> Markdown version of [/jobs/ext/2720792-staff-product-security-engineer](https://www.wearedevelopers.com/jobs/ext/2720792-staff-product-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Staff Product Security Engineer - **Company:** Crusoe's Inc - **Location:** San Francisco, CA, United States - **Experience:** Expert - **Salary:** $250,000.0 - $285,000.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Software System Penetration Testing, Cloud Foundry, Encodings, Continuous Integration, Distributed Systems, Python (Programming Language), Systems Development Life Cycle, Red Team (Cyber Security), Secure Coding, Software Engineering, Systems Integration, AI Infrastructure, Policy as Code, High Performance Computing, ReactJS, Delivery Pipeline, Large Language Models, Software Security, Kubernetes, Bare Metal, Machine Learning Operations, Automation Anywhere, Static Application Security Testing, Dynamic Application Security Testing - **Published:** September 4, 2026 - **Apply:** https://startup.jobs/staff-product-security-engineer-crusoe-7919503 ## About the Role * 8-10 years of deep hands-on experience in offensive security, including manual penetration testing, red team operations, and adversary simulation * Familiarity with modern C2 frameworks (e.g., Cobalt Strike, Sliver, Havoc), exploit development, and security research * Strong expertise across the AI/ML stack, including MLOps, inference architectures, vector databases, RAG, and agentic frameworks (e.g., ReAct, Reflexion) * Experience building, deploying, and securing LLM pipelines and AI workflows in Kubernetes and/or bare-metal environments * Strong software engineering foundations with experience shipping production code in Go, Python, or Rust * Hands-on experience securing Kubernetes, containers, VMs, and CI/CD environments * Deep understanding of application security vulnerabilities, secure coding practices, and distributed system design * Demonstrated ability to lead complex, cross-functional security initiatives end-to-end * Strong communication skills with the ability to influence both engineering teams and executive stakeholders Bonus Points * Public contributions to offensive security or AI security research (talks, blogs, tooling, CVEs, etc.) * Experience building internal red team or adversary simulation programs * Background in high-performance computing, AI infrastructure, or cloud-native platform security * Experience designing policy-as-code frameworks at scale ## Description * Performing advanced manual penetration testing across complex applications, infrastructure, Kubernetes environments, and distributed microservice ecosystems * Leading offensive security initiatives including red team operations, adversary simulation, and security research * Securing AI/ML systems end-to-end, including LLM pipelines, vector databases, RAG architectures, and agentic workflows * Identifying and researching novel attack surfaces unique to LLMs and autonomous systems, contributing to internal and external AI security research * Influencing secure system design across the SDLC, embedding security into CI/CD pipelines, container images, and deployment workflows * Integrating and operationalizing security tooling (SAST, DAST, SCA, container scanning) and driving remediation of complex application-layer vulnerabilities * Building internal security guardrails such as hardened base images, reusable libraries, and policy-as-code frameworks * Developing production-grade security tooling and leading cross-functional security programs from design through deployment ## Related Videos - [Single Server, Global Reach: Running a Worldwide Marketplace on Bare Metal in a Cloud-Dominated World](https://www.wearedevelopers.com/videos/1206-single-server-global-reach-running-a-worldwide-marketplace-on-bare-metal-in-a-cloud-dominated-world) - [A Brief History of Data Storage](https://www.wearedevelopers.com/videos/974-a-brief-history-of-data-storage) - [Watch Tests Go Brrrr! : Getting Started with Cypress in ReactJS](https://www.wearedevelopers.com/videos/282-watch-tests-go-brrrr-getting-started-with-cypress-in-reactjs) - [Real-World Security for Busy Developers](https://www.wearedevelopers.com/videos/1545-real-world-security-for-busy-developers) - [How to Avoid Tech Hype Traps - Josip Stuhli](https://www.wearedevelopers.com/videos/1817-how-to-avoid-tech-hype-traps-josip-stuhli) - [JSON and Beyond](https://www.wearedevelopers.com/videos/968-json-and-beyond) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Dev Digest 129 - Now that's what I call private data!](https://www.wearedevelopers.com/magazine/468-dev-digest-129-now-that-s-what-i-call-private-data) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline)