Senior Security Engineer

Foundation Capital

Phoenix (AZ)

On-site

USD 130,000 - 190,000

Full time

3 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Foundation Capital is seeking a Security Engineer to join the AI Platform Security team. This role emphasizes ownership and setting direction, owning security outcomes for a portfolio of products, and defining how security reviews and standards operate across the organization.

You will push for risk-informed decisions, build tooling, and drive security integration across the SDLC. The ideal candidate will have hands-on security engineering experience and a track record of independent program

Qualifications

  • Security engineer with strong application security expertise and ownership mindset.
  • Ability to design reviews, threat models, and risk acceptance for a portfolio of products.
  • Experience leading vulnerability management and bug bounty programs.
  • Proficiency in Python/ JS/ Go/ Java and ability to read and reason about unfamiliar codebases.

Responsibilities

  • Own end-to-end security for an assigned portfolio of products, including reviews, threat modeling, risk acceptance, and driving high-severity findings to closure.
  • Define the security review bar, standards, checklists, and intake processes used by engineers across the org.
  • Lead vulnerability management and bug bounty program operations, including triage, escalation, SLA ownership, and program evolution.
  • Design and build security automation and tooling to reduce manual toil and scale coverage.

Skills

Security engineering
Application security
Threat modeling
Vulnerability management
CI/CD security
Programming (Python/JS/Go/Java)
Communication

Education

Bachelor's degree in Computer Science

Tools

Snyk
Burp Suite
DAST
SAST

Job description

We're looking for a Security Engineer to join our AI Platform Security team. It is a high-ownership, low-oversight role for an application/product security generalist who has already done the work and is ready to set direction rather than follow it. You'll own security outcomes for a portfolio of products, define how security reviews and standards operate across the organization, and build the tooling and programs that let a lean team cover a large surface area.

We are a lean, high-trust team. You'll make real risk calls, push back on engineering leadership when the data supports it, and be accountable for the areas you own while helping to shape how this team operates as it scales.

What You’ll Do:
  • Own end-to-end security for an assigned portfolio of products: design reviews, threat modeling, risk acceptance, and driving high-severity findings to closure
  • Set technical direction for your program areas: define the review bar, standards, checklists, and intake processes other engineers follow
  • Lead vulnerability management and the bug bounty program: complex triage, escalation, researcher relations, SLA ownership, and program evolution
  • Design and build security automation and internal tooling that removes manual toil and scales coverage beyond headcount
  • Drive shift-left adoption across the SDLC through pipeline gates, guardrails, paved-path patterns, and developer enablement
  • Lead the team's AI/LLM security practice: assessment methodology, testing approach, and applied frameworks for agentic and model-backed features
  • Communicate risk and program health to engineering and executive leadership through metrics, reporting, and clear written narratives
Who We're Looking For:
  • Experience in security engineering, application security, offensive security, or a closely related technical discipline
  • Deep, demonstrated knowledge of vulnerability classes and exploitation: injection, authentication and session flaws, access control, deserialization, SSRF, and their real-world variants
  • Ability to read, review, and write code in at least one language (Python, JavaScript/TypeScript, Go, or Java), and to reason about unfamiliar codebases quickly
  • Track record of owning a security program area independently and driving cross-functional remediation without formal authority
  • Experience threat modeling non-trivial systems and translating findings into decisions engineering teams will actually act on
  • Excellent written communication. You will produce standards, risk narratives, executive reporting, and researcher-facing correspondence
  • Comfort operating with ambiguity and building structure where none exists yet
Preferred:
  • Experience running or substantially maturing a bug bounty or vulnerability disclosure program
  • Hands-on depth with security tooling such as Snyk, Burp Suite, DAST, or SAST platforms, including tuning and integration rather than just usage
  • Demonstrated ability to build security automation or internal tooling used by othersApplied understanding of AI/LLM security risks: prompt injection, insecure tool use, context and data leakage, model supply chain
  • Prior mentorship, tech lead, or team lead experience
  • Bug bounty participation as a researcher, published research, or CVE credit
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Engineering Manager, Application Security
Engineering Manager, Application Security

Qualia • Austin (TX)

On-site
USD 180,000 - 240,000
Medical, Dental & Vision health plans
Competitive salary & equity
Flexible schedules
+3
Senior Product Security Engineer
Senior Product Security Engineer

Function • United States

On-site
USD 150,000 - 190,000
Choose your own holidays
Health Insurance
401k Match
Senior Security Engineer - AI Focus
Senior Security Engineer - AI Focus

Euna Solutions • Atlanta (GA)

On-site
USD 140,000 - 210,000
Product Security Engineer
Product Security Engineer

Stellar IT Solutions LLC • Sunnyvale (CA)

On-site
USD 140,000 - 200,000
Senior Engineer, AI Security
Senior Engineer, AI Security

New York Technology Partners • Plano (TX)

On-site
USD 150,000 - 190,000
Staff Software Security Engineer
Staff Software Security Engineer

Colossus Technologies Group • United States

Remote
USD 220,000 - 270,000
Early-stage equity
Remote (US)
Senior Security Engineer
Senior Security Engineer

ThoughtSpot • Phoenix (AZ), Northern (KY)

Hybrid
USD 120,000 - 180,000
Security Engineer
Security Engineer

Clera • San Francisco (CA)

On-site
USD 180,000 - 250,000
Medical, dental, vision coverage
401k
Visa sponsorship
+2
Sr Engineer I, Product Security
Sr Engineer I, Product Security

NextGen Healthcare, Inc. • Atlanta (GA)

On-site
USD 150,000 - 230,000
Security Engineer
Security Engineer

AegisAI, Inc. • United States

Remote
USD 120,000 - 180,000