Senior Security Engineer

LiteLLM

Tulsa (OK)

On-site

USD 120,000 - 180,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health, dental, and vision benefits

Job summary

LiteLLM is seeking a Senior Security Engineer to join as the first security hire. You’ll own security across application, infrastructure, and the software-delivery pipeline, working directly with engineers to embed secure development practices.

The role emphasizes hands-on security, thorough code reviews of Python components, threat modeling, incident response, and building tooling for SAST/DAST, SBOMs, and secure CI/CD workflows. You’ll shape LiteLLM’s security program from the ground up.

Qualifications

  • Strong security generalist with cross-domain expertise.
  • Deep application-security knowledge, including Python code reviews.
  • Experience with authentication, authorization, and API security.
  • Familiarity with SBOMs, DevSecOps, and vulnerability management.

Responsibilities

  • Conduct deep security reviews of Python proxy, APIs, authentication systems, and enterprise features.
  • Identify and remediate vulnerabilities involving authentication, authorization, secrets, tenant isolation, injection, and data exposure.
  • Partner directly with engineers throughout design, implementation, code review, and release—not only after code is shipped.
  • Build application-security tooling into the development lifecycle, including SAST, DAST, dependency scanning, and secrets detection.
  • Perform internal red teaming and adversarial testing against LiteLLM’s APIs, proxy, and LLM-specific attack surfaces.
  • Threat-model new products and architecture changes before they reach production.
  • Create secure coding guidelines and train engineers on common vulnerabilities and defensive practices.

Skills

Security generalist
Application security
Auth & IAM
Threat modeling
Secure coding
CI/CD security
Vulnerability remediation

Education

Bachelor's or Master's in CS or related field

Tools

Semgrep
Bandit
CodeQL
Burp Suite

Job description

Senior Security Engineer

LiteLLM is the world’s most popular AI Gateway, trusted by companies like Adobe, Netflix, and NASA. Our platform gives developers secure, reliable access to LLMs and adjacent services. We’re looking for our first Security Engineer to help secure LiteLLM’s application, infrastructure, and software-delivery pipeline.

About the role

This is a hands‑on security generalist role with a strong emphasis on application security. You’ll spend most of your time reviewing and hardening LiteLLM’s Python codebase, identifying new attack surfaces, working directly with engineers to fix vulnerabilities, and making secure development practices part of how we build.

You’ll also own security work across IT, CI/CD, cloud infrastructure, and the software supply chain. The ideal candidate has built application/product/infrastructure security programs from scratch and genuinely enjoys security outside of work—through CTFs, vulnerability research, open-source projects, or independent experimentation.

Responsibilities
Application security
  • Conduct deep security reviews of LiteLLM’s Python proxy, APIs, authentication systems, and enterprise features.

  • Identify and remediate vulnerabilities involving authentication, authorization, secrets, tenant isolation, injection, and data exposure.

  • Partner directly with engineers throughout design, implementation, code review, and release—not only after code is shipped.

  • Build application-security tooling into the development lifecycle, including SAST, DAST, dependency scanning, and secrets detection.

  • Perform internal red teaming and adversarial testing against LiteLLM’s APIs, proxy, and LLM‑specific attack surfaces.

  • Threat‑model new products and architecture changes before they reach production.

  • Create secure coding guidelines and train engineers on common vulnerabilities and defensive practices.

Infrastructure, CI/CD, and supply‑chain security
  • Harden LiteLLM’s Docker images, PyPI packages, GitHub Actions workflows, and release infrastructure.

  • Detect dependency confusion, poisoned packages, compromised dependencies, exposed secrets, and unsafe build practices.

  • Implement SBOMs, signed builds, provenance checks, and reproducible‑build practices.

  • Design secure‑by‑default configurations for cloud and self‑hosted deployments, including authentication, IAM, secrets management, and key rotation.

  • Review cloud infrastructure, network boundaries, access controls, and production deployment patterns.

IT security and incident response
  • Strengthen employee identity, device, SaaS, and internal access controls.

  • Build monitoring and anomaly detection for suspicious API, model, authentication, and routing activity.

  • Lead security incident response, vulnerability assessment, remediation, post‑mortems, and stakeholder communication.

  • Establish formal vulnerability intake, CVE triage, disclosure, and remediation processes.

  • Maintain threat models as LiteLLM’s product and architecture evolve.

What we’re looking for
  • A strong security generalist who can work across application security, IT, CI/CD, cloud infrastructure, and the software supply chain.

  • Deep application‑security expertise, including manually auditing production Python code and working with engineers to remediate vulnerabilities.

  • Strong understanding of authentication, authorization, tenant isolation, SSRF, injection, deserialization, secrets management, and common web and API vulnerabilities.

  • Experience using and configuring tools such as Semgrep, Bandit, CodeQL, Burp Suite, and other SAST or DAST tooling.

  • Previous experience at an early‑stage security startup during its 0→1 journey.

  • Experience securing containers, GitHub Actions, build pipelines, packages, and software dependencies.

  • Familiarity with SBOMs, Sigstore, Cosign, Snyk, Grype, Trivy, or equivalent tooling.

  • Strong knowledge of OAuth2, JWT, mTLS, IAM, and high‑throughput API authentication.

  • Familiarity with prompt injection, LLM data exfiltration, tool abuse, and the OWASP Top 10 for LLM Applications.

  • Experience with incident response, CVSS scoring, vulnerability management, CVE triage, and coordinated disclosure.

  • Experience competing in CTFs during college or independently pursuing vulnerability research, reverse engineering, bug bounties, or security projects.

  • A genuine interest in security outside your day job—you regularly explore new attack techniques, build security projects, or contribute to the security community.

  • Bachelor’s or Master’s degree in Computer Science or a related field, or equivalent practical experience.

Why join LiteLLM?
  • Work on application‑security problems at the intersection of AI, APIs, and developer infrastructure.

  • Secure an open‑source product used by enterprises around the world.

  • Work directly with engineers and influence how security is incorporated into product development.

  • Take broad technical ownership in a fast‑moving environment.

  • Competitive salary and health, dental, and vision benefits.

About LiteLLM

LiteLLM is a Python SDK and Proxy Server that enables seamless access to more than 100 LLM APIs through the OpenAI format.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Engineer
Senior Security Engineer

LiteLLM • United States

On-site
USD 140,000 - 210,000
Health insurance
Dental and Vision benefits
Competitive salary
Security Engineer
Security Engineer

LiteLLM • San Francisco (CA)

On-site
USD 140,000 - 190,000
Product Engineer
Product Engineer

LiteLLM • San Francisco (CA)

On-site
USD 150,000 - 210,000
Salary acknowledged equity
Health, dental, and vision benefits
Direct exposure to founders
+1
Senior Security Engineer — App & Cloud Security
Senior Security Engineer — App & Cloud Security

LiteLLM • Tulsa (OK)

On-site
USD 120,000 - 180,000
Health, dental, and vision benefits
Technical Product Manager
Technical Product Manager

LiteLLM • San Francisco (CA)

On-site
USD 120,000 - 180,000
Health insurance
Equity
Dental & Vision
Staff Engineer
Staff Engineer

LiteLLM • San Francisco (CA)

On-site
USD 180,000 - 240,000
Senior Security Engineer - AI Platform & App Security
Senior Security Engineer - AI Platform & App Security

LiteLLM • United States

On-site
USD 140,000 - 210,000
Health insurance
Dental and Vision benefits
Competitive salary
Senior Security Engineer
Senior Security Engineer

Rise Technical Recruitment Limited • Wilmington (DE)

Hybrid
USD 220,000 - 260,000
Equity
Remote work
PTO & Benefits
Security Engineer (AI DevTool Start-Up)
Security Engineer (AI DevTool Start-Up)

Rise Technical Recruitment Limited • San Francisco (CA)

On-site
USD 200,000 - 230,000
Equity
Benefits
401(k)
Founding AI / ML Engineer
Founding AI / ML Engineer

Lume Security • Atlanta (GA)

On-site
USD 100,000 - 130,000
100% medical benefits
Dental benefits
Vision benefits
+1