Staff Security Engineer
$230,000–$250,000 year
RemoteUnited States
Job Summary
Own AI and agentic security by establishing guardrails for cloud and data access, securing ML workloads, and publishing standards for engineering team adoption. Manage the Panther detection platform by defining strategy, coverage across log sources, and high-signal detection standards. Lead incident-response readiness through plan creation, playbook development, and tabletop exercises aligned with HIPAA breach timelines. Drive complex security work across teams by coordinating architecture reviews, threat modeling, and code security assessments. Mentor teammates on detection authoring and code review standards while building security automation tools to extend team reach.
Required Qualifications
- 8+ years in security and software engineering
- deep hands-on experience in AWS and cloud-native infrastructure
- working competence with containerized workloads (EKS)
- working competence with infrastructure-as-code (Terraform)
- A track record of leading complex security work across teams
- Depth in AI and agentic security
- securing LLM applications
- agentic frameworks
- MCP
- prompt-injection and agentic-access defenses
- Depth in threat detection engineering
- designing, authoring, and tuning detections in a modern SIEM
- reasoning about coverage against real threats
- Incident-response experience
- building the plan
- running the response
- The ability to write production code
- Python
- Go
- TypeScript
- build security tooling
- Strong writing and communication
- publish a standard other teams adopt
- explain a hard design to a non-security audience
- Working knowledge of SOC 2
- HIPAA
- the judgment to design controls that hold up without stalling delivery
- Experience mentoring and leveling up other engineers
- This role is fully remote within the US
Desired Qualifications
- Recognized AI-security work
- published standards or research
- contributions to AI-security tooling
- red-teaming of AI/LLM systems
- Startup experience
- health tech
- another regulated, data-sensitive environment
- Deeper specialization in container security
- Kubernetes/EKS
- Helm
- infrastructure-as-code and policy-as-code
- beyond working competence
- Experience consolidating or retiring a security platform
- a measurable cost or coverage result
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.