StackAI

Engineering

ProductSecurityEngineer

$120–200k San Francisco, California, United States FULL TIME Remote Friendly
Market Sentiment
HIGH DEMAND

Neural analysis suggests this role is
optimal for Senior candidates.

The Brief

“Product Security Engineer at StackAI. Skills: Product security, Cryptography, Key management, Secure architecture. Own encryption and signing. Operate KMS”

Industry & Context.

Engineering
Problems you'll solve

Root cause analysis

What They're Looking For.

Must Have

4+ years building security-critical systems, Practical depth in cryptography, Secure architecture judgment, Multi-tenant SaaS isolation experience, Secure-coding skills in Python, Secure-coding skills in TypeScript/Node.js, Wiring security checks into CI/CD

Nice to Have

Cloud and API security fundamentals on GCP, Azure, or AWS, Securing on-prem deployments, Experience in regulated domains, Familiarity with AI/LLM platform security, Startup or growth-stage experience

What You'll Do.

Own encryption and signing

Protect customer data

Strengthen data-protection foundations

Own encryption at rest

Maintain secure-by-default templates

Expand reference implementations

Push scanning further

Translate audit requirements

Translate compliance requirements

Translate incident-response requirements

How You'll Work.

Team & Collaboration

Technical partner to engineering lead

Full Job Description

ABOUT THE ROLE At StackAI, security is how we earn the trust of the enterprises building AI assistants on our platform. We're hiring a hands-on (Senior) Product Security Engineer to design, build, and harden the secure architecture at the core of the product, working as a technical partner to our Core engineering lead. This is a hands-on engineering role. You'll write production code and own the security-critical systems the whole platform depends on: encryption and key management, customer data protection, and how security is built into the way every team ships. If you want deep ownership of these systems and the chance to harden and scale them as the platform grows, we'd love to meet you. WHAT YOU'LL DO - Own encryption and signing. Take ownership of our KMS, key management, BYOK, envelope encryption, and signing pipeline across both cloud and on-prem deployments—operating, hardening, and evolving them as the platform scales. - Protect the most sensitive customer data. Extend our PHI/PII scrubbing and strengthen the data-protection foundations that regulated enterprises already rely on. - Secure the storage layer. Own encryption at rest and tenant isolation. - Keep security the default in how we ship. Maintain and expand the secure-by-default templates and reference implementations embedded in our SDLC—the ones engineers actually want to adopt. - Threat-model the platform. Lead threat modeling on the seams between systems (the execution engine, connector trust boundaries, and multi-tenant isolation), using modern, AI-assisted threat-modeling tooling. - Raise the bar on tooling. Push our scanning further on coverage, signal, and CI enforcement, so critical findings never reach production. - Be the technical point of contact for security standards. Translate audit, compliance, and incident-response requirements into real implementation in our codebase. WHAT WE'RE LOOKING FOR - 4+ years building security-critical systems in production, with significant time spent imp

Free ATS check

Applying for this Product Security Engineer role?

Most applicants get filtered before a human reads their resume. See if yours makes the cut.

How to Apply on Ashby

  • Ashby is a fast modern ATS — most applications take under 3 minutes.
  • The resume parser is strong; verify parsed experience dates and job titles.
  • Custom screening questions are often scored algorithmically — answer completely.
  • Location field affects geo-based screening; use your actual metro area.

ANONYMOUS · UNFILTERED

What do employees actually say about StackAI?

Real rants from real employees. Read before you apply.

Read Company Rants →