Security Engineer (l5) - Workforce Security

Netflix Netflix · Big Tech · United States · Remote · Engineering

Security Engineer specializing in Generative AI (GenAI) Security for workforce-facing initiatives, focusing on third-party solutions like low-code/no-code agents and RAG enterprise search. Responsibilities include identifying and mitigating GenAI threats, evaluating third-party GenAI products, developing hardening guides, performing technical validation (threat modeling, pen testing), prototyping security automation tools, and conducting build-vs-buy evaluations.

What you'd actually do

  1. help drive the development of scalable technical security controls that enhance business agility and reduce risk
  2. focus on GenAI Security for workforce-related business scenarios
  3. focus on securing Netflix's workforce-facing GenAI initiatives, particularly third-party solutions for business productivity scenarios such as low-code/no-code agents and RAG enterprise search
  4. identifying and mitigating GenAI threats, educating stakeholders, and providing direct security support to internal partners
  5. evaluating the security posture of third-party GenAI products and their integration with internal/external systems (via MCP, OAuth, etc.)

Skills

Required

  • Ability to learn and spin up rapidly on quickly evolving GenAI solutions and security concerns
  • Some exposure to commercially available GenAI solutions related to search (RAG) and low-code/no-code agentic solutions from major AI 3rd party vendors.
  • High-level understanding of Machine Learning/AI fundamentals and architecture, including MCP, A2A, and LLMs
  • High-level understanding of GenAI Governance
  • GenAI threat taxonomy knowledge - OWASP GenAI Top 10.
  • Threat Modeling/Penetration Testing/Code Review/Code Comprehension Skills
  • Familiarity with modern GenAI development tools and techniques
  • Familiarity with Third-Party Risk Management (TPRM) methodologies
  • Scripting (must be able to script, not to production level, and use of GenAI is sufficient)
  • Autonomously drives work delivery (bias to action)
  • Cross-functional collaboration skills
  • High-level familiarity with the functionality of commercially available corporate security tooling in the areas of endpoint, identity, data, and vendor security.
  • Ability to navigate ambiguity by taking strategic goals and decomposing them into actionable project plans
  • Using measurement and metrics to drive decision-making and outcomes

Nice to have

  • Value a deeply collaborative team.
  • Use data to inform your judgment, and to support and communicate your decisions.
  • Effectively communicate complex subjects to our internal customers and partners.
  • Enjoy taking full ownership of open-ended problems, from concept to product, and effectively managing your own time.
  • Care about improving the systems around you and leaving things better than you found them.
  • Believe a diverse and inclusive team is a critical aspect of a sustainable and effective work environment.
  • Empathize with your customers, and have an interest in the overall product lifecycle.
  • Challenge the status quo and seek to find novel and customer-centric ways to solve problems.

What the JD emphasized

  • GenAI Security
  • third-party solutions
  • low-code/no-code agents
  • RAG enterprise search
  • security automation
  • build-vs-buy evaluations
  • OWASP GenAI Top 10
  • scripting (must be able to script, not to production level, and use of GenAI is sufficient)

Other signals

  • GenAI Security
  • third-party solutions
  • risk-based security assessments
  • security automation