Security Engineer, Product Security

1 Hour ago • 5 Years + • Full Stack Development

About the job

Job Description

As a founding member of the Product Security team, you'll mature product development workflows, harden service/application architectures, and implement a secure software development lifecycle (SDLC). You'll protect cutting-edge large language models, user data, and reputation by preventing attackers from gaining access. Responsibilities include envisioning and implementing ways to harden products (iOS, Android apps, web apps, and services); implementing framework-level mitigations for vulnerabilities; advocating for a comprehensive SDLC; integrating tooling into CI/CD pipelines; ensuring security in new feature design; coordinating security assessments (penetration tests, bug bounty program management).
Must have:
  • 5+ years in application/product security
  • Familiarity with web application attacks & mitigations
  • Code contribution to complex codebases
  • Implementing secure SDLC in agile startups
  • Cloud experience (GCP or AWS)
  • Experience with web application frameworks & system design
  • CI/CD workflow understanding
  • Linux proficiency
  • Secure system design at scale
  • Kubernetes familiarity
Good to have:
  • Bug bounty program management
  • Mobile application vulnerability knowledge
  • Product feature development experience
  • React/React Native, TypeScript/JavaScript, NextJS, Node.js, Python, Django, Flask, or Golang experience

About the Role

As a founding member of our Product Security team, you will be responsible for maturing our product development workflows, hardening our service and application architectures, and implementing your vision for a secure software development lifecycle. Our user-facing web applications and services are a primary point of interest for threat actors - you will be in the vanguard, responsible for protecting our cutting-edge large language models, user data, and reputation by denying attackers any foothold in our environment. 

What you’ll do

  • Envisioning and implementing ways to holistically harden our product, including iOS and Android mobile applications, web applications, and the web services that support it all

  • Implementing framework-level mitigations for recurrent application vulnerabilities

  • Articulating and advocating for a comprehensive secure software development lifecycle

  • Integrating tooling into CI/CD pipelines to automate the secure development lifecycle

  • Hooking into product design processes to ensure new features are designed with security in mind from the start

  • Coordinating security assessments of product features, including regular penetration tests and managing our bug bounty program

Who you are

Competitive candidates will have:

  • At least 5 years of experience in application or product security

  • Familiarity with common web application and web service attack vectors and their mitigations

  • Ability to understand and contribute code to complex codebases

  • Experience articulating and implementing a secure software development lifecycle in a fast-growing and agile startup 

  • Familiarity with cloud environments such as GCP or AWS

  • Experience with common web application frameworks and system design patterns

  • Understanding of common CI/CD-based workflows

  • Proficiency in Linux-based server environments with a high degree of comfort on the Linux CLI

  • Experience architecting secure system designs to meet product requirements at scale

  • Familiarity with Kubernetes concepts

  • A demonstrated ability to work autonomously to identify and resolve problems independently

Outstanding candidates will have one or more of the following:

  • Experience with bug bounty program management

  • Familiarity with common mobile application vulnerabilities

  • First-hand experience with product feature development

  • Familiarity with React and/or React Native, TypeScript/JavaScript, NextJS, Node.js, Python, Django, Flask, TypeScript, or Golang

  • Our interview process does not require knowledge of any one specific technology or language - these are just some of the key technologies used at Character.ai

  • Previous experience in a technology startup

  • You will be a good fit if you are proactive and have a “get things done” mindset. Given our current pace of growth and load on our systems, most people have had a significant impact during their first week at the company.

About Character.AI

Founded in 2021, Character is a leading AI company offering personalized experiences through customizable AI 'Characters.' As one of the most widely used AI platforms worldwide, Character enables users to interact with AI tailored to their unique needs and preferences.

In just two years, we achieved unicorn status and were named Google Play's AI App of the Year – a testament to our groundbreaking technology and vision.

Ready to shape the future of Consumer AI? 🚀

At Character, we value diversity and welcome applicants from all backgrounds. As an equal opportunity employer, we firmly uphold a non-discrimination policy based on race, religion, national origin, gender, sexual orientation, age, veteran status, or disability. Your unique perspectives are vital to our success.

Compensation Range: $150K - $300K

View Full Job Description

Add your resume

80%

Upload your resume, increase your shortlisting chances by 80%

About The Company

Character is one of the world's leading personal AI platforms. Founded in 2021 by AI pioneers Noam Shazeer and Daniel De Freitas, Character is a full-stack AI company with a globally scaled direct-to-consumer platform. 

California, United States (On-Site)

Menlo Park, California, United States (On-Site)

Menlo Park, California, United States (On-Site)

New York, New York, United States (On-Site)

Menlo Park, California, United States (On-Site)

New York, New York, United States (On-Site)

New York, New York, United States (On-Site)

Menlo Park, California, United States (On-Site)

Menlo Park, California, United States (On-Site)

View All Jobs

Get notified when new jobs are added by Character.AI

Similar Jobs

Get notifed when new similar jobs are uploaded

Similar Skill Jobs

VGW - Frontend Engineer

VGW, Germany (On-Site)

Microsoft - Software Engineer

Microsoft, Costa Rica (On-Site)

Spellbrush - Front-End Engineer (Anime)

Spellbrush, United States (On-Site)

ZeniMax Media - Backend Programmer

ZeniMax Media, United States (On-Site)

Luxoft - Senior Full Stack Developer

Luxoft, Poland (On-Site)

Centum Electronics  - Radar GUI/HMI Developer

Centum Electronics , India (On-Site)

Fliff  Inc  - Senior ReactJS Engineer

Fliff Inc , Bulgaria (Remote)

Get notifed when new similar jobs are uploaded

Jobs in Menlo Park, California, United States

Patreon - Scientist to Machine Learning Engineer

Patreon, United States (Hybrid)

ION - Senior Technical Consultant - Endur

ION, United States (On-Site)

Next Level Business Services - SAP Hybris

Next Level Business Services, United States (On-Site)

Meetelise - Director of Enterprise Sales

Meetelise, United States (Hybrid)

Feld Entertainment - Safety Specialist - Hazwaste

Feld Entertainment, United States (On-Site)

The Walt Disney Company - Senior Software Engineer in Test

The Walt Disney Company, United States (On-Site)

Get notifed when new similar jobs are uploaded

Full Stack Development Jobs

Mozilla - Staff Machine Learning Engineer, Gen AI

Mozilla, Netherlands (Remote)

Social Discovery Group - Senior Automation QA Engineer (C#)

Social Discovery Group, Poland (Remote)

Adobe - Computer Scientist - II

Adobe, India (On-Site)

Next Level Business Services - Java/J2EE Developer

Next Level Business Services, United States (On-Site)

The Walt Disney Company - Sr Software Engineer (Front End/JavaScript)

The Walt Disney Company, United States (On-Site)

Meta - Software Engineer, Pathways Program

Meta, United States (On-Site)

Get notifed when new similar jobs are uploaded