AI Application Security Engineer
Brainco · San Francisco Bay Area
About this role
## AI Application Security Engineer ### About Brain Co. Brain Co. builds AI-native operating systems for large, regulated institutions. Each system is powered by agents that push real workflows forward, backed by **Atlas**, a proprietary platform designed to keep customers **in control**, **secure by design**, and **not locked into one model**. ### Why Now Brain Co. is entering its next phase of **production deployments on a national scale**, with an elite team and a growing footprint across **government, insurance, health, and financial services**. Projects here ship to production and are expected to create measurable customer value and impact. ### About the Role As **Security Engineer, Application & AI**, you will own security for Brain Co.’s **products and application layer**, including: - Secure development practices (secure SDLC, secrets management, input handling) - **Agent security** - Third-party integration security - Data protection for AI products in highly regulated environments This is a **hands-on builder** role: you will write code, ship security tooling, and work directly with **product and ML engineers** to build security in from the start. You are expected to work **AI-natively**—using AI to help with threat modeling, automate security review, scale code analysis, and build internal tooling. ### What You’ll Work On #### Application Security - Own secure development practices across products (AuthN/AuthZ patterns, secrets management, secure-by-default standards) - Integrate security into the development lifecycle (code review, CI/CD pipelines, pre-deployment checks) - Conduct threat modeling across product features and release cycles - Build and maintain security tooling and automated checks that scale across the codebase #### Agent & Integration Security - Own the application-layer security model for agentic products (agent scope, authorization, trust boundaries) - Define secure patterns for third-party integrations and APIs (credential storage/scoping, response validation, limiting agent actions) - Partner with product and ML engineers to define secure agent design patterns (tool scoping, permission boundaries, output validation, safe handling of user context) - Create reusable secure-by-default patterns (design guidelines, review checklists, code-level guardrails) - Produce security artifacts for agent features and deployments (threat models, architecture reviews, documentation for regulated environments) #### Data Protection - Define and enforce data protection standards at the application layer (PHI, PII, government records) - Build safeguards against unauthorized data exposure (access controls, output filtering, audit logging) - Design secure data handling patterns for AI features operating on regulated data ### You Might Be a Great Fit If You… - Have **5+ years** of experience in application security or product security with hands-on experience on production systems at scale - Are a **builder first** (write code, ship security tooling, embed security into engineering workflows) - Have deep fluency in application security fundamentals (OWASP Top 10, AuthN/AuthZ, secure SDLC, secrets management, secure integration patterns, cryptography basics) - Understand the security surface of **agentic AI** at the product layer (design, scoping, review for risk) - Have experience protecting sensitive data at the application layer (access controls, audit logging, preventing exposure via integrations and AI outputs) - W
Listing freshness
CronJobs last confirmed this listing 53m ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.