Senior Product Security Software Engineer in San Francisco

Energy Jobline
San Francisco, United States of America
yesterday

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English
Experience level
Senior
Compensation
$ 215K

Job location

San Francisco, United States of America

Tech stack

JavaScript
Artificial Intelligence
Software System Penetration Testing
Burp Suite
Software as a Service
Code Review
Continuous Integration
Software Debugging
Distributed Systems
Network Security
OAuth
OpenID
Open Web Application Security
Role-Based Access Control
JSON Web Token
Security Assertion Markup Language (SAML)
Secure Coding
Software Engineering
AI Infrastructure
Grafana
Software Security
Gitlab
Build Management
Containerization
Kubernetes
REST
Automation Anywhere
Docker
Static Application Security Testing
Go
Microservices
Dynamic Application Security Testing

Job description

We're seeking a Senior Product Security Software Engineer who is first and foremost a skilled software engineer with AI expertise. You'll design secure systems, build security controls that integrate seamlessly into developer workflows, and help raise the security bar across our AI infrastructure and distributed systems, all while maintaining a pragmatic, delivery-focused mindset.

What You'll Be Working On

  • Design and build secure frameworks and patterns for high-performance AI workflows, agents, and models to protect our clients
  • Create reusable security patterns for product microservices, focusing on service-to-service authorization, API security, and multi-tenant data isolation that scales across product lines
  • Create developer-facing tools and automation that catch security issues early in the development cycle without slowing teams down
  • Perform security reviews, penetration tests, code reviews, and system design reviews for Crusoe's fleet of SaaS offerings.

Requirements

  • 7+ years of experience shipping production software with strong system design skills

  • Deep expertise in Golang and Node.js/JavaScript, with experience building and debugging distributed systems Hands-on experience securing gRPC services, REST APIs, and microservice architectures

  • Strong background implementing authentication and authorization systems using OAuth2, OIDC, SAML, JWT, and RBAC/ABAC models

  • Production experience with application security tooling (SAST, DAST, SCA) and CI/CD integration (e.g., Semgrep, OWASP ZAP, Burp, GitLab)

  • Knowledge of runtime application security and observability tools

  • Solid understanding of cloud- and containerized environments (Docker, Kubernetes) and network security fundamentals

  • Strong grasp of OWASP Top 10, secure coding practices, cryptography, and secure design principles

Bonus Points

  • Experience building reusable security frameworks or internal developer platforms
  • Background in platform or infrastructure-adjacent security engineering
  • Experience influencing security practices across multiple engineering teams
  • Familiarity with supply chain security and dependency risk management

Benefits & conditions

  • Competitive compensation
  • Restricted Stock Units
  • Paid time off & paid holidays
  • Comprehensive health, dental & vision insurance
  • Employer contributions to HSA account
  • Paid parental leave
  • Paid life insurance, short-term and long-term
  • Professional development & tuition reimbursement
  • Mental health & wellness support
  • Commuter benefits (parking & transit)
  • Cell phone stipend
  • 401(k) Retirement plan with company match up to 4% of salary
  • Volunteer time off

Compensation Range

Compensation will be paid in the range of up to $175,000 - $215,000 + Bonus. Restricted Stock Units are included in all offers. Compensation to be determined by the applicants knowledge, education, and abilities, as well as internal equity and alignment with market data.

About the company

Energy Jobline is the largest and fastest growing global Energy Job Board and Energy Hub. We have an audience reach of over 7 million energy professionals, 400,000+ monthly advertised global energy and engineering jobs, and work with the leading energy companies worldwide. We focus on the Oil & Gas, Renewables, Engineering, Power, and Nuclear markets as well as emerging technologies in EV, Battery, and Fusion. We are committed to ensuring that we offer the most exciting career opportunities from around the world for our jobseekers. Job DescriptionJob Description Crusoe is on a mission to accelerate the abundance of energy and intelligence. As the only vertically integrated AI infrastructure company built from the ground up, we own and operate each layer of the stack - from electrons to tokens - to power the world's most ambitious AI workloads. When you join Crusoe, you join a team that is building the future, faster. We're in the midst of the greatest industrial revolution of our time. The demand for AI compute is boundless, and power is a bottleneck. We're solving that - with an energy-first approach that makes AI infrastructure better for the world and faster for the people innovating with AI. We're looking for problem-solving, opportunity-finding teammates with a sense of urgency, who believe in the scale of our ambition and thrive on a path not fully paved - people who want to grow their careers alongside a team of experts across energy, manufacturing, data center construction, and cloud services. If you want to do the most meaningful work of your career, help our customers and partners advance their AI strategies, and be part of a high-performing team that believes in each other, come build with us at Crusoe., Crusoe is building the infrastructure for the next era of AI and high-performance computing; and we're looking for someone to make sure it's built securely from the ground up. As part of the Product Security team, you won't just be securing the future, you'll be building it, working closely with engineering teams, shipping production code, designing secure architectures, and creating the security foundations that protect our platform at scale. This is a high-impact role where you'll shape how security is practiced across the company, not by saying "no," but by making the secure path the easy path.

Apply for this position