> Markdown version of [/jobs/ext/3395927-staff-security-engineer-remote-us](https://www.wearedevelopers.com/jobs/ext/3395927-staff-security-engineer-remote-us). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Staff Security Engineer [Remote-US] - **Company:** Quanata, Llc - **Location:** San Francisco, CA, United States (Remote available) - **Experience:** Expert - **Salary:** $235,000.0 - $305,000.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Java (Programming Language), JavaScript (Programming Language), Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Automated Storage and Retrieval Systems, Software as a Service, Cloud Computing, Cloud Computing Security, Cloud Engineering, Encodings, Cyber Security, Information Systems, Continuous Integration, Information Leak Prevention, DevOps, Programming Tools, Distributed Systems, Github, Identity and Access Management, Intrusion Detection and Prevention, Python (Programming Language), Key Management, Machine Learning, Open Web Application Security, Productivity Software, Security Information and Event Management, Software Engineering, Systems Integration, TypeScript, Software Vulnerability Management, Data Logging, Data Classification, Delivery Pipeline, Large Language Models, Software Security, Containerization, Gitlab-ci, Kubernetes, Information Technology, Deployment Automation, Build Tools, CIS Benchmarks, Terraform, Software Version Control, Devsecops, Docker, Jenkins, Golang - **Published:** September 21, 2026 - **Apply:** https://www.careerjet.com/job/usc14270f094c5f6e9531d0da91c8823b2/eaa ## About the Role * Bachelor's degree in Computer Science, Cybersecurity, Engineering, Information Systems, or a related technical field; an equivalent combination of education and relevant experience; or equivalent relevant experience. * 8+ years of experience in full-stack security, product security, application security, cloud security, DevSecOps, infrastructure security, or software engineering with significant security responsibilities. * 5+ years of demonstrated experience working with AI, machine learning, LLM, GenAI, or AI-enabled application environments, including hands-on experience securing, assessing, building, integrating, or operating AI-enabled systems. * Proven experience conducting security architecture reviews, threat modeling, secure design reviews, code or configuration reviews, and risk assessments for modern applications, APIs, platforms, and distributed systems. * Experience evaluating and securing third-party SaaS platforms, AI tools, model providers, developer tools, APIs, integrations, and vendor-managed services. * Experience partnering across security operations, detection engineering, incident response, GRC, privacy, infrastructure, and product engineering teams. * Strong hands-on experience securing cloud-native environments, preferably AWS, including IAM, networking, logging, monitoring, secrets management, workload identity, infrastructure-as-code, and secure deployment practices. * Strong understanding of modern CI/CD pipelines, source control, build systems, artifact management, deployment automation, container security, software delivery workflows, and software supply chain risk. * Working knowledge of AI-specific security risks, including prompt injection, insecure tool use, excessive agency, data leakage, sensitive data exposure, RAG security risks, model and provider trust boundaries, plugin and MCP risks, insecure agent permissions, model extraction, model abuse, and AI supply chain concerns. * Ability to translate AI and cloud security risks into practical engineering requirements, compensating controls, standards, detections, and operational procedures. * Strong written and verbal communication skills, with the ability to explain complex technical risks, document standards, influence decisions, and drive remediation across technical and business teams. * Demonstrated ability to work independently, self-organize, prioritize competing risks, and lead complex cross-functional security initiatives from concept through execution. Bonus Points * Experience securing agentic AI systems, MCP servers, AI agents, tool-calling or autonomous workflows, internal copilots, LLM gateways, AI assistants, or AI-enabled developer productivity tools. * Experience with AWS AI/ML and GenAI services such as Amazon Bedrock, SageMaker, Comprehend, Transcribe, Textract, or related AWS-native capabilities. * Experience securing RAG architectures, vector databases, embedding pipelines, knowledge retrieval systems, data classification workflows, and sensitive data within AI applications. * Experience implementing AI security guardrails such as model access controls, approved-provider patterns, prompt and context protections, DLP integrations, logging requirements, policy enforcement, and AI usage monitoring. * Experience with detection engineering, SIEM/SOAR platforms, cloud security posture management, vulnerability management, endpoint security, or related security operations tooling. * Experience developing secure software in Python, TypeScript, JavaScript, Go, Java, or similar languages. * Experience with Kubernetes, Docker, Terraform, GitHub Actions, GitLab CI/CD, Jenkins, or similar cloud-native and DevOps technologies. * Familiarity with frameworks and guidance such as the OWASP Top 10 for LLM Applications, MITRE ATLAS, NIST AI Risk Management Framework, CIS benchmarks, SOC 2, ISO 27001, or cloud security reference architectures. * Relevant certifications such as AWS Certified Security - Specialty, CISSP, CSSLP, CCSP, GIAC, OSCP, or other cloud, application security, AI security, or security engineering certifications. * Experience as a senior individual contributor influencing engineering teams, establishing security standards, and delivering security outcomes without direct management authority. ## Description As a Staff Security Engineer, you'll play a key role in securing the AI-enabled systems, applications, and platforms that power our organization. You'll partner closely with engineering, product, infrastructure, and security teams to make security an integral part of how AI solutions are designed, built, deployed, and operated. This is a hands-on technical leadership role for someone who is equally comfortable diving into architecture and threat models, evaluating emerging AI risks, and translating security requirements into practical engineering solutions. You'll help secure everything from LLM applications and RAG pipelines to agentic AI workflows, third-party integrations, CI/CD pipelines, and AWS-native infrastructure. Your impact will extend beyond AI. As a senior individual contributor, you'll help shape our broader security strategy, establish scalable security patterns and standards, and influence technical decisions across the organization. You'll have the autonomy to tackle complex security challenges and drive initiatives from strategy through implementation. Your Day-to-Day * Partner with engineering and product teams to embed security into AI-enabled products, internal applications, APIs, services, and platforms throughout their lifecycle. * Lead threat modeling, security architecture reviews, and risk assessments for LLM applications, RAG pipelines, agentic workflows, MCP servers, model providers, third-party AI tools, plugins, automations, and AI-assisted development. * Define and implement secure AI engineering patterns, guardrails, standards, and reference architectures across identity, data protection, prompt and context handling, tool permissions, logging, monitoring, abuse prevention, and incident readiness. * Strengthen AWS-native infrastructure and CI/CD environments, including infrastructure-as-code, containerized workloads, secrets management, workload identity, deployment pipelines, and software supply chain controls. * Partner with security operations, detection engineering, incident response, and vulnerability management teams to improve AI-related detection, observability, telemetry, and response capabilities. * Evaluate AI applications, SaaS platforms, model providers, MCPs, agents, developer tools, and other third-party technologies for security, privacy, access, data exposure, logging, contractual, and operational risks. * Develop practical security guidance, training, and enablement materials that help engineering and business teams use AI safely and build secure solutions. * Lead cross-functional security-by-design initiatives, translate security objectives into technical requirements, influence architectural decisions, and take ownership of broader security projects and critical incident response efforts as organizational needs evolve. ## Related Videos - [Go with the Flow: Stop the Leaks Before Your Memory's a Waterfall!](https://www.wearedevelopers.com/videos/100073-go-with-the-flow-stop-the-leaks-before-your-memory-s-a-waterfall) - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [The New AI Security Stack: Observe, Detect, Protect](https://www.wearedevelopers.com/videos/100302-the-new-ai-security-stack-observe-detect-protect) - [Scoring 2000 Products per Request: Performance Pitfalls in Golang](https://www.wearedevelopers.com/videos/2073-scoring-2000-products-per-request-performance-pitfalls-in-golang) - [Bringing AI Model Testing and Prompt Management to Your Codebase with GitHub Models](https://www.wearedevelopers.com/videos/1536-bringing-ai-model-testing-and-prompt-management-to-your-codebase-with-github-models) ## Related Articles - [Got AI ideas but no money? Here are 10 free ways to level up your AI skills with Google Cloud](https://www.wearedevelopers.com/magazine/600-got-ai-ideas-but-no-money-here-are-10-free-ways-to-level-up-your-ai-skills-with-google-cloud) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [How to Become an AI Engineer](https://www.wearedevelopers.com/magazine/331-how-to-become-an-ai-engineer) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this)