Product Security Engineer, North Security
Security Engineer · Senior · Full Time · Remote
Opens Cohere's application page
Role
What you'll do.
Cohere is hiring a Senior Product Security Engineer to work on frontier AI model security for enterprise customers. This hands-on engineering role involves leading security reviews, threat modeling AI-powered products, performing vulnerability testing, and building scalable security controls for complex systems handling sensitive enterprise data. The ideal candidate combines strong software engineering fundamentals with production security expertise, particularly in emerging areas like prompt injection, agentic AI systems, and multi-tenant isolation.
Responsibilities
- Lead Security Reviews and Architecture Assessment: Conduct comprehensive security reviews of architecture, codebase, and security-sensitive changes across product teams. Identify both individual vulnerabilities and systemic design patterns that create recurring security risks. Provide actionable feedback that improves both immediate security posture and long-term system resilience.
- Secure AI-Powered Products: Evaluate and mitigate AI-specific security risks including prompt injection attacks, unsafe tool utilization, identity and delegation failures, excessive agentic behavior, unauthorized data exposure, tenant isolation breaches, and sandbox escape scenarios. Apply security domain expertise to novel attack surfaces unique to generative AI systems.
- Perform Threat Modeling and Risk Analysis: Lead threat modeling sessions for new capabilities before implementation. Identify trust boundaries, document abuse cases, and map high-impact failure modes. Translate security findings into prioritized, practical mitigations that product teams can execute during development cycles.
- Conduct Hands-On Vulnerability Testing: Investigate suspected vulnerabilities independently, develop proofs of concept, assess exploitability and business impact, and work collaboratively with engineering teams through remediation. Perform both automated and manual testing to validate security assumptions in production systems.
- Build Scalable Security Guardrails and Controls: Design and implement secure defaults, approved design patterns, and reusable security controls that reduce recurring vulnerability classes. Develop review requirements, automated security checks, and policy-as-code solutions that scale across multiple engineering teams.
- Strengthen Engineering Security Capability: Partner directly with engineers to build lasting security expertise within product teams. Document practical security guidance, share threat modeling techniques, and mentor engineers on secure coding practices for AI systems. Transform security reviews into learning opportunities for product teams.
- Influence Risk-Based Decision Making: Communicate technical security findings, business impact analysis, and remediation trade-offs clearly to engineers, product leaders, and executive stakeholders. Present security risks with appropriate context to enable informed risk decisions across the organization.
Qualifications
What we look for.
Technical
Software Engineering Fundamentals
Strong foundation in software engineering principles with ability to independently understand, analyze, test, and contribute fixes to production codebases. Demonstrated proficiency reading and understanding complex production code across various architectural patterns.
Programming Language Proficiency
Production-level proficiency in at least one of Python, Go, or TypeScript. Ability to write functional security tooling, proof-of-concept exploits, and automated security tests in one or more of these languages.
Vulnerability Analysis and Classification
Deep understanding of common vulnerability classes and their underlying root causes, including injection attacks, authorization flaws, IDOR, SSRF, unsafe deserialization, race conditions, cryptographic misuse, and software supply-chain vulnerabilities. Ability to recognize patterns and identify systemic design failures.
Modern Application Architecture Knowledge
Comprehensive understanding of contemporary application architectures including RESTful and GraphQL APIs, OAuth/OIDC authentication flows, cloud platform security models, containerization, Kubernetes orchestration, CI/CD pipeline security, and infrastructure-as-code security considerations.
Security Domain Modeling
Rigorous reasoning capability about security domains including untrusted input handling, authorization models, isolation mechanisms, identity management, delegation patterns, and data boundary protection. Strong conceptual foundation in applied cryptography and secure system design principles.
Education
Bachelor's Degree in Computer Science or Related Field
Formal education in computer science, cybersecurity, electrical engineering, mathematics, or closely related field, or equivalent professional experience demonstrating mastery of foundational computer science and security concepts.
Experience
Production Security Review Leadership
Demonstrated track record leading security reviews and threat modeling exercises for complex, production-grade systems. Ability to point to specific examples where security recommendations resulted in meaningful design improvements and measurable risk reduction.
Multi-Team Security Influence
Experience driving security improvements across multiple engineering teams, particularly in situations where influence and technical credibility mattered more than formal authority. Proven ability to collaborate effectively with engineers who may initially resist security recommendations.
Multi-Tenant or Sensitive Data Systems
Production experience securing multi-tenant SaaS platforms, enterprise software, or systems that process sensitive customer data. Understanding of data isolation requirements, customer data protection obligations, and the security implications of shared infrastructure.
Secure Code and Architectural Assessment
Hands-on experience reviewing code for security vulnerabilities and assessing application architecture for security flaws. Ability to identify both obvious vulnerabilities and subtle design patterns that create security risks.
Skills
Required
Python
Production-level Python proficiency for analyzing codebases, writing security tooling, and developing vulnerability proofs of concept.
Go
Production-level Go proficiency for understanding modern systems code and contributing security fixes to Go-based production systems.
TypeScript
Production-level TypeScript/JavaScript proficiency for analyzing and securing web applications and backend services.
Threat Modeling
Ability to systematically identify attack surfaces, trust boundaries, and failure modes in complex systems before implementation.
Vulnerability Assessment
Capability to identify, classify, assess exploitability, and determine business impact of security vulnerabilities in production systems.
Security Code Review
Expertise conducting detailed security reviews of application code and architecture to identify vulnerabilities and design flaws.
OAuth/OIDC Authentication
Deep understanding of modern authentication and authorization mechanisms, including OAuth 2.0, OpenID Connect, and identity delegation flows.
API Security
Comprehensive knowledge of REST API security, GraphQL security, and security considerations for service-to-service communication.
Cloud Security
Understanding of cloud platform security models, cloud-native security controls, and security implications of cloud infrastructure choices.
Preferred
Agentic AI System Security
Nice to haveDirect experience securing systems with autonomous AI agents, including understanding of prompt injection vectors, agent behavior control, and tool-use safety mechanisms.
Security Tooling Development
Nice to haveExperience building or operating security tools including Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA), custom linters, or policy-as-code solutions.
Offensive Security Experience
Nice to haveBackground in penetration testing, red team exercises, or independent security research demonstrating ability to think like an attacker and identify novel attack vectors.
Vulnerability Disclosure Program Management
Nice to haveExperience operating, coordinating, or participating in vulnerability disclosure programs or bug bounty initiatives, including coordinating researcher submissions and remediation workflows.
Public Security Contributions
Nice to haveOpen-source security project contributions, published security research, conference presentations on security topics, or credited vulnerability discoveries demonstrating commitment to security community.
Kubernetes Security
Nice to haveProduction experience securing Kubernetes deployments, including understanding of container security, network policies, RBAC, and supply chain security for container images.
CI/CD Security
Nice to haveExperience securing continuous integration and continuous deployment pipelines, including supply chain security and build system hardening.
Cryptography Implementation Knowledge
Nice to haveUnderstanding of cryptographic algorithms, common implementation pitfalls, and practical guidance on secure cryptographic design patterns in applications.
Tech stack
Languages
Frameworks
Databases
Tools
Other
Compensation
Pay and benefits.
Base·USD 180,000 – 385,000
Equity·Stock options
Benefits
Weekly Lunch Stipend
Receive $75 USD weekly lunch allowance (or equivalent in local currency) to support meal costs during workdays.
Comprehensive Health and Dental Coverage
Full health insurance and dental benefits with separate mental health budget, supporting overall wellness and preventive care.
Retirement Planning Benefits
RRSP matching for Canadian employees, 401(k) for US employees, and Pension Scheme access for international employees.
Parental Leave Top-Up
100% salary continuation for up to 6 months parental leave for either parent, supporting work-life balance and family planning.
Annual Enrichment Benefits
Budget allocated annually for arts and culture activities, fitness and wellness programs, quality time initiatives, and workspace improvement credit to personalize your work environment.
Education and Learning Stipend
Annual budget for professional development including conference attendance, online courses, workshops, and executive coaching.
Generous Vacation Policy
6 weeks of paid vacation time (30 working days annually) enabling extended time off for rest, travel, and personal pursuits.
Office Travel and Offsite Budget
Budget for traveling to other Cohere office locations if working remotely, plus annual company offsite events for team building and collaboration.
Home Office Setup Stipend
One-time $500 stipend to properly set up and equip your home workspace with ergonomic furniture and tools.
Flexible Work Arrangement
Remote-first work model with option to work from any of Cohere's global offices including Toronto, London, NYC, San Francisco, Montreal, Paris, Berlin, and Seoul.
Co-Working Benefit
For remote employees not near a Cohere office, access to co-working spaces in your city to work alongside other professionals.
Office Perks
Daily lunch programs, abundant snacks, and regular community and social events at physical office locations.
Full posting
Original listing.
Who are we?
Cohere is the leading security-first enterprise AI company. We build cutting-edge foundation AI models and end-to-end products that are designed to solve real-world business problems.
We’re training and deploying frontier models for enterprises who are building AI systems. We believe that our work is instrumental to the widespread adoption of AI and we are looking for folks that want to be part of that.
We obsess over what we build. Each one of us is responsible for contributing to increasing the capabilities of our models and the value they drive for our customers. Cohere is a team of researchers, engineers, designers, and more, who are all passionate about their craft.
We are a global technology company headquartered in Toronto with key offices in London, New York City, San Francisco, Montreal, Paris, Berlin and Seoul. Join us!
Why this role
Enterprises hand Cohere their most sensitive data and put our models inside workflows they can't afford to get wrong. Securing that means working on problems the industry hasn't settled yet, what authorization means when an agent acts on a user's behalf, how to contain tools that consume untrusted input, and whether tenant boundaries hold when a model can be steered by the data it reads. The established playbooks only take you so far.
We're hiring a Senior Product Security Engineer to work these problems alongside the engineers building the products, reviewing architecture and code, threat modeling before implementation, testing what ships, and turning what you learn into defaults other teams inherit. This is a hands-on engineering role, not an advisory one.
What you’ll do
Lead security reviews. Review architecture, code, and security-sensitive changes. Identify both individual vulnerabilities and the recurring design patterns behind them.
Secure AI-powered products. Evaluate risks such as prompt injection, unsafe tool use, identity and delegation failures, excessive agency, data exposure, tenant isolation, and sandbox escapes.
Threat model new capabilities. Identify trust boundaries, abuse cases, and high-impact failure modes before implementation. Translate findings into practical, prioritized mitigations.
Perform hands-on testing. Investigate suspected vulnerabilities, develop proofs of concept, assess exploitability and impact, and partner with engineers through remediation.
Build scalable guardrails. Develop secure defaults, approved patterns, reusable controls, review requirements, and automated checks that reduce recurring risks.
Strengthen engineering capability. Pair with engineers, document practical guidance, and help product teams develop durable security expertise.
Influence risk decisions. Explain technical findings, business impact, and remediation options clearly to engineers, product leaders, and executives.
You may be a good fit if
You have strong software engineering fundamentals and can independently understand, test, and contribute fixes to production codebases.
You are proficient in at least one of Python, Go, or TypeScript.
You have led security reviews or threat models for complex production systems and can point to meaningful design or risk improvements that resulted.
You understand common vulnerability classes and their underlying design failures, including injection, authorization flaws, IDOR, SSRF, unsafe deserialization, race conditions, cryptographic misuse, and software supply-chain risks.
You understand modern application architecture, including web applications, APIs, OAuth/OIDC, cloud platforms, containers, Kubernetes, and CI/CD systems.
You can reason rigorously about untrusted input, authorization, isolation, identity, delegation, and data boundaries. Direct experience with agentic AI systems is valuable but not required.
You have driven security improvements involving multiple engineering teams, including situations where influence mattered more than authority.
You communicate clearly with both technical and non-technical audiences.
Nice to have
Experience building or operating security tooling such as SAST, DAST, SCA, custom linters, or policy-as-code.
Experience securing multi-tenant SaaS, enterprise software, or systems that process sensitive customer data.
Offensive security experience through penetration testing, red teaming or security research.
Experience operating or participating in a vulnerability disclosure or bug bounty program.
Contributions to open-source security projects, published research, conference talks, or credited vulnerability discoveries.
Full-Time Employees at Cohere enjoy these Perks:
A weekly lunch stipend of $75/£75 or equivalent in your local currency for lunch.
Full health and dental benefits, including a separate budget for mental health.
RRSP matching, 401K, Pension Scheme.
100% Parental Leave top-up for up to 6 months, for either parent.
Annual enrichment benefits:
Arts & culture, fitness/wellness, quality time, and a workspace improvement credit.
Education & learning stipend for conferences, courses, and coaching.
6 weeks of paid vacation (30 working days!)
Budget for traveling to other offices if you are remote, plus an annual company offsite.
How and Where We Work:
Cohere is remote-friendly, but we also have offices in Toronto, London, New York City, San Francisco, Montreal, Paris, Berlin and Seoul with more opening soon.
For those in the office: a daily lunch program, plenty of snacks, and regular community and social events.
For those not near an office: a co-working benefit so you can work alongside others in your city.
Everyone receives a $500 home office stipend to set up your workspace properly.
If any of the above doesn’t line up exactly with your experience, we still encourage you to apply.
We strive to create an inclusive work environment for all; we welcome applicants from all backgrounds and are committed to providing equal opportunities. Should you require any accommodations during the recruitment process, please submit an Accommodations Request Form, and we will work together to meet your needs.
We may use AI-enabled tools to screen and assess applicants against the criteria for this position. This helps our recruiters identify potentially qualified candidates, but it doesn't limit the applications our recruiters may review or consider.
Beware of Scams: Cohere will never ask for payment or third-party services (e.g., CV writing) as part of our hiring process. All legitimate roles are listed on the Cohere careers page and LinkedIn only, with all communications from Cohere employees coming from an @cohere.com or @cw.cohere email alias. If jobs are viewed on other sites then please verify these through our official careers page.
Redirects to Cohere's application page.
Other roles
More at Cohere.
Software Engineer, Data Infrastructure
Mid
Forward Deployed Engineer, Infrastructure Specialist (Middle East)
Mid
Forward Deployed Engineer, Agentic Platform (West Coast)
Senior
Senior Mobile Engineer (iOS or Android)
Senior
Forward Deployed Engineer, Agentic Platform (UK Public Sector)
Senior