Product Security Engineer

Applied Intuition Applied Intuition · Robotics · Sunnyvale, CA · Security & IT Operations

This role focuses on embedding security into the product design and development lifecycle for an AI company. The engineer will analyze architectures, conduct security assessments using AI-assisted testing, mature vulnerability management, provide secure coding guidance, collaborate with incident response, and mature SAST/DAST tooling. The role requires experience in security engineering, programming languages, security tools, AI implementation for security, cloud security, and CI/CD pipeline security.

What you'd actually do

  1. Analyze Applied Intuition’s applications and system architectures from their inception to release. Proactively identify potential security vulnerabilities and integrate robust security controls and conduct architecture reviews and threat modeling.
  2. Conduct regular security assessments and utilize AI-assisted testing on products and systems to systematically identify and mitigate vulnerabilities before they can be exploited.
  3. Assist in maturing Applied’s vulnerability management program and drive risk-contextualized resolutions discovered through various security platforms, collaborating closely with development teams.
  4. Provide continuous guidance and education to developers on secure coding practices, emerging threats, and general security best practices to cultivate a security-conscious culture.
  5. Collaborate with incident response teams and join security incident calls that impact product operations and create targeted remediation suggestions based on current threat landscapes.

Skills

Required

  • 5+ years of demonstrable experience as a Security Engineer, Application Security Engineer, or Product Security Engineer within a highly complex, rapidly scaling software organization.
  • Proficiency in modern programming languages (such as Python, Typescript, etc.)
  • Knowledge of security tools (e.g., Burp Suite, OWASP ZAP)
  • Familiarity with modern security protocols and encryption methods.
  • Implemented AI to rapidly identify, validate, and scale security programs.
  • Deep, practical knowledge of container security (Kubernetes)
  • Securing ephemeral workloads across major public cloud platforms (AWS, GCP, Azure) and on-premises environments.
  • Hands-on experience deploying, tuning, and automating SAST, DAST, and CI/CD pipeline security tools.
  • Specific operational experience configuring and driving remediation through cloud security platforms.
  • Proven experience securing large-scale platform migrations and managing the distinct security lifecycles of both legacy systems and modern microservices.

Nice to have

  • Direct professional experience in the autonomous vehicle, automotive, aerospace, or defense sectors.
  • Familiarity with physics-based simulation environments, deterministic computing constraints, or managing High-Performance Computing (HPC) clusters.
  • Demonstrable contributions to open-source security tools, published vulnerability research, or recognized vulnerability disclosures (CVEs)

What the JD emphasized

  • Implemented AI to rapidly identify, validate, and scale security programs