Staff Security Engineer
Posted 4hrs ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
Staff Security Engineer securing cloud applications and AI/LLM systems at Robots & Pencils. Defining architecture, threat defenses, automation, and production security standards.
Responsibilities:
- Define security architecture and engineering standards across web, API, and cloud-native systems, leading the hardening of complex services
- Lead threat modeling and security design reviews across applications and AI systems, setting how risk is identified and prioritized
- Architect cloud security controls across identity, network, and data layers, owning IAM strategy, secrets management, and encryption
- Lead the integration of security automation into CI/CD pipelines, driving shift-left detection and policy-as-code across teams
- Lead detection engineering, logging, and incident response practices across production systems
- Own the security of AI and LLM-powered applications in production, defining defenses against prompt injection, data leakage, model abuse, and agentic-AI threats
- Lead the design and integration of AI services into production security workflows, including LLM APIs, tool and function calling, and multi-step agent flows for detection and triage
- Use tools like Claude, Cursor, and other modern AI assistants to ship higher-quality work at pace
- Partner with product, engineering, and leadership to shape security strategy and align technical direction with business outcomes
- Translate complex security tradeoffs, risks, and opportunities into clear narratives for technical and non-technical stakeholders
- Lead security reviews and technical discussions, raising engineering rigor across the team
- Engage with engineering, data, and client teams to align security work with business priorities and measurable outcomes
- Define security architecture and engineering standards, including responsible AI practices
- Mentor and grow junior and mid-level engineers through coaching, code reviews, and pairing
- Own ambiguous, high-stakes work through production with attention to reliability, cost, and safety
Requirements:
- Position is remote based in the US; applicants outside of the US will not be considered
- 7+ years of professional security or software engineering experience
- At least 3 years leading application and cloud security initiatives
- Deep expertise in application security, secure coding practices, and the OWASP Top 10
- Strong experience with threat modeling, penetration testing, vulnerability management, and secure code review
- Deep cloud security expertise across identity, network, and data layers
- Strong experience embedding security automation and policy-as-code into CI/CD pipelines
- Strong experience with detection engineering, logging, and incident response at scale
- Strong experience securing AI and LLM-powered applications, including prompt injection, data leakage, model abuse, and agentic-AI threats
- Experience with security, compliance, and governance frameworks
- Demonstrated leadership and technical mentoring experience across a team or organization
- Strong stakeholder communication skills, with the ability to translate technical depth across audiences
- Demonstrable, day-to-day usage and expert knowledge of AI-forward tools such as Claude and Cursor
- Excellent problem-solving skills and the ability to navigate highly ambiguous technical and business challenges with sound judgment
Benefits:
- Paid time off
- Medical insurance
- Dental insurance
- Vision insurance
- 401(k)



















