> Markdown version of [/jobs/ext/2709191-security-engineer](https://www.wearedevelopers.com/jobs/ext/2709191-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer - **Company:** Ai, Inc - **Location:** United States - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Artificial Intelligence, Cloud Computing, Cloud Computing Security, Code Review, Continuous Integration, Distributed Systems, Software Engineering, Software Systems, Systems Architecture, Large Language Models, Software Security - **Published:** September 4, 2026 - **Apply:** https://startup.jobs/security-engineer-sierra-7812170 ## About the Role Strong security fundamentals and depth in at least one domain, such as product security, platform or cloud security, enterprise security, identity, detection and response, or offensive security. You can apply that expertise across unfamiliar systems and emerging threats. Product and Platform Mindset. You care about building secure, scalable systems that enable, not block, innovation. You work closely with teams across Sierra to make trade-offs clear and help them move quickly without sacrificing trust. Software Engineering and Systems Thinking. You're comfortable reading and writing code, understanding how production systems fit together, and building pragmatic software solutions to security problems. You can reason about system design and contribute to APIs, services, and security controls, with an eye toward reliability and maintainability. Curiosity and Ownership. You take ambiguous, cross-cutting problems from first principles to production and go deep when needed: threat modeling a distributed system, tracing an authorization decision across services, or following an investigation from weak signal to root cause. You define the problem, align partners, build the solution, and own it in production. ## Description Design and ship systems and controls that make Sierra secure by default - spanning product security, infrastructure security, enterprise security, identity, and detection and response. You'll work across all layers of our platform to identify risk, strengthen architectures, and build durable defenses. Own Cross-Cutting Systems. Partner with product, platform, and infrastructure team to threat model designs, review code and architectures, and implement and evolve Sierra's security primitives. You'll make pragmatic design trade-offs between usability, performance, reliability, and security. Find and Reduce Real Risk. Identify vulnerabilities, investigate suspicious behavior, and improve detections and response workflows across applications, cloud infrastructure, identity, endpoints, and internal systems. Turn what you learn into systemic fixes and controls that prevent entire classes of issues. Automate and Scale Security Workflows. Create developer-friendly tooling to reduce risk and friction - whether through automating security checks in CI/CD, building secure paved paths, improving vulnerability discovery, or instrumenting high-signal detection and response., * You've worked across more than one of product security, infrastructure security, enterprise security, detection and response, or offensive security. * You've built security frameworks, platforms, or solutions that engineers and responders rely on to prevent, detect, investigate, and remediate security issues at scale. * You have exposure to AI systems or care about designing secure-by-default LLM applications and agentic systems. * You think like an attacker - you naturally ask "what could go wrong?" when reviewing designs or investigating systems. You've found or fixed real security issues in production. * You thrive in 0*1 environments, where foundational systems have to balance speed, reliability, and trust. Our values * Trust: We build trust with our customers with our accountability, empathy, quality, and responsiveness. We build trust in AI by making it more accessible, safe, and useful. We build trust with each other by showing up for each other professionally and personally, creating an environment that enables all of us to do our best work. * Customer Obsession: We deeply understand our customers' business goals and relentlessly focus on driving outcomes, not just technical milestones. Everyone at the company knows and spends time with our customers. When our customer is having an issue, we drop everything and fix it. * Craftsmanship: We get the details right, from the words on the page to the system architecture. We have good taste. When we notice something isn't right, we take the time to fix it. We are proud of the products we produce. We continuously self-reflect to continuously self-improve. * Intensity: We know we don't have the luxury of patience. We play to win. We care about our product being the best, and when it isn't, we fix it. When we fail, we talk about it openly and without blame so we succeed the next time. * Family: We know that balance and intensity are compatible, and we model it in our actions and processes. We are the best technology company for parents. We support and respect each other and celebrate each other's personal and professional achievements. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Are Code Reviews Worth It? Insights from 16 Years of Review Data](https://www.wearedevelopers.com/videos/1135-are-code-reviews-worth-it-insights-from-16-years-of-review-data) - [Green Cloud Computing](https://www.wearedevelopers.com/videos/592-green-cloud-computing) - [Rethinking Intelligence: AI, Accessibility, and the Future of Inclusive Work - Artur Ortega](https://www.wearedevelopers.com/videos/1377-rethinking-intelligence-ai-accessibility-and-the-future-of-inclusive-work-artur-ortega) - [The New AI Security Stack: Observe, Detect, Protect](https://www.wearedevelopers.com/videos/100302-the-new-ai-security-stack-observe-detect-protect) - [Build a CI/CD pipeline to automate code reviews and ensure code quality](https://www.wearedevelopers.com/videos/349-build-a-ci-cd-pipeline-to-automate-code-reviews-and-ensure-code-quality) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What is Software Engineering in the Age of AI?](https://www.wearedevelopers.com/magazine/640-what-is-software-engineering-in-the-age-of-ai) - [What is Software Engineering?](https://www.wearedevelopers.com/magazine/289-what-is-software-engineering) - [How to Become an AI Engineer](https://www.wearedevelopers.com/magazine/331-how-to-become-an-ai-engineer)