- We’re hiring a Senior Product Security Engineer to work these problems alongside the engineers building the products, reviewing architecture and code, threat modeling before implementation, testing what ships, and turning what you learn into defaults other teams inherit. This is a hands-on engineering role, not an advisory one
- Lead security reviews. Review architecture, code, and security-sensitive changes. Identify both individual vulnerabilities and the recurring design patterns behind them
- Secure AI-powered products. Evaluate risks such as prompt injection, unsafe tool use, identity and delegation failures, excessive agency, data exposure, tenant isolation, and sandbox escapes
- Threat model new capabilities. Identify trust boundaries, abuse cases, and high-impact failure modes before implementation. Translate findings into practical, prioritized mitigations
- Perform hands-on testing. Investigate suspected vulnerabilities, develop proofs of concept, assess exploitability and impact, and partner with engineers through remediation
- Build scalable guardrails. Develop secure defaults, approved patterns, reusable controls, review requirements, and automated checks that reduce recurring risks
- Strengthen engineering capability. Pair with engineers, document practical guidance, and help product teams develop durable security expertise
- Influence risk decisions. Explain technical findings, business impact, and remediation options clearly to engineers, product leaders, and executives
Benefits
- Six weeks’ paid vacation
- Equity / stock options
- RRSP, 401(k), and Pension Scheme contributions
- Coverage for 100% of your insurance premiums across health, dental, vision, and travel
- Additional coverage for accessing mental health providers/services
- Six months of fully paid parental leave, including adoption and surrogacy
- Financial support for egg freezing and IVF in Canada and the UK
- A monthly fitness and wellness allowance
- Globally dispersed company that supports a work from home culture
- A $2,000 annual education benefit for professional development
- A weekly stipend for meals when working remotely and catered lunch when working from one of our global offices
- A monthly arts and culture allowance
- A monthly quality time allowance- You understand common vulnerability classes and their underlying design failures, including injection, authorization flaws, IDOR, SSRF, unsafe deserialization, race conditions, cryptographic misuse, and software supply-chain risks
- You have driven security improvements involving multiple engineering teams, including situations where influence mattered more than authority
- You communicate clearly with both technical and non-technical audiences
- You can reason rigorously about untrusted input, authorization, isolation, identity, delegation, and data boundaries. Direct experience with agentic AI systems is valuable but not required
- You understand modern application architecture, including web applications, APIs, OAuth/OIDC, cloud platforms, containers, Kubernetes, and CI/CD systems
- You have led security reviews or threat models for complex production systems and can point to meaningful design or risk improvements that resulted
- You are proficient in at least one of Python, Go, or TypeScript
- You have strong software engineering fundamentals and can independently understand, test, and contribute fixes to production codebases
- If any of the above doesn’t line up exactly with your experience, we still encourage you to apply
- Offensive security experience through penetration testing, red teaming or security research
- Experience building or operating security tooling such as SAST, DAST, SCA, custom linters, or policy-as-code
- Experience operating or participating in a vulnerability disclosure or bug bounty program
- Contributions to open-source security projects, published research, conference talks, or credited vulnerability discoveries
- Experience securing multi-tenant SaaS, enterprise software, or systems that process sensitive customer data
📌 Product Security Engineer (North Security) (Canada)
🏢 Cohere
📍 Canada