Staff Security Engineer - Product Security

4 Months ago • 5 Years +

About the job

Job Description

Product Security Engineer role at Character.ai requires 5+ years of application security experience, familiarity with web application attacks & mitigations, and secure SDLC implementation.
Must have:
  • Application Security
  • Web Application Attacks
  • Secure SDLC
  • Cloud Environments
Good to have:
  • Bug Bounty
  • Mobile App Vulnerabilities
  • React/React Native
  • TypeScript/JavaScript
Perks:
  • Fast-Growing Startup
  • Shape the Future
Not hearing back from companies?
Unlock the secrets to a successful job application and accelerate your journey to your next opportunity.

About the Role

Responsibilities:

As a founding member of our Product Security team, you will be responsible for maturing our product development workflows, hardening our service and application architectures, and implementing your vision for a secure software development lifecycle. Our user-facing web applications and services are a primary point of interest for threat actors - you will be in the vanguard, responsible for protecting our cutting-edge large language models, user data, and reputation by denying attackers any foothold in our environment. 

Job responsibilities may include:

  • Envisioning and implementing ways to holistically harden our product, including iOS and Android mobile applications, web applications, and the web services that support it all

  • Implementing framework-level mitigations for recurrent application vulnerabilities

  • Articulating and advocating for a comprehensive secure software development lifecycle

  • Integrating tooling into CI/CD pipelines to automate the secure development lifecycle

  • Hooking into product design processes to ensure new features are designed with security in mind from the start

  • Coordinating security assessments of product features, including regular penetration tests and managing our bug bounty program

Requirements:

Competitive candidates will have:

  • At least 5 years of experience in application or product security

  • Familiarity with common web application and web service attack vectors and their mitigations

  • Ability to understand and contribute code to complex codebases

  • Familiarity with common web application authentication flows.

  • Experience articulating and implementing a secure software development lifecycle in a fast-growing and agile startup 

  • Familiarity with cloud environments such as GCP or AWS

  • Experience with common web application frameworks and system design patterns

  • Understanding of common CI/CD-based workflows

  • Proficiency in Linux-based server environments with a high degree of comfort on the Linux CLI

  • Experience architecting secure system designs to meet product requirements at scale

  • Familiarity with Kubernetes concepts

  • A demonstrated ability to work autonomously to identify and resolve problems independently

Outstanding candidates will have one or more of the following:

  • Experience with bug bounty program management

  • Familiarity with common mobile application vulnerabilities

  • First-hand experience with product feature development

  • Familiarity with React and/or React Native, TypeScript/JavaScript, NextJS, Node.js, Python, Django, Flask, or Golang

    • Our interview process does not require knowledge of any one specific technology or language - these are just some of the key technologies used at Character.ai

  • Previous experience in a technology startup

You will be a good fit if you are proactive and have a “get things done” mindset. Given our current pace of growth and load on our systems, most people have had a significant impact during their first week at the company.

About Character.AI

Founded in 2021, Character is a leading AI company offering personalized experiences through customizable AI 'Characters.' As one of the most widely used AI platforms worldwide, Character enables users to interact with AI tailored to their unique needs and preferences.

In just two years, we achieved unicorn status and were named Google Play's AI App of the Year – a testament to our groundbreaking technology and vision.

Ready to shape the future of Consumer AI? 🚀

At Character, we value diversity and welcome applicants from all backgrounds. As an equal opportunity employer, we firmly uphold a non-discrimination policy based on race, religion, national origin, gender, sexual orientation, age, veteran status, or disability. Your unique perspectives are vital to our success.

Compensation Range: $150K - $350K

View Full Job Description

Add your resume

80%

Upload your resume, increase your shortlisting chances by 80%

About The Company

Character is one of the world's leading personal AI platforms. Founded in 2021 by AI pioneers Noam Shazeer and Daniel De Freitas, Character is a full-stack AI company with a globally scaled direct-to-consumer platform. 

Menlo Park, California, United States (On-Site)

Menlo Park, California, United States (On-Site)

New York, New York, United States (On-Site)

Menlo Park, California, United States (On-Site)

New York, New York, United States (On-Site)

New York, New York, United States (On-Site)

Menlo Park, California, United States (On-Site)

Menlo Park, California, United States (On-Site)

View All Jobs

Get notified when new jobs are added by Character.AI

Similar Jobs

Rockstar Games - Lead Data Security Engineer

Rockstar Games, United Kingdom (On-Site)

Embark Studios - Game Security Engineer

Embark Studios, Sweden (On-Site)

Rockstar Games - Data Security Engineer

Rockstar Games, United States (On-Site)

ESL FACEIT Group - EFG - Senior Security Engineer - Remote

ESL FACEIT Group - EFG, (Remote)

Zynga - Application Security Engineer

Zynga, India (On-Site)

Blizzard Entertainment - Principal Game Security Engineer

Blizzard Entertainment, United States (Hybrid)

The Workshop - Security Engineer - Blockchain

The Workshop, Spain (Hybrid)

Get notifed when new similar jobs are uploaded

Similar Skill Jobs

Tencent - Senior Software Engineer - Network

Tencent, China (On-Site)

Fantastic Pixel Castle - Principal Technical Animator

Fantastic Pixel Castle, United States (Remote)

Felix & Paul Studios - Artiste technique / Technical Artist

Felix & Paul Studios, Canada (Hybrid)

CD PROJEKT RED - Character Animator

CD PROJEKT RED, Poland (On-Site)

Starkflow - Technical Lead - Odoo

Starkflow, Mexico (On-Site)

Sandsoft Games - Senior QA Lead

Sandsoft Games, Saudi Arabia (On-Site)

Sandsoft Games - Senior QA Lead

Sandsoft Games, Spain (On-Site)

Blizzard Entertainment - Senior Software Engineer, Game Services, Battle.Net

Blizzard Entertainment, United States (Hybrid)

Get notifed when new similar jobs are uploaded

Jobs in Menlo Park, California, United States

Evolution - Receptionist

Evolution, United States (On_site)

Keywords Studios (Player Support) - Label Management Associate

Keywords Studios (Player Support), United States (On-Site)

PlayStation Global - QA Lead

PlayStation Global, United States (On-Site)

PlayStation Global - Staff Program Manager

PlayStation Global, United States (On-Site)

CD PROJEKT RED - Gameplay Designer

CD PROJEKT RED, United States (Hybrid)

CD PROJEKT RED - Lead Mission Designer

CD PROJEKT RED, United States (Hybrid)

Rockstar Games - Senior Manager, Communications Operations

Rockstar Games, United States (On-Site)

Patreon - Senior Product Designer

Patreon, United States (Hybrid)

Patreon - Senior Product Designer

Patreon, United States (Hybrid)

Blizzard Entertainment - Senior Software Engineer, Game Services, Battle.Net

Blizzard Entertainment, United States (Hybrid)

Get notifed when new similar jobs are uploaded

Similar Category Jobs

Tencent - Senior Software Engineer - Network

Tencent, China (On-Site)

Evolution - Receptionist

Evolution, United States (On_site)

Evolution - Procurement Coordinator

Evolution, Brazil (On-Site)

PlayStation Global - Manager, Partner Sourcing

PlayStation Global, United Kingdom (On-Site)

Azra Games - Feature Designer

Azra Games, United States (Hybrid)

Get notifed when new similar jobs are uploaded