls for data pipelines, model training environments, and customer-facing AI agents.
- Research emerging threats in AI/ML security, focusing on LLMs and generative AI, and develop proactive defenses.
Requirements
- Minimum 4 years of application security engineering experience, with a proven record in securing large-scale production systems.
- Understanding of developer workflows and a commitment to balancing risk reduction with engineering velocity.
- Technical proficiency in at least two programming languages (Python, Java, Go, JavaScript/TypeScript) and the ability to review code across multiple languages.
- Knowledge of security tools and methodologies such as SAST/DAST, vulnerability management, security testing frameworks, and DevSecOps practices.
- Excellent communication skills to convey complex security concepts to both technical and non-technical audiences.
- A proactive, builder's mindset focused on automation, scaling, and empowering teams.
- Alignment with WRITER's values: Connect, Challenge, and Own.
Benefits
- Generous PTO and company holidays
- Medical, dental, and vision coverage
- 16 weeks paid parental leave
- Fertility and family planning support
- Early-detection cancer testing
- Flexible spending account options
- Health savings account with company contribution
- Annual work-life stipends (Wellness, Learning and Development)