> Markdown version of [/jobs/ext/2710366-software-engineer-ai-security-product](https://www.wearedevelopers.com/jobs/ext/2710366-software-engineer-ai-security-product). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Software Engineer - AI Security Product - **Company:** Obsidian Security, Inc. - **Location:** Palo Alto, United States - **Experience:** Starter - **Salary:** $155,000.0 - $180,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, BigQuery, Software as a Service, Cloud Computing Security, Continuous Integration, Data Warehousing, Python (Programming Language), OAuth, Open Web Application Security, Salesforce.Com, Software Engineering, Data Streaming, Okta, Large Language Models, Snowflake, Multi-Agent Systems, Backend, AI Platforms, Gsuite, Vertica, Virtual Agents, GPT, Data Pipelines, Databricks - **Published:** September 4, 2026 - **Apply:** https://startup.jobs/software-engineer-ai-security-product-obsidian-security-8691882 ## About the Role * 1-3 years of software engineering experience shipping and owning production backend systems, with proficiency in a modern language (Python, Go, or similar). * Experience with - AWS/GCP, containers, CI/CD, observability, and production ownership. * Hands-on experience with LLM APIs and agentic patterns (tool/function calling, MCP, agent frameworks), or a demonstrated ability to ramp up fast. * Hands-on experience with a modern data stack (dbt, and a columnar warehouse or query engine such as ClickHouse, Snowflake, BigQuery, or Databricks). * Clear communicator across engineers, PMs, and customer security teams. * Comfortable operating with ambiguity in a fast-moving problem space. Nice to Have * Strong grasp of how SaaS platforms (Google Workspace, Microsoft 365, Salesforce, Okta) expose data - APIs, event schemas, permissions, auth flows. * Deep knowledge of AI and SaaS security - OWASP LLM Top 10, MITRE ATLAS, prompt injection, agent/tool-use risks, OAuth abuse, and identity models across major AI and SaaS platforms. * Experience in building a cybersecurity product. * Strong grasp of identity and access control concepts - OAuth flows, scopes, tokens, and non-human identities. ## Description AI is the fastest-moving attack surface in the enterprise. Copilot, ChatGPT Enterprise, Gemini, Claude, and a wave of agentic tools are being wired into corporate SaaS faster than security teams can keep up - with broad OAuth scopes, opaque data flows, and non-human identities acting on behalf of employees. Obsidian sits directly in the path of this shift. As a software engineer working on AI Security, you'll define how Obsidian understands, identifies, and mitigates risk in AI and agentic platforms. You'll own the threat models and data modeling that protect customers - and you'll work in the data yourself, because in this space, the security judgment and the query are inseparable. What You'll Do * Develop deep expertise in how AI platforms (ChatGPT Enterprise, Copilot, Gemini, Claude, Glean, agentic frameworks) authenticate, what scopes they request, and where risk concentrates. * Research emerging AI attack techniques - prompt injection, tool/agent misuse, RAG poisoning, over-permissioned integrations * Prototype and ship highly available AI Agent security products. * Build and improve data pipelines for high efficiency, development velocity and low cost. ## Related Videos - [ Evaluating AI models for code comprehension](https://www.wearedevelopers.com/videos/1462-evaluating-ai-models-for-code-comprehension) - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [The New AI Security Stack: Observe, Detect, Protect](https://www.wearedevelopers.com/videos/100302-the-new-ai-security-stack-observe-detect-protect) - [Streaming AI Responses in Real-Time with SSE in Next.js & NestJS](https://www.wearedevelopers.com/videos/1630-streaming-ai-responses-in-real-time-with-sse-in-next-js-nestjs) - [Automated Security for the Entire SDLC](https://www.wearedevelopers.com/videos/100323-automated-security-for-the-entire-sdlc) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) ## Related Articles - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift) - [Dev Digest 210: AI Agents Are Go! Is MCP Dead? LLMs Crack Anonymity](https://www.wearedevelopers.com/magazine/709-dev-digest-210-ai-agents-are-go-is-mcp-dead-llms-crack-anonymity) - [Dev Digest 137 - AI'm not sure about this](https://www.wearedevelopers.com/magazine/485-dev-digest-137-ai-m-not-sure-about-this) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [MLOps And AI Driven Development](https://www.wearedevelopers.com/magazine/82-mlops-and-ai-driven-development) - [Stephan Gillich - Bringing AI Everywhere](https://www.wearedevelopers.com/magazine/489-stephan-gillich-bringing-ai-everywhere)