Jobs / Decagon

Platform Engineer, Security

Decagon · San Francisco, CA, United States
San Francisco, CA, United StatesExp: 3-5 yrs200,000-330,000 USD/yearlyOnsite
Remuneration
Offers Equity
Location
San Francisco, CA, United States
Visa sponsorship
Not specified

Job summary

Lead the application security strategy and implementation for Decagon AI's conversational platform, serving enterprise customers at scale. Partner with engineering teams to build security directly into AI-powered applications, ensuring protection against application-layer threats while maintaining performance and reliability. Apply deep application security expertise to AI systems and shape security practices across the engineering organization.

Benefits

Unlimited vacation policyMedical benefitsDental benefitsVision benefitsLife insuranceDisability benefitsRetirement plan (401K)Parental leaveFertility benefitsFamily building benefitsDaily lunchesSnacks in office

Qualifications

  • 3-5 years of hands-on application security engineering experience.
  • Expertise in secure software development practices, including threat modeling, secure code review, and vulnerability assessment.
  • Strong software engineering background with ability to review code across multiple languages and frameworks used in AI/ML applications.
  • Experience implementing application security testing tools and integrating security into CI/CD pipelines.
  • Knowledge of OWASP Top 10, common application vulnerabilities, and modern application security frameworks.
  • Proven track record working with engineering teams to remediate security findings while balancing security and business requirements.

Responsibilities

  • Design and implement application security controls across the AI agent platform, including secure coding practices, threat modeling, and vulnerability management.
  • Collaborate with product engineering teams to integrate security throughout the software development lifecycle, from design, coding, PR, and deployment.
  • Establish application security testing programs including static analysis (SAST), dynamic analysis (DAST), and interactive testing (IAST) tailored for AI applications.
  • Lead security code reviews and architecture assessments for new features, focusing on AI model integration points and customer data handling.
  • Build security tooling and automation to enable developers to identify and remediate vulnerabilities quickly.
  • Respond to security incidents involving application vulnerabilities, coordinating remediation efforts and post-incident improvements.

Skills

GCP

Relocation

No