Senior Security Engineer, Product

10 Minutes ago • 5 Years + • Product Management • $200,000 PA - $350,000 PA

Job Summary

Job Description

Lead the application security strategy and implementation for Decagon AI's conversational platform that serves enterprise customers at scale. You'll partner with engineering teams to build security directly into our AI-powered applications, ensuring protection against application-layer threats while maintaining the performance and reliability our customers expect. This role offers the opportunity to apply deep application security expertise to AI systems and shape security practices across our rapidly growing engineering organization.
Must have:
  • Design and implement application security controls across our AI agent platform, including secure coding practices, threat modeling, and vulnerability management.
  • Collaborate closely with product engineering teams to integrate security throughout the software development lifecycle, from design, coding, PR, and deployment
  • Establish application security testing programs including static analysis (SAST), dynamic analysis (DAST), and interactive testing (IAST) tailored for AI applications
  • Lead security code reviews and architecture assessments for new features, with special focus on AI model integration points and customer data handling
  • Build security tooling and automation to enable developers to identify and remediate vulnerabilities quickly while maintaining development velocity
  • Respond to security incidents involving application vulnerabilities, coordinating remediation efforts and post-incident improvements
Good to have:
  • Experience securing AI/ML applications, including prompt injection, model extraction, and adversarial input protections
  • Background with large-scale, multi-tenant SaaS applications handling sensitive customer data
  • Familiarity with Google Cloud application security services and container security best practices
  • Knowledge of enterprise compliance requirements (SOC 2, ISO 27001, GDPR) from an application security perspective
  • Experience with modern security tools like Semgrep, CodeQL, Cursor Bug Bot, XBOW, or similar
Perks:
  • Medical, dental, and vision benefits
  • Take what you need vacation policy
  • Daily lunches, dinners and snacks in the office to keep you at your best

Job Details

About Decagon

Decagon is the leading conversational AI platform empowering every brand to deliver concierge customer experience. Our AI agents provide intelligent, human-like responses across chat, email, and voice, resolving millions of customer inquiries across every language and at any time.

Since coming out of stealth, Decagon has experienced rapid growth. We partner with industry leaders like Hertz, Eventbrite, Duolingo, Oura, Bilt, Curology, and Samsara to redefine customer experience at scale. We've raised over $200M from Bain Capital Ventures, Accel, a16z, BOND Capital, A*, Elad Gil, and notable angels such as the founders of Box, Airtable, Rippling, Okta, Lattice, and Klaviyo.

We’re an in-office company, driven by a shared commitment to excellence and velocity. Our values—customers are everything, relentless momentum, winner’s mindset, and stronger together—shape how we work and grow as a team.

About the Team

The Security Engineering team at Decagon protects the platform that powers the most advanced conversational AI agents for enterprise customers across voice, chat, email and SMS. We build the security foundations that enable Decagon's AI agents to handle sensitive customer data with trust while defending against sophisticated, AI-enabled threats at massive scale.

Our mission is to provide magical support experiences — ensuring that AI agents and human agents can collaborate safely to help users resolve their issues while maintaining the highest standards of security and privacy.

About the Role

Lead the application security strategy and implementation for Decagon AI's conversational platform that serves enterprise customers at scale. You'll partner with engineering teams to build security directly into our AI-powered applications, ensuring protection against application-layer threats while maintaining the performance and reliability our customers expect. This role offers the opportunity to apply deep application security expertise to AI systems and shape security practices across our rapidly growing engineering organization.

In this role, you will

  • Design and implement application security controls across our AI agent platform, including secure coding practices, threat modeling, and vulnerability management.
  • Collaborate closely with product engineering teams to integrate security throughout the software development lifecycle, from design, coding, PR, and deployment
  • Establish application security testing programs including static analysis (SAST), dynamic analysis (DAST), and interactive testing (IAST) tailored for AI applications
  • Lead security code reviews and architecture assessments for new features, with special focus on AI model integration points and customer data handling
  • Build security tooling and automation to enable developers to identify and remediate vulnerabilities quickly while maintaining development velocity
  • Respond to security incidents involving application vulnerabilities, coordinating remediation efforts and post-incident improvements

Your background looks something like this

  • Have 5+ years of hands-on application security engineering experience
  • Expertise in secure software development practices, including threat modeling, secure code review, and vulnerability assessment
  • Strong software engineering background with ability to review code across multiple languages and frameworks commonly used in AI/ML applications
  • Experience implementing application security testing tools and integrating security into CI/CD pipelines
  • Knowledge of OWASP Top 10, common application vulnerabilities, and modern application security frameworks
  • Proven track record working with engineering teams to remediate security findings while balancing security and business requirements

Even better

  • Experience securing AI/ML applications, including prompt injection, model extraction, and adversarial input protections
  • Background with large-scale, multi-tenant SaaS applications handling sensitive customer data
  • Familiarity with Google Cloud application security services and container security best practices
  • Knowledge of enterprise compliance requirements (SOC 2, ISO 27001, GDPR) from an application security perspective
  • Experience with modern security tools like Semgrep, CodeQL, Cursor Bug Bot, XBOW, or similar

Benefits:

  • Medical, dental, and vision benefits
  • Take what you need vacation policy
  • Daily lunches, dinners and snacks in the office to keep you at your best

Similar Jobs

Looks like we're out of matches

Set up an alert and we'll send you similar jobs the moment they appear!

Similar Skill Jobs

Looks like we're out of matches

Set up an alert and we'll send you similar jobs the moment they appear!

Jobs in San Francisco, California, United States

Looks like we're out of matches

Set up an alert and we'll send you similar jobs the moment they appear!

Product Management Jobs

Looks like we're out of matches

Set up an alert and we'll send you similar jobs the moment they appear!

About The Company

San Francisco, California, United States (On-Site)

San Francisco, California, United States (On-Site)

San Francisco, California, United States (On-Site)

San Francisco, California, United States (On-Site)

New York, New York, United States (On-Site)

San Francisco, California, United States (Hybrid)

San Francisco, California, United States (On-Site)

San Francisco, California, United States (On-Site)

New York, New York, United States (On-Site)

San Francisco, California, United States (Hybrid)

View All Jobs

Get notified when new jobs are added by Decagon

Level Up Your Career in Game Development!

Transform Your Passion into Profession with Our Comprehensive Courses for Aspiring Game Developers.

Job Common Plug