Security Engineer
Mid · Full Time
Opens LiteLLM's application page
Role
What you'll do.
Security Engineer at LiteLLM, the world's most popular AI Gateway trusted by companies like Adobe, Netflix, and NASA. You'll own the security posture across application and CI/CD levels, proactively identifying and neutralizing vulnerabilities while ensuring zero critical security incidents. This role requires hands-on security engineering expertise, offensive security skills, and proven experience with application security and supply chain protection in a fast-paced, high-impact technical environment.
Responsibilities
- Application Security Ownership: Own all aspects of LiteLLM's application-level security posture with accountability for maintaining zero critical or high-severity vulnerabilities. Conduct regular security assessments, implement secure coding practices, and ensure all application components meet enterprise-grade security standards.
- Vulnerability Identification and Remediation: Proactively identify, assess, and remediate potential attack vectors across the platform through code reviews, penetration testing, and security audits. Actively hunt for vulnerabilities using offensive security techniques and white-hat hacking methodologies to stay ahead of emerging threats.
- CI/CD Security and Supply Chain Protection: Oversee CI/CD pipeline security and ensure secure release processes with zero supply chain incidents. Implement secure infrastructure practices, manage dependency vulnerabilities, secure container registries, and enforce authentication and authorization controls throughout the deployment pipeline.
- Cross-Functional Security Collaboration: Collaborate with engineering, infrastructure, and product teams to embed security throughout the software development lifecycle and deployment processes. Provide security guidance, conduct threat modeling sessions, and mentor developers on secure coding practices.
- Security Posture Enhancement: Continuously improve and adapt security practices to address emerging threats in the AI/LLM space and broader technology landscape. Research new attack vectors, evaluate security tools and technologies, and implement offensive security improvements to strengthen defenses.
- Incident Response and Threat Analysis: Lead incident response efforts for security incidents, conduct root cause analysis, and implement preventive measures. Monitor security logs and alerts, investigate suspicious activities, and maintain documentation of security events and remediation actions.
Qualifications
What we look for.
Technical
Application Security Engineering
Deep expertise in identifying and remediating application-level vulnerabilities including OWASP Top 10, API security, authentication/authorization flaws, and injection attacks. Experience with secure code review techniques and static/dynamic security analysis tools.
CI/CD Security and DevSecOps
Hands-on experience securing continuous integration and deployment pipelines. Knowledge of container security (Docker/Kubernetes), secrets management, supply chain security, Software Bill of Materials (SBOM), and secure build practices.
Offensive Security and Penetration Testing
Proven background in offensive security, white-hat hacking, or penetration testing. Experience with security testing tools, vulnerability scanning, and exploitation techniques to identify and validate security weaknesses.
Python and Backend Security
Strong proficiency in Python for security automation, scripting, and analysis. Understanding of backend/server security principles, API security, and secure integration patterns relevant to LiteLLM's Python SDK architecture.
Security Tools and Practices
Proficiency with security scanning tools, SAST/DAST solutions, vulnerability management platforms, and monitoring systems. Experience with security frameworks, compliance standards, and threat modeling methodologies.
Education
Computer Science or Cybersecurity Foundation
Bachelor's degree in Computer Science, Cybersecurity, Information Security, or related technical field, or equivalent hands-on security experience and demonstrable expertise through certifications or published work.
Security Certifications (Preferred)
Relevant security certifications such as OSCP, GPEN, CEH, or similar demonstrate commitment to professional security engineering. Advanced certifications indicate specialized expertise in offensive security or application security domains.
Experience
Startup Security Leadership
Proven experience building security programs at early-stage startups (Seed through Series D). Demonstrated ability to work independently, prioritize security initiatives with limited resources, and wear multiple hats in fast-paced environments.
Security Engineering Track Record
3+ years of hands-on security engineering experience with demonstrated impact on application security and infrastructure hardening. Portfolio of security-related projects showcased on GitHub, personal blog, or similar platforms.
Capture The Flag (CTF) Participation
Evidence of competitive security skills through Capture The Flag competition wins or strong performance. CTF experience demonstrates practical vulnerability identification, exploitation, and problem-solving abilities.
API and LLM Security Familiarity
Experience with API security best practices and ideally exposure to AI/LLM infrastructure security challenges. Understanding of model API gateway architecture and associated security considerations.
Skills
Required
Python Security Automation
Ability to write Python scripts for security automation, vulnerability analysis, and integration with security tools. Critical for developing custom security solutions within LiteLLM's Python-based platform.
Vulnerability Assessment and Remediation
Expertise in identifying, classifying, and remediating security vulnerabilities across application layers. Knowledge of vulnerability severity scoring, risk prioritization, and coordinated disclosure processes.
CI/CD Pipeline Security
Hands-on experience securing build pipelines, managing secrets in CI/CD systems, scanning dependencies for vulnerabilities, and implementing secure artifact management.
Penetration Testing and Offensive Security
Practical skills in penetration testing, security assessments, exploitation techniques, and adversarial thinking. Ability to identify vulnerabilities before malicious actors do.
Threat Modeling
Ability to conduct threat modeling sessions, identify attack surfaces, and design security controls. Experience with threat modeling methodologies like STRIDE or PASTA.
Incident Response and Forensics
Experience with security incident investigation, log analysis, forensic analysis, and root cause analysis. Ability to coordinate incident response and implement lessons learned.
API Security
Deep understanding of REST API security, authentication/authorization mechanisms, rate limiting, API gateway security, and protection against common API attacks.
Container and Infrastructure Security
Knowledge of container security, Kubernetes security, secrets management, and infrastructure hardening. Experience with containerized application security in production environments.
Preferred
Go Programming Language
Nice to haveFamiliarity with Go language, which LiteLLM may use in certain components, helps with code review and security assessment of polyglot systems.
LLM/AI Security
Nice to havePrior experience with AI/ML security, model governance, or API gateway security in AI infrastructure. Understanding of unique security challenges in AI/LLM deployments.
Open Source Security
Nice to haveExperience maintaining or contributing to open source projects with security considerations. Familiarity with open source security best practices and supply chain security for dependencies.
Cloud Security
Nice to haveSecurity expertise in cloud platforms (AWS, GCP, Azure), cloud-native security, and securing distributed systems. Knowledge of cloud security frameworks and compliance requirements.
Security Compliance and Standards
Nice to haveExperience with security compliance frameworks, SOC 2, ISO 27001, GDPR, or similar standards. Ability to design and implement security controls that meet regulatory requirements.
Security Tooling
Nice to haveHands-on experience with security tools such as SAST/DAST scanners, vulnerability management platforms, SBOM generators, and security monitoring solutions.
GitHub Actions and DevOps
Nice to havePractical experience with GitHub Actions, continuous integration platforms, and DevOps practices to implement and automate security controls in modern development workflows.
Secure Code Review
Nice to haveExpertise in conducting thorough secure code reviews, identifying logic flaws and security anti-patterns, and providing actionable feedback to development teams.
Tech stack
Languages
Frameworks
Databases
Tools
Other
Compensation
Pay and benefits.
Base·USD 200,000 – 230,000
Equity·Stock options
Benefits
Competitive Salary and Equity
Market-competitive compensation package with stock options and equity participation, allowing you to share in LiteLLM's growth as a high-impact AI infrastructure company.
Deep Technical Ownership
Significant autonomy and responsibility for security strategy and implementation. Direct impact on company-wide security posture with minimal bureaucracy in a fast-paced startup environment.
High-Impact Role at Scale
Protect a platform trusted by industry leaders including Adobe, Netflix, and NASA. Your work directly impacts the security of systems serving millions of AI API calls globally.
Cutting-Edge Technology
Work with modern AI/LLM infrastructure, cloud-native technologies, and emerging security challenges in the artificial intelligence space. Opportunity to shape security practices in a rapidly evolving field.
Fast-Paced Learning Environment
Engage with diverse security challenges across application security, supply chain security, and AI infrastructure. Continuous learning opportunities with exposure to emerging threats and security innovations.
Cross-Functional Collaboration
Partner with talented engineering teams to embed security throughout development and deployment. Influence product design and architecture decisions from a security perspective.
Startup Flexibility
Wear multiple hats in a startup environment where your contributions directly influence company success. Build security processes and practices from the ground up with measurable impact.
Full posting
Original listing.
Security Engineer
LiteLLM is the world's most popular AI Gateway, trusted by top companies like Adobe, Netflix, and NASA. Our platform empowers developers with secure, reliable access to LLMs and adjacent services. We're searching for a Security Engineer to proactively protect LiteLLM at both the application and CI/CD levels.
About The Role
You will own LiteLLM’s security posture across application and supply chain domains. Your mandate is to ensure zero critical or high vulnerabilities and to proactively identify and neutralize attack vectors before they become risks. You’ll oversee application-level security, maintain secure CI/CD processes, and focus on offensive security improvements.
Responsibilities
Own all aspects of application-level security and maintain zero critical or high vulnerabilities
Proactively identify, assess, and remediate potential attack vectors across the platform
Protect LiteLLM by actively hunting vulnerabilities and ensuring robust defenses
Oversee CI/CD security and ensure secure release processes with zero supply chain incidents
Collaborate cross-functionally to embed security throughout development and deployment
Continuously improve and adapt security practices to address emerging threats
What We're Looking For
Experience at a startup (Seed to Series D) with a willingness to wear multiple hats
Strong background in security engineering and hands-on offensive or white-hat hacking
Demonstrated experience with application and CI/CD security
Security-related projects showcased on your resume, GitHub, or similar
Passion for proactive, offensive security
Evidence of winning past CTFs
Why Join LiteLLM?
Own the security mandate at a high-impact technical company
Fast-paced environment with deep technical ownership
Competitive salary and benefits
About LiteLLM
LiteLLM is a Python SDK and Proxy Server enabling seamless calls to 100+ LLM APIs in the OpenAI format, trusted by industry leaders worldwide.
Ready to secure LiteLLM’s future? Apply now!
Redirects to LiteLLM's application page.
Other roles
More at LiteLLM.
Staff Engineer
Staff
Senior Support Engineer - India
Senior
Senior Support Engineer - Brazil
Senior
Support Engineer
Mid
Rust Engineer
Senior