> Markdown version of [/jobs/ext/3037516-agentic-devsecops-engineer-backend-x-security-in-house-product-full-remote-jlpt-n2](https://www.wearedevelopers.com/jobs/ext/3037516-agentic-devsecops-engineer-backend-x-security-in-house-product-full-remote-jlpt-n2). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # (Agentic DevSecOps Engineer(Backend × Security))In-house Product | Full Remote | JLPT N2~ - **Company:** G TALENT LLC - **Location:** United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Software System Penetration Testing, Cloud Computing Security, Cyber Security, Continuous Integration, Software Debugging, Identity and Access Management, Python (Programming Language), Open Web Application Security, Secure Coding, Security Support Provider Interface, Software Engineering, Tokenization, TypeScript, Data Processing, Data Classification, Large Language Models, Software Security, Backend, GWAPT, Virtual Agents, Devsecops, Static Application Security Testing, Vulnerability Analysis, Golang, Dynamic Application Security Testing - **Published:** September 23, 2026 - **Apply:** https://arc.dev/remote-jobs/j/redirect/pm2vbvizrt ## About the Role (Required) 5+ years of practical experience as a software development engineer Experience in backend development using TypeScript, Python, Go, etc. Daily use of AI coding agents such as Claude Code in business operations Business-level Japanese proficiency Strong communication skills, debugging skills, teamwork skills, problem-solving skills, and logical thinking skills Ability to proactively drive projects forward even in highly uncertain situations (Preferred) Practical experience in secure code reviews, threat modeling, and API/web vulnerability assessments Experience addressing supply chain security issues based on the OWASP Top 10, API Top 10, CVE, and OSV Practical experience with cloud security on AWS (IAM, GuardDuty, Security Hub, CloudTrail) Experience integrating security into CI/CD (implementation and adoption of SAST, SCA, and secret detection) Experience with AI/LLM security (testing for prompt injection, jailbreak, and tool abuse) Knowledge of OWASP LLM Top 10, MITRE ATLAS, Promptfoo, Garak, PyRIT, etc. Experience building agents and automation on LLM SDKs (tool integration, MCP integration) Practical experience with penetration testing (at a level capable of handling chained attack vectors) Experience handling large-scale personal data (classification, masking, tokenization, access proxies) Understanding of the Personal Information Protection Act and GDPR Experience with security compliance for regulated industries (checklists, customer audits, trust centers) Experience reading technical documentation and communicating in English Certifications such as OSCP, GWAPT, CISSP, and Information Processing Security Support Specialist ## Description The organization is seeking a dedicated engineer to take full responsibility-from design to implementation-for the core security agents of the Agentic Security Life Cycle (ASLC). ASLC is a security operations cycle centered around AI agents supporting each stage of the development lifecycle. Security agents will be built for every stage: Design, Code, Build, Test, Release, and Operations, as well as for two cross-cutting layers: Data Protection and AI Security. The median time from CVE disclosure to the emergence of a functional exploit has collapsed from 56 days in 2024 to approximately 10 hours in 2026. It is clear that manual human response cannot keep pace, necessitating the leverage of AI technology for automated defense. (Responsibilities) Design, Implementation, and Operations of Security Agents: Architect and build AI security agents supporting each phase of the development lifecycle using the Claude Agent SDK. CI/CD Security Integration: Embed SAST, SCA, secret detection, and related automated security checks directly into CI pipelines. Threat Modeling and Security Reviews: Conduct threat modeling for high-risk features and perform rigorous security reviews on implementation code and API architectures. In-Housing Vulnerability Assessments: Internalize and execute DAST, API security testing, and penetration testing workflows. Data Privacy & Protection Engineering: Implement data classification, masking, tokenization, fine-grained access control, and privacy protections. Adversarial AI Testing & Safeguards: Perform adversarial red-teaming/testing on internal AI agents and construct robust guardrail systems. (Organizational Structure) This position represents the first dedicated security engineer hire. Rather than working in isolation, you will join a collaborative structure where the VP of Security and a Security Specialist will continuously handle strategy, implementation requirements, and customer-facing response. As a member of the Security Team responsible for both data privacy and overall service safety, the engineer will work within a global, remote-first engineering organization. (Role Expectations & Ideal Motivations) Leveraging strong background and core skills in software engineering to tackle complex security domain challenges. Building and designing core security frameworks and mechanisms from the ground up, rather than simply operating third-party security software. Driving the development and deployment of AI agents as the primary focus of daily engineering activities. Possessing a strong interest and drive to build pioneering solutions in uncharted territories from zero to one. Viewing security not as a cost center, but as a core driver of product quality and strategic business competitiveness. (What You'll Gain from This Position) High degree of autonomy and total ownership in driving key security initiatives. Collaborative work culture within a distributed, remote-first global engineering organization. Opportunity to place AI agent development at the absolute center of daily engineering operations. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Developing the Backend with Stefan Lingler, CTO at Shpock](https://www.wearedevelopers.com/videos/100360-developing-the-backend-with-stefan-lingler-cto-at-shpock) - [Go with the Flow: Stop the Leaks Before Your Memory's a Waterfall!](https://www.wearedevelopers.com/videos/100073-go-with-the-flow-stop-the-leaks-before-your-memory-s-a-waterfall) - [Real-World Security for Busy Developers](https://www.wearedevelopers.com/videos/1545-real-world-security-for-busy-developers) - [Nest.js - TypeScript in the backend can also be clean](https://www.wearedevelopers.com/videos/1033-nest-js-typescript-in-the-backend-can-also-be-clean) - [Scoring 2000 Products per Request: Performance Pitfalls in Golang](https://www.wearedevelopers.com/videos/2073-scoring-2000-products-per-request-performance-pitfalls-in-golang) ## Related Articles - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Dev Digest 210: AI Agents Are Go! Is MCP Dead? LLMs Crack Anonymity](https://www.wearedevelopers.com/magazine/709-dev-digest-210-ai-agents-are-go-is-mcp-dead-llms-crack-anonymity) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers)