Featured Job

Security Engineer

Mountain View, CA Full-time Hybrid 09/17/2026 Job ID: 000232
Apply Now
supply chain and build integrity program dependency and third-party IP provenance artifact signing code signing infrastructure SBOM generation and consumption

Summary

What you’ll impact

The organization is seeking a Senior Security Engineer to secure its software, build systems, and cloud infrastructure for AGI compute platforms. The role involves ownership of supply chain and build integrity, adversarial assessments, and integrating security throughout the development lifecycle.

Responsibilities

What you'll do

  • Own and grow our supply chain and build integrity program - dependency and third-party IP provenance, artifact signing and code signing infrastructure, SBOM generation and consumption, reproducible builds, and hardening of CI/CD systems, build caches, and build runners. This is a priority area for us and the part of the role with the most room to define itself
  • Bring an adversarial perspective to our own systems: hands-on security assessment of our code and build tooling, internal services and dashboards, developer platforms, and the systems that hold our design data - including manual code review, application and API testing, and assessment of the infrastructure behind them
  • Conduct vulnerability research against the systems we build and depend on, and turn what you find into fixes and durable controls
  • Partner with software, compiler, ML, and silicon teams on threat modeling and design review for new systems, and translate the results into concrete engineering work rather than a list of findings
  • Harden our cloud infrastructure: identity and access management, network segmentation, secrets management, workload identity, infrastructure-as-code review, and guardrails that make the secure path the default path
  • Build and run our vulnerability management program - discovery, triage, prioritization based on real exploitability in our environment, and driving remediation to completion with the owning teams
  • Integrate security into the SDLC in ways engineers actually adopt: code scanning, dependency policy, pre-merge checks, secrets detection, and paved-road libraries and templates
  • Write the automation, tooling, and services that scale our security work - internal utilities, developer-facing tools, and the plumbing that makes findings actionable. This is an engineering role, not a governance role
  • Help protect highly sensitive IP and export-controlled technical data, working with our People, IT, and Legal teams on the controls that support it

Requirements

What you’ll bring

  • 8+ years in security engineering, with real depth in at least two of the following and working competence across the rest: application and product security, offensive security, cloud infrastructure security, supply chain and build security, detection and response
  • Strong application security fundamentals: threat modeling, manual secure code review, common vulnerability classes and their mitigations, and experience running SAST, DAST, and SCA tooling against real applications, services, and APIs without drowning teams in false positives.
  • Hands-on offensive experience - penetration testing, red team engagements, or vulnerability research - with current-day fluency in application and cloud attack paths, and the judgment to know when an attacker's perspective is the fastest way to settle a design argument
  • Strong software engineering skills. You write and ship production-quality code (Go, Python, Rust, or similar) and are comfortable reading code in languages you don't write. You've built tools other engineers chose to use
  • Working knowledge of at least one major cloud provider (GCP, AWS, or Azure) - IAM models, network architecture, secrets management, logging - and the appetite to go deep on the parts you haven't owned yet
  • Familiarity with modern supply chain and build integrity concepts - artifact signing, provenance and attestation, SBOMs, CI/CD as an attack surface - and the interest to own that program end to end. We care more that you understand why build systems are a target than that you've already deployed a particular toolchain
  • A track record of shipping fixes with development teams rather than filing tickets at them. You've been the security person engineers actually wanted in the room
  • Comfort operating with ambiguity and breadth. You can prioritize the small number of things that actually reduce risk, say no to the rest, and explain both decisions to engineers and to leadership

Ready to Move Forward?

Apply now and our recruiting team will reach out with next steps, interview guidance, and client insights tailored to this role.