Our platform gives developers secure, reliable access to LLMs and adjacent services. We’re looking for our first Security Engineer to help secure the company’s application, infrastructure, and software-delivery pipeline.
About the role
This is a hands-on security generalist role with a strong emphasis on application security. You’ll spend most of your time reviewing and hardening the company’s Python codebase, identifying new attack surfaces, working directly with engineers to fix vulnerabilities, and making secure development practices part of how we build.
You’ll also own security work across IT, CI/CD, cloud infrastructure, and the software supply chain. The ideal candidate has built application/product/infrastructure security programs from scratch and genuinely enjoys security outside of work—through CTFs, vulnerability research, open-source projects, or independent experimentation.
Responsibilities
Application security
Conduct deep security reviews of the company’s Python proxy, APIs, authentication systems, and enterprise features.
Identify and remediate vulnerabilities involving authentication, authorization, secrets, tenant isolation, injection, and data exposure.
Partner directly with engineers throughout design, implementation, code review, and release—not only after code is shipped.
Build application-security tooling into the development lifecycle, including SAST, DAST, dependency scanning, and secrets detection.
Perform internal red teaming and adversarial testing against the company’s APIs, proxy, and LLM-specific attack surfaces.
Threat-model new products and architecture changes before they reach production.
Create secure coding guidelines and train engineers on common vulnerabilities and defensive practices.
Infrastructure, CI/CD, and supply-chain security
Harden the company’s Docker images, PyPI packages, GitHub Actions workflows, and release infrastructure.
Implement SBOMs, signed builds, provenance checks, and reproducible-build practices.
Design secure-by-default configurations for cloud and self-hosted deployments, including authentication, IAM, secrets management, and key rotation.
Review cloud infrastructure, network boundaries, access controls, and production deployment patterns.
IT security and incident response
Strengthen employee identity, device, SaaS, and internal access controls.
Build monitoring and anomaly detection for suspicious API, model, authentication, and routing activity.
Lead security incident response, vulnerability assessment, remediation, post-mortems, and stakeholder communication.
Establish formal vulnerability intake, CVE triage, disclosure, and remediation processes.
Maintain threat models as the company’s product and architecture evolve.
Requirements
A strong security generalist who can work across application security, IT, CI/CD, cloud infrastructure, and the software supply chain.
Deep application-security expertise, including manually auditing production Python code and working with engineers to remediate vulnerabilities.
Strong understanding of authentication, authorization, tenant isolation, SSRF, injection, deserialization, secrets management, and common web and API vulnerabilities.
Experience using and configuring tools such as Semgrep, Bandit, CodeQL, Burp Suite, and other SAST or DAST tooling.
Previous experience at an early-stage security startup during its 0→1 journey.
Familiarity with SBOMs, Sigstore, Cosign, Snyk, Grype, Trivy, or equivalent tooling.
Strong knowledge of OAuth2, JWT, mTLS, IAM, and high-throughput API authentication.
Familiarity with prompt injection, LLM data exfiltration, tool abuse, and the OWASP Top 10 for LLM Applications.
Experience with incident response, CVSS scoring, vulnerability management, CVE triage, and coordinated disclosure.
Experience competing in CTFs during college or independently pursuing vulnerability research, reverse engineering, bug bounties, or security projects.
A genuine interest in security outside your day job—you regularly explore new attack techniques, build security projects, or contribute to the security community.
Bachelor’s or Master’s degree in Computer Science or a related field, or equivalent practical experience.
Benefits
Work on application-security problems at the intersection of AI, APIs, and developer infrastructure.
Work directly with engineers and influence how security is incorporated into product development.
Take broad technical ownership in a fast-moving environment.
Competitive salary and health, dental, and vision benefits.
About the company
The company (the company's site) is a Python SDK and Proxy Server that enables seamless access to more than 100 LLM APIs through the OpenAI format.
Ready to secure the infrastructure powering enterprise AI? Apply now.
Experience: 5+ years
Visa: US citizen/visa only
Where you’d work
Fully remote
You can work from
United States
No visa sponsorship
You must already be able to work in the United States
Good
Your chances
Still hiring, not crowded yet, and a person reads your message.
20 checks run
9 good signs
2 red flags
Still hiring?
13 checks
Actively hiring
StaleHiring
In its favour4
Still on the company's own careers site, checked 3 h agoModerate evidence
Specific about the basics: pay, place, level, stack and contract all statedSlight evidence
A tight salary range, set for one seat: $220K to $260KSlight evidence
1 moreFewer
A hiring contact is attached to itSlight evidence
Against it1
None of the company's 9 open roles was posted in the last 2 weeksModerate evidence
How crowded?
7 checks
Low
QuietCrowded
In its favour5
You can message the hiring contact and skip the queueModerate evidence
Remote within United States onlySlight evidence
Only for people already authorized to work in United StatesSlight evidence
2 moreFewer
Senior level: far fewer people qualifySlight evidence
Asks for GitHub Actions, which fewer than 1% of open roles doSlight evidence
Against it1
Open for 2 weeks: applications have had time to pile upModerate evidence
?
Fits Me
How well does this role fit you?
Answer a few questions or drop your CV, and every role gets a fit score with the reasons, this one first.