Senior Product Security Engineer

Crusoe · Data AI · San Francisco, CA - US · IT, Compliance, and Security

Senior Product Security Engineer role focused on building secure frameworks and controls for AI infrastructure and distributed systems, shipping production code, and integrating security into developer workflows.

What you'd actually do

  1. Design and build secure frameworks and patterns for high-performance AI workflows, agents, and models to protect our clients
  2. Create reusable security patterns for product microservices, focusing on service-to-service authorization, API security, and multi-tenant data isolation that scales across product lines
  3. Create developer-facing tools and automation that catch security issues early in the development cycle without slowing teams down
  4. Perform security reviews, penetration tests, code reviews, and system design reviews for Crusoe’s fleet of SaaS offerings.

Skills

Required

  • Golang
  • Node.js/JavaScript
  • distributed systems
  • gRPC services
  • REST APIs
  • microservice architectures
  • OAuth2
  • OIDC
  • SAML
  • JWT
  • RBAC/ABAC models
  • SAST
  • DAST
  • SCA
  • CI/CD integration
  • Semgrep
  • OWASP ZAP
  • Burp
  • GitLab
  • runtime application security
  • observability tools
  • Docker
  • Kubernetes
  • network security fundamentals
  • OWASP Top 10
  • secure coding practices
  • cryptography
  • secure design principles

Nice to have

  • reusable security frameworks
  • internal developer platforms
  • platform or infrastructure-adjacent security engineering
  • influencing security practices across multiple engineering teams
  • supply chain security
  • dependency risk management

What the JD emphasized

  • shipping production software
  • AI expertise
  • security foundations
  • secure systems
  • security controls
  • AI infrastructure
  • distributed systems
  • pragmatic, delivery-focused mindset