About the Role
We are seeking a software engineer to enhance product security and support rapid product iteration. You will collaborate with product and research teams to integrate security into design and development, and build tools to maintain system safety at scale.
Responsibilities
- Partner with product and research teams to embed security into the development lifecycle: threat modeling, design reviews, and secure defaults for new features.
- Design and implement security controls across our product stack (authentication, authorization, session management, input validation, etc.).
- Build and maintain security tooling and automation for engineers: secure frameworks and templates, CI/CD checks, dependency management, and vulnerability detection.
- Collaborate with researchers to identify and mitigate AI-specific product risks, such as model abuse, prompt injection, data leakage, or misuse of capabilities.
- Improve observability and detection for security-relevant events: access anomalies, abuse patterns, and suspicious behavior in production.
Requirements
- Bachelor’s degree or equivalent experience in computer science, engineering, or similar.
- Proficiency in at least one backend language (Python or Rust).
- Strong generalist software engineering background and ability to review production code for security risks.
- Hands-on experience securing web apps and APIs especially auth flows, access control, secrets management, input validation, and data protection.
- Familiarity with common vulnerability classes and prevention frameworks; experience hardening prototypes into production.
- Comfort with modern cloud infrastructure and understanding how application concerns intersect with infrastructure.
- Comfort operating across the stack and owning projects end-to-end.
- Thrive in a highly collaborative environment involving many, different cross-functional partners and subject matter experts.
- A bias for action with a mindset to take initiative to work across different stacks and different teams where you spot the opportunity to make sure something ships.
- Experience securing AI‑powered products or working with ML/LLM APIs and their unique threat models.
- Background in human-computer interaction, especially where security or trust plays a central role in the user experience.
- Strong skills in rapid prototyping and iteration, with a habit of turning ad-hoc fixes into reusable patterns and tools.
- Open‑source security work, bug bounty write‑ups, or published tooling.
Skills
- Python
- Rust
- Security
- Web Application Security
- API Security
- Cloud Infrastructure
- AI Security
- ML/LLM APIs
- Human-Computer Interaction
- Prototyping
- Open-source security
Location
- San Francisco, California
Work Type
- Full-time
Experience Level
- Mid-level
- Senior
Education Level
- Bachelor's degree or equivalent experience
Salary/Compensations
- $350,000 - $475,000 USD
Benefits
- Generous health, dental, and vision benefits
- Unlimited PTO
- Paid parental leave
- Relocation support
- Visa sponsorship
About the Company
- The mission of Thinking Machines is to build AI that extends human will and judgment.
