Staff Product Security Engineer @FirstPrinciples
Product Management
Salary unspecified
Employment Type full-time
Posted 1mth ago

[Hiring] Staff Product Security Engineer @FirstPrinciples

1mth ago - FirstPrinciples is hiring a remote Staff Product Security Engineer. πŸ’Έ Salary: unspecified πŸ“Location: Northern America, Northern Europe

Role Description

We are looking for a Staff Product Security Engineer to define and build the security architecture for Theo and the cloud platform surrounding it. This is a hands-on software engineering and architecture role embedded within Engineering. You will review designs and code, build security-critical systems, test our platform adversarially, and help engineers make security a foundational property of the product.

Your goal will not simply be to identify risk or prevent releases. It will be to create secure defaults, reusable controls, and engineering systems that allow us to move quickly without compromising trust.

What You'll Do

  • Define the security architecture for Theo.
  • Design security across our SaaS application, APIs, cloud infrastructure, model-serving systems, agent runtimes, data platforms, research environments, and deployment pipelines.
  • Secure agent identity and authority.
  • Build robust authentication and authorization for users, services, and AI agents.
  • Secure tool and code execution.
  • Help design hardened execution environments for agent-generated and user-provided code.
  • Lead threat modelling and secure design.
  • Address AI- and agent-specific threats.
  • Build security-critical software.
  • Embed security into development.
  • Test the platform adversarially.
  • Own vulnerabilities through resolution.
  • Protect our AI and scientific assets.
  • Build detection and response into the platform.
  • Engineer compliance into the product.
  • Raise the security capability of Engineering.

Qualifications

  • 7+ years of experience in product security, application security, cloud security, offensive security, or security-focused software engineering.
  • Strong software engineering ability in at least one production language such as Python, Go, Rust, or TypeScript.
  • Deep experience securing modern cloud and SaaS systems.
  • Strong knowledge of authentication, authorization, IAM, tenant isolation, secrets management, encryption, network boundaries, logging, and secure software supply chains.
  • Hands-on experience with threat modelling, architecture review, secure code review, vulnerability analysis, penetration testing, and remediation.
  • An attacker-informed mindset developed through authorized red teaming, white-hat research, bug bounties, consulting, internal product-security work, or similar experience.
  • A history of moving beyond findings to durable fixes.
  • The judgment to balance security, product velocity, usability, and business risk.
  • The ability to influence critical decisions across teams without relying on formal authority.
  • Clear written and verbal communication, intellectual honesty, high agency, and comfort working where the threat model and correct architecture are still emerging.

Bonus if you have

  • Security experience with LLM applications, agentic systems, RAG, tool use, MCP integrations, code-generating systems, or multi-agent orchestration.
  • Experience designing secure sandboxes, delegated authorization systems, machine identities, or fine-grained policy enforcement.
  • Experience securing model training, evaluation, inference, model registries, datasets, embeddings, or GPU and Kubernetes infrastructure.
  • Experience implementing technical controls for SOC 2 Type II, FedRAMP, or NIST SP 800-53.
  • Published vulnerability research, CVEs, meaningful bug-bounty findings, open-source security tools, or participation in respected security communities.
  • Deep systems and network security expertise across Linux/Unix internals, TCP/IP, DNS, routing, firewalls, proxies, and VPNs.
  • Experience establishing product security architecture in a high-growth startup, frontier technology company, or research environment.

What Success Looks like

  • Theo has a clear, risk-based product and platform security architecture.
  • Critical agent, identity, tool-use, data-access, and code-execution paths have explicit boundaries, enforceable controls, and adversarial test coverage.
  • Engineering teams have secure-by-default components and workflows that prevent recurring vulnerabilities.
  • Security testing is integrated into product delivery, with clear ownership and measurable remediation.
  • SOC 2 controls are reflected in how the platform actually operates.
Before You Apply
️
remote Be aware of the location restriction for this remote position: Northern America, Northern Europe
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Staff Product Security Engineer @FirstPrinciples
Product Management
Salary unspecified
Employment Type full-time
Posted 1mth ago
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
️
remote Be aware of the location restriction for this remote position: Northern America, Northern Europe
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
Γ—
Apply to the best remote jobs
before everyone else

Access 125,000+ vetted remote jobs and get daily alerts.

4.9 β˜…β˜…β˜…β˜…β˜… from 500+ reviews

⚑ 127,054+ remote jobs, refreshed hourly

πŸ”” Real-time alerts: Apply first, direct to employer

πŸ›‘οΈ Vetted companies, no scams, true remote only

Unlock All Jobs Now

Maybe later