Product Security Engineer

Airtable Airtable · Enterprise · San Francisco, CA · Engineering

Product Security Engineer at Airtable, focusing on securing the application layer of their platform, including AI/LLM powered features. The role involves developing self-service security frameworks, automated guardrails, threat modeling, and securing LLM integrations. Experience in product security, web application security, and securing LLM integrations is required.

What you'd actually do

  1. Develop self-service security frameworks and "paved roads" that allow engineering teams to ship secure code by default.
  2. Focus on automated guardrails for common vulnerabilities, while prioritizing deep-dive design reviews into complex business logic and data isolation issues (for example, multi-tenant isolation and authorization/permission bypasses) that automated tools cannot catch.
  3. Partner with product and engineering teams to review designs early, contribute to threat modeling for new features and complex initiatives, and provide clear, actionable security guidance.
  4. Research emerging threats and evolving best practices, specifically regarding AI and LLM safety, and implement controls to secure these workflows.
  5. Manage and evolve our approach to external penetration testing and bug bounties, driving remediation for findings and treating vulnerability management as an engineering problem.

Skills

Required

  • Product security
  • Application security
  • JavaScript or TypeScript
  • Node.js
  • Modern web application frameworks
  • Securing LLM integrations
  • Prompt injection
  • Data leakage risks
  • Writing and reviewing code
  • Communicating complex security risks
  • Collaborating cross-functionally

Nice to have

  • Experience shipping production code
  • Deep familiarity with modern web application frameworks
  • Proficiency in writing clean, maintainable code
  • Treat security as an engineering problem to be solved with software, not just policies
  • Balancing security with engineering velocity
  • Working in a fast-paced environment
  • Navigating ambiguity
  • Continuously learning about emerging threats and technologies
  • Contributing to long-term security strategy

What the JD emphasized

  • 4+ years of experience in product security or application security, with experience shipping production code.
  • Please note this is not an early career position.
  • hands-on experience securing LLM integrations and identifying prompt injection or data leakage risks.