Senior Security Engineer

Cohere Cohere · AI Frontier · Toronto, ON · Product

Senior Security Engineer role focused on application security, vulnerability management, and integrating security into CI/CD and cloud-native environments at an AI company. The role involves advising leadership, leading security operations, collaborating with development teams, and assessing/automating security tools.

What you'd actually do

  1. Serve as trusted advisor to team’s leadership and partner teams by clearly articulating business risks associated with security issues
  2. Lead security operation functions – including vulnerability management, SAST, DAST, detection engineering, and incident response – in CI/CD and cloud-native production environments
  3. Integrate security into our applications throughout the software development lifecycle
  4. Collaborate with product and development teams, driving the success of larger projects to ensure that software is built and deployed securely without compromising agility and speed
  5. Driving and supporting bug bounty program, application security reviews and threat modeling, including code review and dynamic testing

Skills

Required

  • 5+ years previous experience in Application/Product Security or Security Operations
  • strong focus on security tool onboarding and optimization
  • understanding of vulnerability management
  • network security
  • cloud security concepts
  • industry best practices across many fields of security
  • comfortable with ambiguity
  • able to make informed decisions with little data
  • flexible and constructive approach when solving problems
  • able to make trade-offs between build vs. buy decisions
  • understand secure engineering best practices
  • articulate problem statements and propose solutions to both technically savvy and non-technical audiences
  • deep technical understanding of common security vulnerabilities and risks
  • countermeasures and compensating controls
  • hands-on security engineer interested in automating controls

Nice to have

  • AI systems security

What the JD emphasized

  • security tool onboarding and optimization
  • automate security processes