Senior Security Engineer, AI Incident Response
Security Engineer · Senior · Full Time · Remote
Opens Snowflake's application page
Role
What you'll do.
Lead Snowflake's AI incident response strategy as a Senior Security Engineer, architecting product-integrated security capabilities across Cortex AI, Cortex Agents, and enterprise AI pipelines. You'll design detection and remediation playbooks for LLM-specific threats including prompt injection, agent hijacking, and adversarial attacks while embedding security requirements into AI feature development from design through deployment. This role requires 5+ years of information security experience with deep expertise in AI/ML threat modeling, cloud-native security, and incident command leadership to protect thousands of enterprises relying on Snowflake's advanced AI capabilities.
Responsibilities
- Lead AI Security Incident Response Operations: Command and lead incident response for product-level security events with specialized focus on AI-specific threat vectors including prompt injection attacks, model abuse scenarios, agent hijacking attempts, and data exfiltration through AI workloads. Serve as primary incident commander for security incidents affecting Snowflake's AI product surface.
- Integrate Security Into AI Product Pipelines: Work directly with Cortex AI, Cortex Agents, and Snowflake Intelligence teams to embed security requirements and incident response capabilities from design phase through production deployment. Ensure AI feature pipelines incorporate security checkpoints and threat detection mechanisms.
- Develop AI Abuse Response Strategy and Playbooks: Define, codify, and maintain comprehensive incident response playbooks for LLM misuse, adversarial inputs, and AI-assisted attacks. Create detection methodologies, containment procedures, and remediation workflows tailored to agentic and AI-native architectures.
- Address Security Tech Debt in AI Stack: Identify and remediate incident response readiness gaps across Cortex and agentic architectures. Ensure new AI product components meet IR requirements from inception, reducing security debt and operational friction.
- Secure Modern AI-Native Infrastructure: Architect security controls for container-based inference services, RAG pipelines, vector stores, and agent orchestration layers operating across multi-cloud environments. Design response capabilities for AI operational infrastructure including model serving endpoints, Cortex Search indexes, and Snowpark ML pipelines.
- Build Automation and Detection Tooling: Lead development of data-driven automation tools and security instrumentation that accelerates detection and response capabilities for product security incidents at Snowflake scale. Create frameworks for continuous monitoring of AI attack surfaces.
- Provide Cross-Functional Security Leadership: Represent incident response team to cloud engineering, AI platform teams, corporate security, and business units. Translate security risks into actionable guidance for product teams while maintaining empathy for developer experience and secure-by-default practices.
- Architect Secure AI Capabilities: Partner with AI and security engineering teams to provide expert guidance on secure architecture patterns for high-impact, customer-facing AI features. Conduct threat modeling exercises and security assessments for emerging AI capabilities.
- Drive Customer Trust and Data Protection: Ensure meaningful security outcomes for enterprises trusting Snowflake with sensitive data and AI workloads. Build incident response processes that maintain customer confidence in Snowflake's security posture and AI platform reliability.
Qualifications
What we look for.
Technical
AI/ML Security Threat Modeling
Demonstrated expertise in threat modeling and security testing across AI attack surfaces including prompt injection, indirect injection attacks, model inversion, embedding extraction, and supply chain attacks on AI dependencies. Deep understanding of LLM-specific vulnerabilities and exploitation techniques.
Incident Response and Forensics
Proven track record serving as incident commander for product-focused security incidents. Strong capabilities in incident investigation, containment, and post-incident analysis with data-driven decision making.
Cloud-Native Security Architecture
Working knowledge of cloud-native threat landscapes across AWS, Azure, and GCP. Understanding of SaaS platform security architecture, container security, Kubernetes orchestration, and multi-cloud incident response coordination.
SQL and Programming Automation
SQL proficiency for data analysis and forensics. Experience building security automation and tooling with common programming languages, particularly Python, for developing detection logic and response workflows.
AI Infrastructure and Data Governance
Familiarity with unique data governance and security challenges introduced by LLMs, RAG architectures, agentic systems, vector databases, and embedding pipelines. Understanding of model serving, inference security, and AI-specific data protection requirements.
Education
Bachelor's Degree in Computer Science or Related Field
Bachelor's degree in Computer Science, Information Security, Cybersecurity, or closely related discipline. Equivalent professional experience in security roles may substitute for formal degree requirement.
Experience
5+ Years Information Security Experience
Minimum 5+ years working in information security roles, primarily focused on incident response, security engineering, or product/application security. Direct experience leading security initiatives and contributing to incident response program maturity.
AI/ML Security Program Leadership
Experience leading or actively building an application or security engineering program with documented expertise in securing AI and ML systems. Demonstrated ability to influence product teams on security best practices for AI workloads.
Product Security Incident Command
Direct experience serving as incident commander or lead responder for security incidents impacting customer-facing products. Track record of managing high-severity incidents and coordinating response across technical teams.
Skills
Required
Incident Response Leadership
Experience commanding incident response operations, triaging severity, coordinating cross-functional teams, and making critical decisions under pressure with incomplete information.
LLM and AI Security
Deep expertise in Large Language Model security, prompt engineering attack vectors, and emerging AI-specific threat tactics including jailbreaking, model extraction, and adversarial machine learning techniques.
Threat Modeling and Risk Assessment
Strong capabilities in systematic threat identification, attack surface analysis, and risk prioritization for complex AI and cloud-native systems.
Security Architecture and Design
Experience designing security controls and incident response capabilities into cloud-native and AI-native systems. Ability to translate security requirements into implementable technical solutions.
Python for Security Automation
Proficiency in Python programming to develop security tools, automation scripts, detection logic, and instrumentation for incident response workflows.
Cloud Security and Multi-Cloud Environments
Practical experience with AWS, Azure, and/or GCP security architectures, threat landscapes, and incident response procedures specific to cloud-based platforms.
Security Communication and Stakeholder Management
Strong ability to translate complex security concepts and risk assessments into actionable guidance for product engineering teams, executives, and business stakeholders.
Preferred
AI Infrastructure Security
Nice to haveHands-on experience securing AI and ML infrastructure including model serving platforms, vector databases, embedding pipelines, API gateways, and LLM-integrated application architectures.
Agentic Systems and Orchestration
Nice to haveExperience with agentic incident response capabilities, including autonomous agents, skill development, and orchestration pipeline security. Understanding of agent-based systems threat models.
Adversarial ML and Emerging AI Threats
Nice to haveCurrent knowledge of attacker tactics, techniques, and procedures (TTPs) including emerging AI-specific methods such as adversarial machine learning, agent manipulation, and enterprise-focused LLM jailbreaking.
CI/CD and Secure Release Pipeline
Nice to haveFamiliarity with continuous integration/continuous deployment practices and secure software development lifecycle patterns, with emphasis on integrating security checkpoints into AI feature pipelines.
Security Certifications
Nice to haveRelevant security certifications such as GCIA (Certified Incident Handler), GCIH (Incident Handler), GCSA (Certified Security Architect), GDAT (Defensive Architecture), CISSP (Certified Information Systems Security Professional), or cloud certifications from AWS, Azure, or GCP.
Snowflake Platform Knowledge
Nice to havePrior experience working with Snowflake's data platform, understanding of Cortex AI capabilities, Snowpark ML, or similar enterprise data and AI platforms.
Tech stack
Languages
Frameworks
Databases
Tools
Other
Compensation
Pay and benefits.
Base·USD 176,000 – 253,000
Equity·Stock options
Benefits
Comprehensive Health and Wellness Coverage
Medical, dental, and vision insurance with employee and dependent coverage. Mental health resources, wellness programs, and fitness benefits supporting work-life balance.
Competitive Retirement Plans
401(k) matching program and investment options. Financial planning resources and retirement advisory services for long-term wealth building.
Equity Compensation and Stock Options
Substantial stock option grants reflecting your role's strategic importance. Participation in Snowflake's growth as a leading cloud data platform company.
Generous Time Off and Flexible Work Arrangements
Unlimited paid time off, flexible work hours, and remote work options. Support for work-life integration and personal development time.
Professional Development and Learning
Annual learning and development budget for security certifications (GCIA, GCIH, CISSP), conference attendance, and training programs. Internal mentorship and knowledge-sharing opportunities.
Career Growth and Leadership Opportunities
Clear advancement paths within security organization. Opportunity to lead security initiatives, mentor junior engineers, and shape Snowflake's security strategy.
Parental Leave and Family Support
Comprehensive parental leave policies supporting new parents. Adoption assistance and family planning benefits.
Relocation Assistance
Support for employees relocating to role location. Flexible arrangement options for candidates from diverse geographical backgrounds.
Full posting
Original listing.
At Snowflake, we are powering the era of the agentic enterprise. To usher in this new era, we seek AI-native thinkers across every function who are energized by the opportunity to reinvent how they work. You don’t just use tools; you possess an innate curiosity, treating AI as a high-trust collaborator that is core to how you solve problems and accelerate your impact. We look for low-ego individuals who thrive in dynamic and fast-moving environments and move with an experimental mindset — who rapidly test emerging capabilities to discover simpler, more powerful ways to deliver results. At Snowflake, your role isn't just to execute a function, but to help redefine the future of how work gets done.
We are hiring a Senior Security Engineer, dedicated to Product Security Incident Response. In this role, you will lead and architect Snowflake's product-integrated Incident Response strategy, with a primary focus on AI and LLM security. You'll design, plan, and drive the implementation of incident response capabilities across Snowflake's AI product surface - including Cortex AI, Cortex Agents, Snowflake Intelligence, and the data pipelines that power them.
AS A SENIOR SECURITY ENGINEER, AI INCIDENT RESPONSE AT SNOWFLAKE, YOU WILL:
Lead incident response for product-level security events, with deep focus on AI-specific threat vectors including prompt injection, model abuse, agent hijacking, and data exfiltration through AI workloads.
Integrate IR into AI product pipelines - work directly with teams shipping Cortex features, Snowflake Intelligence, and AI-powered developer experiences to embed security requirements from design through deployment.
Develop and codify our AI abuse response strategy - defining detection, containment, and remediation playbooks for LLM misuse, adversarial inputs, and AI-assisted attacks targeting Snowflake customers.
Address tech debt across the AI product stack, ensuring that new Cortex and agentic architectures meet IR readiness requirements from the ground up.
Represent the IR team to cloud engineering, AI platform teams, corporate security, and customer-facing business units.
Secure modern AI-native codebases operating across multi-cloud environments - including container-based inference services, RAG pipelines, vector stores, and agent orchestration layers.
Partner with world-class AI and security engineering teams, providing expert guidance on secure architecture for high-impact AI features and customer-facing AI capabilities.
Design and manage response capabilities built into Snowflake's AI operational infrastructure - from model serving endpoints to Cortex Search indexes and Snowpark ML pipelines.
Lead with data, code, and automation - build tooling that accelerates detection and response for product security incidents at Snowflake scale.
Drive meaningful security outcomes for the customers and enterprises trusting Snowflake with their most sensitive data and AI workloads.
OUR IDEAL SENIOR SECURITY ENGINEER WILL HAVE:
5+ years of experience in information security, primarily in incident response, security engineering, or product/application security (preferred).
Direct experience serving as incident commander for product focused security incidents.
Experience leading or actively building an application or security engineering program, with a clear point of view on securing AI/ML systems.
Experience with threat modeling and security testing across AI attack surfaces, including prompt injection, indirect injection, model inversion, embedding extraction, and supply chain attacks on AI dependencies.
Familiarity with the unique data governance and security challenges introduced by LLMs, RAG architectures, and agentic systems.
Working knowledge of cloud-native environments (AWS, Azure, GCP) and the threat landscape specific to SaaS and AI platforms.
SQL proficiency, plus experience building automation and tools with common programming languages (Python preferred).
Strong communication skills, with the ability to translate security risk into actionable guidance for product teams.
Empathy for developer experience, helping AI engineers ship securely rather than slowing them down.
Bachelor's degree in Computer Science or a related field, or equivalent experience.
BONUS POINTS FOR THE FOLLOWING:
Experience securing AI/ML infrastructure, including model serving, vector databases, embedding pipelines, API gateways, and LLM-integrated application architectures.
Experience building agentic incident response capabilities, including skills, agents, and pipelines.
Understanding of current attacker TTPs, including emerging AI-specific techniques such as adversarial ML, agent manipulation, and LLM jailbreaking in enterprise contexts.
Familiarity with CI/CD and secure release lifecycle patterns, with an emphasis on building security into AI feature pipelines.
Preferred certifications: GCIA, GCIH, GCSA, GDAT, CISSP/GISP, or cloud certifications (AWS, Azure, GCP).
WHY JOIN OUR SECURITY INCIDENT RESPONSE TEAM AT SNOWFLAKE?
This is a chance to do incident response at the frontier of AI security, on products that thousands of enterprises rely on. You will work alongside strong AI and security engineering teams, shape how Snowflake responds to novel LLM and agentic threats, and build the tooling and playbooks that define response for AI-native systems. The work is high-impact and highly visible, with direct influence on the trust customers place in Snowflake's AI capabilities.
Snowflake is growing fast, and we’re scaling our team to help enable and accelerate our growth. We are looking for people who share our values, challenge ordinary thinking, and push the pace of innovation while building a future for themselves and Snowflake.
How do you want to make your impact?
For jobs located in the United States, please visit the job posting on the Snowflake Careers Site for salary and benefits information: careers.snowflake.com
Redirects to Snowflake's application page.
Other roles
More at Snowflake.
Software Engineer AI Team
Mid
Staff/Principal AI Software Engineer - Snowflake CoWork
Principal
Sr Manager, Applied Field Engineering - AI/ML
Manager
Principal Data Platform Architect
Principal
Senior Software Engineer - NatSec
Senior