Security Engineer – Engineering Security
RegionUSA
SalaryUSD 50 - 55
Job description
We are Hiring: Security Engineer – Engineering Security
Location: Seattle, WA (Preferred) / Sunnyvale, CA
Duration: 6 Months Contract
Work Model: Full-Time, approximately 40 hours/week
Open Positions: 5
Looking for local candidates only. Candidates with 4–6 years of experience are also welcome.
Key Focus Areas:
- ERD Security and Privacy Reviews
- Threat Modeling
- Third-Party AI Agent Security Testing
- Application and API Security
- Cloud and Distributed Systems Security
- Adversarial Security Testing
Key Responsibilities:
- Conduct security and privacy design reviews for services, applications, APIs, engineering proposals, and AI integrations.
- Perform threat modeling for critical services and AI agents, identifying attack surfaces, threats, attack paths, mitigations, and residual risks.
- Perform hands-on security testing of third-party AI agents, including prompt injection, tool misuse, excessive agency, data access, permissions, external integrations, and sensitive-data exposure.
- Document security findings, risk assessments, evidence, and actionable remediation guidance.
- Collaborate with engineering, security, privacy, and third-party teams to validate remediation.
- Develop repeatable security assessment processes, threat models, test cases, reporting templates, and automation workflows.
Minimum Qualifications:
- 3+ years of professional experience in Security Engineering, Application Security, Product Security, Offensive Security, Systems Architecture, or a related field.
- Experience reviewing technical designs and identifying security risks across applications, APIs, cloud services, microservices, or distributed systems.
- Strong understanding of threat modeling, vulnerability classification, authentication, authorization, least privilege, and data protection.
- Hands-on experience with security testing, vulnerability investigation, penetration testing, adversarial testing, or security control validation.
- Strong communication and collaboration skills with engineering, security, privacy, and third-party teams.
Preferred:
- Experience assessing AI/LLM agents, prompt injection, and unsafe tool use.
- Experience with privacy design reviews and cloud security.
- Security automation experience using Python, Go, Bash, or similar languages.
- Hands-on penetration testing and vulnerability assessment across applications, APIs, cloud infrastructure, and networks.
- Experience identifying real-world attack paths and providing actionable remediation guidance.
first seen 2026-10-03 01:30:01 · last verified 2026-10-08 13:30:01
pentestcareers.com // breach the job market