Security Engineer

Mid · Full Time

San FranciscoUSD 200k – 230k4d ago
Apply for this role

Opens LiteLLM's application page

Role

What you'll do.

Security Engineer at LiteLLM, the world's most popular AI Gateway trusted by companies like Adobe, Netflix, and NASA. You'll own the security posture across application and CI/CD levels, proactively identifying and neutralizing vulnerabilities while ensuring zero critical security incidents. This role requires hands-on security engineering expertise, offensive security skills, and proven experience with application security and supply chain protection in a fast-paced, high-impact technical environment.

Responsibilities

  • Application Security Ownership: Own all aspects of LiteLLM's application-level security posture with accountability for maintaining zero critical or high-severity vulnerabilities. Conduct regular security assessments, implement secure coding practices, and ensure all application components meet enterprise-grade security standards.
  • Vulnerability Identification and Remediation: Proactively identify, assess, and remediate potential attack vectors across the platform through code reviews, penetration testing, and security audits. Actively hunt for vulnerabilities using offensive security techniques and white-hat hacking methodologies to stay ahead of emerging threats.
  • CI/CD Security and Supply Chain Protection: Oversee CI/CD pipeline security and ensure secure release processes with zero supply chain incidents. Implement secure infrastructure practices, manage dependency vulnerabilities, secure container registries, and enforce authentication and authorization controls throughout the deployment pipeline.
  • Cross-Functional Security Collaboration: Collaborate with engineering, infrastructure, and product teams to embed security throughout the software development lifecycle and deployment processes. Provide security guidance, conduct threat modeling sessions, and mentor developers on secure coding practices.
  • Security Posture Enhancement: Continuously improve and adapt security practices to address emerging threats in the AI/LLM space and broader technology landscape. Research new attack vectors, evaluate security tools and technologies, and implement offensive security improvements to strengthen defenses.
  • Incident Response and Threat Analysis: Lead incident response efforts for security incidents, conduct root cause analysis, and implement preventive measures. Monitor security logs and alerts, investigate suspicious activities, and maintain documentation of security events and remediation actions.

Qualifications

What we look for.

Technical

  • Application Security Engineering

    Deep expertise in identifying and remediating application-level vulnerabilities including OWASP Top 10, API security, authentication/authorization flaws, and injection attacks. Experience with secure code review techniques and static/dynamic security analysis tools.

  • CI/CD Security and DevSecOps

    Hands-on experience securing continuous integration and deployment pipelines. Knowledge of container security (Docker/Kubernetes), secrets management, supply chain security, Software Bill of Materials (SBOM), and secure build practices.

  • Offensive Security and Penetration Testing

    Proven background in offensive security, white-hat hacking, or penetration testing. Experience with security testing tools, vulnerability scanning, and exploitation techniques to identify and validate security weaknesses.

  • Python and Backend Security

    Strong proficiency in Python for security automation, scripting, and analysis. Understanding of backend/server security principles, API security, and secure integration patterns relevant to LiteLLM's Python SDK architecture.

  • Security Tools and Practices

    Proficiency with security scanning tools, SAST/DAST solutions, vulnerability management platforms, and monitoring systems. Experience with security frameworks, compliance standards, and threat modeling methodologies.

Education

  • Computer Science or Cybersecurity Foundation

    Bachelor's degree in Computer Science, Cybersecurity, Information Security, or related technical field, or equivalent hands-on security experience and demonstrable expertise through certifications or published work.

  • Security Certifications (Preferred)

    Relevant security certifications such as OSCP, GPEN, CEH, or similar demonstrate commitment to professional security engineering. Advanced certifications indicate specialized expertise in offensive security or application security domains.

Experience

  • Startup Security Leadership

    Proven experience building security programs at early-stage startups (Seed through Series D). Demonstrated ability to work independently, prioritize security initiatives with limited resources, and wear multiple hats in fast-paced environments.

  • Security Engineering Track Record

    3+ years of hands-on security engineering experience with demonstrated impact on application security and infrastructure hardening. Portfolio of security-related projects showcased on GitHub, personal blog, or similar platforms.

  • Capture The Flag (CTF) Participation

    Evidence of competitive security skills through Capture The Flag competition wins or strong performance. CTF experience demonstrates practical vulnerability identification, exploitation, and problem-solving abilities.

  • API and LLM Security Familiarity

    Experience with API security best practices and ideally exposure to AI/LLM infrastructure security challenges. Understanding of model API gateway architecture and associated security considerations.

Skills

Required

  • Python Security Automation

    Ability to write Python scripts for security automation, vulnerability analysis, and integration with security tools. Critical for developing custom security solutions within LiteLLM's Python-based platform.

  • Vulnerability Assessment and Remediation

    Expertise in identifying, classifying, and remediating security vulnerabilities across application layers. Knowledge of vulnerability severity scoring, risk prioritization, and coordinated disclosure processes.

  • CI/CD Pipeline Security

    Hands-on experience securing build pipelines, managing secrets in CI/CD systems, scanning dependencies for vulnerabilities, and implementing secure artifact management.

  • Penetration Testing and Offensive Security

    Practical skills in penetration testing, security assessments, exploitation techniques, and adversarial thinking. Ability to identify vulnerabilities before malicious actors do.

  • Threat Modeling

    Ability to conduct threat modeling sessions, identify attack surfaces, and design security controls. Experience with threat modeling methodologies like STRIDE or PASTA.

  • Incident Response and Forensics

    Experience with security incident investigation, log analysis, forensic analysis, and root cause analysis. Ability to coordinate incident response and implement lessons learned.

  • API Security

    Deep understanding of REST API security, authentication/authorization mechanisms, rate limiting, API gateway security, and protection against common API attacks.

  • Container and Infrastructure Security

    Knowledge of container security, Kubernetes security, secrets management, and infrastructure hardening. Experience with containerized application security in production environments.

Preferred

  • Go Programming Language

    Nice to have

    Familiarity with Go language, which LiteLLM may use in certain components, helps with code review and security assessment of polyglot systems.

  • LLM/AI Security

    Nice to have

    Prior experience with AI/ML security, model governance, or API gateway security in AI infrastructure. Understanding of unique security challenges in AI/LLM deployments.

  • Open Source Security

    Nice to have

    Experience maintaining or contributing to open source projects with security considerations. Familiarity with open source security best practices and supply chain security for dependencies.

  • Cloud Security

    Nice to have

    Security expertise in cloud platforms (AWS, GCP, Azure), cloud-native security, and securing distributed systems. Knowledge of cloud security frameworks and compliance requirements.

  • Security Compliance and Standards

    Nice to have

    Experience with security compliance frameworks, SOC 2, ISO 27001, GDPR, or similar standards. Ability to design and implement security controls that meet regulatory requirements.

  • Security Tooling

    Nice to have

    Hands-on experience with security tools such as SAST/DAST scanners, vulnerability management platforms, SBOM generators, and security monitoring solutions.

  • GitHub Actions and DevOps

    Nice to have

    Practical experience with GitHub Actions, continuous integration platforms, and DevOps practices to implement and automate security controls in modern development workflows.

  • Secure Code Review

    Nice to have

    Expertise in conducting thorough secure code reviews, identifying logic flaws and security anti-patterns, and providing actionable feedback to development teams.

Tech stack

Languages

PythonGoJavaScript/TypeScriptBash/Shell Scripting

Frameworks

FastAPIFlaskOpenAI Python SDK

Databases

PostgreSQLRedis

Tools

GitHub ActionsDockerKubernetesOWASP ZAPBanditSonarQubeDependabot

Other

Vulnerability ManagementSecrets ManagementThreat ModelingSecurity Monitoring and SIEMAPI Security Testing

Compensation

Pay and benefits.

Base·USD 200,000 – 230,000

Equity·Stock options

Benefits

  • Competitive Salary and Equity

    Market-competitive compensation package with stock options and equity participation, allowing you to share in LiteLLM's growth as a high-impact AI infrastructure company.

  • Deep Technical Ownership

    Significant autonomy and responsibility for security strategy and implementation. Direct impact on company-wide security posture with minimal bureaucracy in a fast-paced startup environment.

  • High-Impact Role at Scale

    Protect a platform trusted by industry leaders including Adobe, Netflix, and NASA. Your work directly impacts the security of systems serving millions of AI API calls globally.

  • Cutting-Edge Technology

    Work with modern AI/LLM infrastructure, cloud-native technologies, and emerging security challenges in the artificial intelligence space. Opportunity to shape security practices in a rapidly evolving field.

  • Fast-Paced Learning Environment

    Engage with diverse security challenges across application security, supply chain security, and AI infrastructure. Continuous learning opportunities with exposure to emerging threats and security innovations.

  • Cross-Functional Collaboration

    Partner with talented engineering teams to embed security throughout development and deployment. Influence product design and architecture decisions from a security perspective.

  • Startup Flexibility

    Wear multiple hats in a startup environment where your contributions directly influence company success. Build security processes and practices from the ground up with measurable impact.

Full posting

Original listing.

Security Engineer

LiteLLM is the world's most popular AI Gateway, trusted by top companies like Adobe, Netflix, and NASA. Our platform empowers developers with secure, reliable access to LLMs and adjacent services. We're searching for a Security Engineer to proactively protect LiteLLM at both the application and CI/CD levels.

About The Role

You will own LiteLLM’s security posture across application and supply chain domains. Your mandate is to ensure zero critical or high vulnerabilities and to proactively identify and neutralize attack vectors before they become risks. You’ll oversee application-level security, maintain secure CI/CD processes, and focus on offensive security improvements.

Responsibilities

  • Own all aspects of application-level security and maintain zero critical or high vulnerabilities

  • Proactively identify, assess, and remediate potential attack vectors across the platform

  • Protect LiteLLM by actively hunting vulnerabilities and ensuring robust defenses

  • Oversee CI/CD security and ensure secure release processes with zero supply chain incidents

  • Collaborate cross-functionally to embed security throughout development and deployment

  • Continuously improve and adapt security practices to address emerging threats

What We're Looking For

  • Experience at a startup (Seed to Series D) with a willingness to wear multiple hats

  • Strong background in security engineering and hands-on offensive or white-hat hacking

  • Demonstrated experience with application and CI/CD security

  • Security-related projects showcased on your resume, GitHub, or similar

  • Passion for proactive, offensive security

  • Evidence of winning past CTFs

Why Join LiteLLM?

  • Own the security mandate at a high-impact technical company

  • Fast-paced environment with deep technical ownership

  • Competitive salary and benefits

About LiteLLM

LiteLLM is a Python SDK and Proxy Server enabling seamless calls to 100+ LLM APIs in the OpenAI format, trusted by industry leaders worldwide.

Ready to secure LiteLLM’s future? Apply now!

Redirects to LiteLLM's application page.

Other roles

More at LiteLLM.

View all 7 roles