Security AI Engineer, Principal Member of Technical Staff (CA, US, 95131)

QuantumScape

United States

On-site

USD 155,000 - 236,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Annual bonus
RSU/Equity
Health insurance
Employee Stock Purchase Plan

Job summary

QuantumScape is seeking a Principal AI Security Engineer to own our security AI and automation platform. You will partner with cloud, network security, and detection engineering teams to reduce risk and expand coverage for a small security team.

You will design and operate AI agents on GKE, enforce least‑privilege controls, build MCP servers, and modernize security workflows across SIEM, ITSM, and GRC systems while maintaining auditable, production-grade infrastructure.

Qualifications

  • 10+ years of hands-on cybersecurity, cloud infrastructure, or platform engineering.
  • Experience shipping production software or infrastructure — not just scripts.
  • Hands-on experience with large language models: agent frameworks, tool and function calling, retrieval, prompt engineering, and systematic evaluation.
  • Track record of building or maturing security capabilities from initial gap identification through operationalization in complex environments.
  • Experience working alongside engineering, IT, and infrastructure teams in an embedded or advisory capacity.

Responsibilities

  • Own security AI and automation platform and advise across cloud security, network security, and detection engineering.
  • Develop AI agents and MCP servers with least-privilege, scoped tooling.
  • Build and operate multi-agent security platform on GKE, including routing and provenance.
  • Automate security workflows and integrate with SIEM, ITSM, and GRC platforms.
  • Define escalation gates, and ensure auditable decision provenance for automated actions.

Skills

AI agent engineering
Cloud security
Platform engineering
Python production code
LLMs & agent frameworks
Security advisory

Education

Bachelor's degree in Computer Science or related field

Tools

Google ADK
LangGraph
Anthropic Claude
Model Context Protocol (MCP)
GKE
Terraform
Kubernetes
Google SecOps Chronicle
Entra ID

Job description

QuantumScape is on a mission to transform energy storage with solid-state lithium-metal battery technology. The company’s next‑generation batteries are designed to enable greater energy density, faster charging and enhanced safety to support the transition away from legacy energy sources toward a lower carbon future.

About the Team:

Our Cybersecurity Team sits at the intersection of innovation and protection. We are a small, high‑leverage group that operates like a product engineering team: we build the platforms, agents, and automation that allow a lean team to defend a company with world‑changing intellectual property.

We are actively building an internal agentic AI platform for security and IT operations — multi‑agent workflows that triage incidents, perform asset reconnaissance, run access reviews, and generate audit evidence, with humans in the loop wherever judgment matters. If you are excited about applying AI to hard security problems in a fast‑moving, deeply technical environment, you'll feel right at home here.

What We Need:

We need an engineer who builds. Someone who can stand up cloud infrastructure, reason about a network end to end, and then automate the security work that runs on top of it using AI agents. This role is about replacing manual, repetitive security operations with engineered systems that are auditable, testable, and safe by design.

Here's what that looks like in this role:

  • Design, build, and operate AI agents that perform real security work — incident triage, asset reconnaissance, access reviews, evidence collection, and reporting
  • Engineer the infrastructure those agents run on: Kubernetes, service networking, workload identity, secrets, and observability
  • Build and maintain Model Context Protocol (MCP) servers that connect agents to our security, cloud, and IT platforms with least‑privilege, scoped tooling
  • Replace runbooks and manual toil with automated pipelines that close the loop into ticketing, SIEM, and GRC systems
  • Treat the agent platform as production security infrastructure — no public exposure of internal tooling, least privilege everywhere, full audit trail
  • Hold a high bar for correctness: an agent that is confidently wrong is worse than no agent at all
  • Harden cloud and network environments by identifying gaps, enforcing segmentation, and ensuring monitoring coverage
  • Communicate with clarity across all levels of the organization, adapting your message to your audience
  • Take problems all the way to resolution — not just to identification — closing loops and holding yourself and others accountable
What You'll Do:

As a Principal AI Security Engineer, you will be the technical owner of our security AI and automation platform, and a trusted advisor across cloud security, network security, and detection engineering. You will partner with platform engineering, IT, and infrastructure teams to reduce risk and dramatically increase what a small security team can cover.

Security AI Agent Engineering
  • Build and operate a multi‑agent security platform (Python, Google Agent Development Kit, Anthropic Claude) deployed on GKE — including agent routing, session management, streaming interfaces, and multi‑agent handoff
  • Design human‑in‑the‑loop gating so any agent action with real‑world consequence requires explicit approval, with full decision provenance retained
  • Develop and maintain MCP servers exposing scoped tools over Microsoft Defender XDR, Google SecOps (Chronicle), Entra ID, GCP, Jira/Confluence, and Microsoft 365
  • Build evaluation harnesses and regression suites that measure agent accuracy, tool‑call correctness, and hallucination rate before anything reaches production
  • Own agent observability: prompt and response logging, tool‑call auditing, cost and latency telemetry, and behavioral drift detection
  • Ship analyst‑facing surfaces — a web frontend with SSO and role‑based access control, plus agentic CLI workflows for hands‑on investigation
Security Automation Modernization
  • Identify the highest‑toil security workflows and rebuild them as automated pipelines: alert enrichment, phishing triage, vulnerability ticket routing, access certification, and audit evidence collection
  • Codify detection content and response actions as version‑controlled, peer‑reviewed, testable artifacts (detection‑as‑code)
  • Integrate automation into SIEM, ITSM, and GRC platforms so findings become tracked, closed‑loop work rather than another dashboard
  • Define what stays human: escalation criteria, blast‑radius limits, approval gates, and rollback paths for every automated action
  • Measure and report the outcome — analyst hours reclaimed, mean time to triage, coverage gained, and false‑positive reduction
Cloud & Infrastructure Security Engineering (GCP-focused)
  • Design and harden GCP foundations: organization policy, IAM and service account hygiene, Workload Identity Federation, VPC Service Controls, Secret Manager, CMEK, and Cloud Audit Logs
  • Harden GKE end to end — control plane configuration, node hardening, workload identity, admission control, network policy, and supply chain integrity (image signing, Binary Authorization, SBOM)
  • Build infrastructure as code (Terraform) with policy‑as‑code guardrails so security posture is enforced at deploy time rather than discovered during an audit
  • Eliminate privilege escalation and lateral movement paths across projects, service accounts, and peered networks
  • Instrument cloud telemetry into Google SecOps and validate detection coverage across GCP, Azure, and SaaS log sources
Network & Platform Security
  • Assess and harden network architecture across on‑premises, cloud, and OT‑adjacent environments, ensuring alignment with security best practices
  • Design and enforce segmentation and zero‑trust access patterns, including perimeter and egress controls
  • Partner with IT and infrastructure teams on firewall policy management, private connectivity and cloud interconnects, VPN architecture, and secure remote access
  • Ensure agent and automation workloads follow strict networking principles: private in‑cluster service discovery, controlled egress, and no public exposure of internal tooling
  • Evaluate and improve network visibility tooling (NDR, IDS/IPS, flow logging) and feed that telemetry into automated detection and hunting
  • Provide security guidance on network and platform architecture decisions, including IT/OT boundary controls
Securing AI Itself
  • Own the security model for our own AI usage: prompt injection resistance, tool authorization boundaries, token scoping and lifetime, and data classification controls governing what agents are permitted to read
  • Define and operationalize GenAI governance — approved tooling, handling rules for classified intellectual property, and monitoring of AI application usage across the company
  • Review third‑party AI integrations, connectors, and MCP servers, and build the controls that let the business adopt them safely rather than blocking them outright
  • Track the evolving AI threat landscape and translate it into concrete detections, guardrails, and architecture requirements
Advisory & Cross‑Functional Enablement
  • Act as a security advisor to engineering, platform, and IT teams, translating complex security requirements into practical, actionable guidance
  • Influence technology decisions, architecture reviews, and vendor assessments from a security lens
  • Communicate risk and program progress clearly to both technical and non‑technical stakeholders, including senior leadership
  • Foster a culture of security ownership and automation‑first thinking across the organization
Skills You'll Need

Experience

  • Bachelor's degree in Computer Science, Computer Engineering, or a related technical field and 10+ years of hands‑on experience across cybersecurity, cloud infrastructure, or platform engineering, with demonstrated depth in cloud security, networking, and automation
  • Proven track record shipping production software or infrastructure — not just scripts. You have built systems that other people depend on daily
  • Hands‑on experience building with large language models: agent frameworks, tool and function calling, retrieval, prompt engineering, and systematic evaluation
  • Track record of building or maturing security capabilities from initial gap identification through operationalization in complex, fast‑paced environments
  • Experience working alongside engineering, IT, and infrastructure teams in an embedded or advisory capacity

Technical Skills

  • AI & Agent Engineering: Practical experience with agent frameworks (Google ADK, LangGraph, or equivalent), LLM APIs (Anthropic Claude, Vertex AI, or comparable), Model Context Protocol (MCP), tool‑use design, and agent evaluation. Ability to reason clearly about non‑determinism, guardrails, and failure modes.
  • Programming: Strong production‑quality Python (typing, testing, packaging, async). Working knowledge of a second language such as Go, TypeScript, or PowerShell.
  • Cloud Platforms: Deep GCP expertise — IAM, VPC and networking, GKE, Cloud Run, Secret Manager, Workload Identity Federation, Cloud Logging and Audit Logs, and Security Command Center. Working knowledge of Microsoft Azure and Entra ID.
  • Infrastructure & DevOps: Kubernetes, containers, Terraform, CI/CD pipelines, GitOps, secrets management, and observability tooling.
  • Networking: Strong grasp of TCP/IP, DNS, TLS, routing, firewall management, segmentation, private connectivity and interconnects, IDS/IPS and NDR tooling, and IT/OT boundary controls.
  • Detection & Response: Hands‑on experience with SIEM and XDR platforms including Google SecOps (Chronicle), Microsoft Defender XDR, and Microsoft Sentinel; detection engineering, correlation logic, and response automation.
  • Security Engineering Breadth: Vulnerability management (Tenable or equivalent), endpoint control and application allowlisting (ThreatLocker or equivalent), identity and privileged access (SSO, FIDO2, PAM), and software supply chain security (SBOM, image scanning, signing).
  • Frameworks: MITRE ATT&CK, NIST CSF and NIST SP 800-207, CIS Benchmarks; familiarity with emerging AI security guidance such as the OWASP Top 10 for LLM Applications and the NIST AI Risk Management Framework.
  • Operating Systems: Solid experience across Linux and Windows environments.

Nice to Have

  • Experience securing or operating manufacturing and OT environments
  • Experience with automotive supplier security assessments (TISAX / VDA ISA) or comparable regulated audit regimes
  • Contributions to open‑source agent, MCP, or security tooling

Certifications

  • CISSP (Certified Information Systems Security Professional) preferred
  • Google Professional Cloud Security Engineer, CKA/CKS, or equivalent cloud and Kubernetes certifications strongly considered
  • Relevant certifications such as GCIH, GCFA, GCIA, GCTI, or equivalent advanced certifications are strongly considered
ONSITE:

This position is required to work onsite 5 days per week to meet the minimum essential duties and requirements of this position.

Compensation & Benefits:

The expected salary range for this role is from $155,000 to $236,000 and a final salary will be determined by the candidate's experience, educational background and internal equity. QuantumScape also offers an annual bonus and a generous RSU/Equity package as part of its compensation plan. In addition, we do offer a tremendous benefits plan including employee paid health care, Employee Stock Purchase Plan (ESPP), and other benefits.

We are an equal opportunity employer and value diversity at our company. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status.

We will ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, to perform essential job functions, and to receive benefits and privileges of employment. Please contact us to request an accommodation.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Infrastructure Engineer
Senior Infrastructure Engineer

QuantumScape Battery, Inc. • San Jose (CA)

On-site
USD 126,400 - 192,800
Annual bonus
Employee Stock Purchase Plan
Employee paid health care
Principal AI SOC Engineer
Principal AI SOC Engineer

Quantum Sky • Reston (VA)

Hybrid
USD 200,000 - 225,000
Health/Dental/Vision
401(k) match
Paid Time Off
+4
Senior Infrastructure Engineer (CA, US, 95110)
Senior Infrastructure Engineer (CA, US, 95110)

QuantumScape • United States

On-site
USD 126,400 - 192,800
Annual bonus
Generous RSU/Equity package
Employee-paid health care
Senior Infrastructure Engineer
Senior Infrastructure Engineer

QuantumScape • San Jose (CA)

On-site
USD 126,000 - 193,000
Annual bonus
RSU/Equity
Health benefits
+1
Sr. Director, Enterprise IT Infrastructure (CA, US, 95110)
Sr. Director, Enterprise IT Infrastructure (CA, US, 95110)

QuantumScape • United States

On-site
USD 223,000 - 300,000
Annual bonus
RSU/Equity
Health benefits
AI Security Engineer
AI Security Engineer

AlignityX • McLean (VA)

On-site
USD 100,000 - 200,000
Security Engineer - Member of Technical Staff
Security Engineer - Member of Technical Staff

Simile • San Francisco (CA)

On-site
USD 200,000 - 400,000
Equity grants
Comprehensive medical, dental, and vision coverage
Flexible time off policies
Principal AI Security Engineer, Automation Platform
Principal AI Security Engineer, Automation Platform

QuantumScape • United States

On-site
USD 155,000 - 236,000
Annual bonus
RSU/Equity
Health insurance
+1
Staff Security Engineer
Staff Security Engineer

Topaz Labs • Emeryville (CA)

On-site
USD 130,000 - 160,000
100% covered medical/dental/vision
15 days annual PTO
401k matching
Senior Manager, Security Engineering
Senior Manager, Security Engineering

Quanta Services, Inc. • Houston (TX)

On-site
USD 140,000 - 210,000