Product Security Engineer

Zof AI

San Francisco, Northern (CA, KY)

Hybrid

USD 140,000 - 210,000

Full time

3 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Zof AI is seeking a Product Security Engineer to own the security posture of a platform that reads, executes, and modifies customer source code. This role focuses on isolating agent workloads and tenants, secrets handling, supply chain security, and enterprise controls that buyers audit before trusting us with a repository.

You will work in a mid to senior capacity on-site in San Francisco, collaborating with engineering and sales to clear enterprise security reviews and questionnaires as part

Qualifications

  • Experience securing production software systems or cloud infrastructure.
  • Strong software engineering foundation and ability to ship code.
  • Working knowledge of application security and vulnerability classes.
  • Experience with cloud security, identity and access control.
  • Familiarity with SOC 2 compliance.

Responsibilities

  • Own the security posture of a platform that reads, executes, and modifies customer source code.
  • Harden sandbox, tenant, and workload isolation boundaries for agents.
  • Design secrets management and least-privilege access across the platform.
  • Secure the software supply chain from dependencies through build and deploy.
  • Build technical controls behind SOC 2 and enterprise security requirements.
  • Teach agent fleets to find, prove, and remediate real vulnerabilities in customer code.
  • Run threat modeling, design reviews, and incident response as a regular practice.
  • Partner with engineering and sales to clear enterprise security reviews and questionnaires.

Skills

Threat modeling
Ship code
Security ownership
Clear communication

Job description

Zof AI is seeking a Product Security Engineer to own the security posture of a platform that reads, executes, and modifies customer source code. This role covers isolation between agent workloads and tenants, secrets and credential handling, supply chain security, and the enterprise controls that buyers audit before they trust us with a repository. If you have worked as an Application Security Engineer, Product Security Engineer, Cloud Security Engineer, or Infrastructure Security Engineer, this is that discipline at Zof AI. The ideal candidate thinks in threat models, ships controls instead of policy documents, and treats customer code as the most sensitive asset we hold.

Engineering · Mid to Senior · Full-time · On-site · San Francisco, CA

Responsibilities
  • Own the security posture of a platform that reads, executes, and modifies customer source code.
  • Harden the sandbox, tenant, and workload isolation boundaries agents run inside.
  • Design secrets management, credential handling, and least privilege access across the platform.
  • Secure the software supply chain from dependencies through build and deploy.
  • Build the technical controls behind SOC 2 and enterprise security requirements.
  • Teach our agent fleets to find, prove, and remediate real vulnerabilities in customer code.
  • Run threat modeling, design reviews, and incident response as a regular practice.
  • Partner with engineering and sales to clear enterprise security reviews and questionnaires.
Requirements
  • Experience securing production software systems or cloud infrastructure.
  • Strong software engineering foundation and comfort shipping code, not just reviewing it.
  • Working knowledge of application security and common vulnerability classes.
  • Experience with cloud security, identity, and access control.
  • Familiarity with compliance frameworks such as SOC 2.
  • Clear written and verbal communication.
  • Comfort operating in a fast-moving environment.
  • High ownership of security outcomes, not just findings.
Nice to have
  • Experience with sandboxing, container isolation, or multi-tenant architecture.
  • Experience with LLM or agent security, including prompt injection and tool use risk.
  • Experience with static analysis, fuzzing, or automated vulnerability detection.
  • Experience leading enterprise security reviews or SOC 2 audit readiness.

Hands-on experience working with AI agents and threat modeling what they are allowed to do is required

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Product Security Engineer - AI Platform & Enterprise Security
Product Security Engineer - AI Platform & Enterprise Security

Zof AI • San Francisco (CA), Northern (KY)

Hybrid
USD 140,000 - 210,000
Site Reliability Engineer
Site Reliability Engineer

Zof AI • San Francisco (CA), Northern (KY)

Hybrid
USD 150,000 - 210,000
Deployment Engineer
Deployment Engineer

Zof AI • San Francisco (CA), Northern (KY)

Hybrid
USD 150,000 - 210,000
Full Stack Developer
Full Stack Developer

Zof AI • San Francisco (CA), Northern (KY)

Hybrid
USD 110,000 - 170,000
Senior AI Software Engineer
Senior AI Software Engineer

Zof AI • San Francisco (CA), Northern (KY)

Hybrid
USD 150,000 - 210,000
Software Engineer, Security
Software Engineer, Security

XOXO AI Inc. • San Francisco (CA)

On-site
USD 250,000 - 500,000
Health, dental, vision benefits
Equity between 1% and 5%
Applied Data Scientist
Applied Data Scientist

Zof AI • San Francisco (CA), Northern (KY)

Hybrid
USD 120,000 - 180,000
Product Security Engineer - Team Lead
Product Security Engineer - Team Lead

Meta • Bellevue (WA)

On-site
USD 180,000 - 260,000
Senior Product Security Engineer
Senior Product Security Engineer

7AI, Inc. • Boston (MA)

Hybrid
USD 120,000 - 160,000
Backend Developer
Backend Developer

Zof AI • San Francisco (CA), Northern (KY)

Hybrid
USD 140,000 - 190,000