Live opening · Posted 6 hours ago
At a glance
The key details from the original listing.
Your early-applicant advantage
Live timing from JobBeeper.
About the role
Description supplied by the original job listing.
As a Staff Security Engineer, you will own security across the full stack from AI-generated applications and agent pipelines to the cloud infrastructure and runtime environments where that code executes. You will work across Application Security, Product Security, Cloud Security, Infrastructure Security, and Runtime Defence to build systems that are secure by design and resilient at scale.
The candidate will have responsibilities across the following functions:
Secure AI-Generated Applications:
Define security patterns and guardrails for applications generated by AI agents.
Build secure-by-default frameworks across authentication, authorisation, data access, APIs, and business logic.
Identify and prevent vulnerabilities in dynamically generated applications.
Build validation layers for AI-generated code, including static and semantic validation.
Detect prompt injection, adversarial inputs, and other AI-specific attack patterns.
Secure Cloud and Runtime Infrastructure:
Design secure, multi-tenant environments for executing untrusted, AI-generated code.
Build isolation across compute, network, and storage layers.
Prevent container escapes, privilege escalation, lateral movement, and other runtime attacks.
Harden AWS/GCP infrastructure across IAM, VPCs, secrets, workloads, and service-to-service communication.
Design and implement zero-trust security architectures.
Own End-to-End Threat Modelling:
Threat model systems spanning AI agents, generated applications, APIs, cloud infrastructure, and runtime environments.
Identify systemic security risks across multi-tenant and agent-driven architectures.
Develop reusable threat models and security patterns for AI-native systems.
Assess attack paths across both application and infrastructure layers.
Build Security Detection and Defence:
Build detection capabilities for abnormal execution, malicious workloads, and data-exfiltration attempts.
Design logging, SIEM, monitoring, and real-time alerting systems.
Develop security controls that detect and prevent attacks across application and infrastructure layers.
Red-team AI-generated applications and execution environments to identify systemic weaknesses.
Secure CI/CD and Agent Pipelines:
Secure build and deployment pipelines used by AI agents.
Prevent software supply-chain attacks and insecure code propagation.
Ensure artefact integrity throughout the development and deployment lifecycle.
Feed security learnings back into AI generation and engineering systems.
Build Security Engineering Primitives:
Design authentication and authorisation frameworks.
Build secure SDKs, APIs, gateways, rate limiting, and input/output validation layers.
Develop reusable security tooling and frameworks that engineering teams can adopt at scale.
Work closely with engineering and product teams to make security part of system design rather than a post-development review.
Requirements:
8-15 years of security engineering experience, with strong hands-on experience across both Application/Product Security and Cloud/Infrastructure Security.
Strong coding and automation skills in Python, JavaScript/TypeScript, or backend systems.
Deep understanding of application security fundamentals, including: OWASP Top 10 Authentication and authorisation, API security, Injection vulnerabilities, Secure software development, threat modelling
Strong cloud and infrastructure security experience across: AWS/GCP, Kubernetes and containers, IAM and secrets management, Network security, Container security, Runtime protection, Multi-tenant environments
Experience designing and securing systems that execute untrusted or user-generated code.
Ability to work across application, infrastructure, and platform layers rather than operating within a single security domain.
Experience partnering closely with engineering and product teams and driving security initiatives from architecture through implementation.
Good to Have:
Experience securing AI/LLM or agentic systems.
Experience with prompt injection, output validation, and AI-specific threat models.
Experience with sandboxed or ephemeral execution environments.
Experience securing high-scale, multi-tenant platforms.
Experience building security systems rather than only identifying vulnerabilities.
Strong systems thinking: you understand how an application vulnerability can become an infrastructure or runtime risk, and vice versa.
Experience building scalable security solutions for environments where millions of applications or workloads may be generated and executed dynamically.
Skills
Application Security, Cloud Security, Network Security, Security Operations, SIEM
Experience
8-12 yrs
More openings worth a look
Recently tracked roles with full details and direct application links.