Senior Security Engineer, AI Incident Response
Security Engineer · Senior · Full Time
Opens Snowflake's application page
Role
What you'll do.
Senior Security Engineer leading AI-focused incident response strategy at Snowflake, architecting product-integrated security capabilities for LLM and agentic systems. This role combines deep incident command experience with AI security expertise to design detection, containment, and remediation playbooks for emerging threats like prompt injection and agent hijacking. Requires 5+ years in security with demonstrable incident response leadership and technical capability in threat modeling AI systems across cloud-native environments.
Responsibilities
- Lead AI Security Incident Response: Command and coordinate product-level security incidents with deep specialization in AI-specific threat vectors including prompt injection, model abuse, agent hijacking, model inversion, and data exfiltration through AI workloads. Drive detection, investigation, containment, and remediation for LLM and agentic system compromises across Snowflake's customer base.
- Integrate Security into AI Product Development: Embed incident response requirements directly into AI product pipelines including Cortex AI, Cortex Agents, Snowflake Intelligence, and associated data pipelines. Work cross-functionally with product engineering teams shipping Cortex features and AI-powered developer experiences to ensure security-by-design from initial architecture through production deployment.
- Develop AI Abuse Response Strategy: Codify comprehensive playbooks for detecting, containing, and remediating LLM misuse, adversarial inputs, supply chain attacks on AI dependencies, and AI-assisted attacks targeting Snowflake customers. Establish metrics, escalation procedures, and stakeholder communication protocols for AI-specific security events.
- Address Technical Debt in AI Infrastructure: Systematically remediate security gaps across the AI product stack, ensuring new Cortex and agentic architectures meet incident response readiness requirements from inception. Prioritize and resolve vulnerabilities in model serving endpoints, RAG pipelines, vector stores, and agent orchestration layers.
- Secure Modern AI-Native Architectures: Apply security expertise to container-based inference services, retrieval-augmented generation pipelines, vector database integrations, and agent orchestration frameworks operating across multi-cloud environments. Evaluate and mitigate threats specific to LLM-integrated application architectures and embedded inference systems.
- Build Detection and Response Automation: Design, develop, and deploy tooling that accelerates detection and response for product security incidents at enterprise scale. Create monitoring, alerting, and automated remediation capabilities integrated into Snowflake's AI operational infrastructure and incident response workflows.
- Cross-Functional Security Advocacy: Represent the incident response team to cloud engineering, AI platform teams, corporate security, and customer-facing business units. Provide expert guidance on secure architecture patterns for high-impact AI features and translate security requirements into actionable developer guidance that doesn't impede shipping velocity.
- Establish IR Readiness Standards: Define and enforce incident response readiness requirements for AI product launches. Design response capabilities built into operational infrastructure including monitoring, logging, forensic data collection, and recovery procedures tailored to Cortex Search indexes and Snowpark ML pipeline architectures.
- Lead Data-Driven Security Operations: Establish metrics-driven incident response program leveraging automation and evidence-based decision making. Build dashboards and reporting that demonstrates security outcomes for customers and enterprises trusting Snowflake with sensitive data and AI workloads.
Qualifications
What we look for.
Technical
AI/LLM Security Expertise
Demonstrated experience identifying and mitigating AI-specific security threats including prompt injection, indirect prompt injection, model inversion attacks, embedding extraction, adversarial ML techniques, agent manipulation, and LLM jailbreaking. Understanding of how these threats manifest in enterprise AI deployments and customer-facing AI capabilities.
Incident Command and Response Leadership
Proven track record serving as incident commander for product-focused security incidents. Experience leading cross-functional response teams, making rapid triage decisions under pressure, and managing escalation protocols for high-severity events impacting production systems and customers.
Threat Modeling and Security Architecture
Advanced capability in threat modeling AI attack surfaces, security architecture review, and application security assessment. Experience designing security controls and detection mechanisms for novel system architectures including vector databases, RAG systems, and multi-agent frameworks.
Cloud-Native Security
Deep working knowledge of cloud-native threat landscapes across AWS, Azure, and GCP. Experience securing containerized inference services, serverless AI workloads, managed Kubernetes environments, and SaaS platform-specific security concerns including multi-tenancy isolation and data governance.
Programming and Automation
Strong programming capability, particularly in Python, to build security automation, incident response tools, and monitoring solutions. SQL proficiency for querying security logs, performing forensic analysis, and automating detection logic. Experience with Infrastructure as Code and CI/CD security integration patterns.
Application and Product Security Engineering
Experience building or leading application security programs with emphasis on shifting security left into development workflows. Understanding of secure software development lifecycle (SSDLC), secure coding practices, and security testing methodologies tailored to AI/ML systems.
Data Governance for LLM Systems
Familiarity with unique data governance, privacy, and security challenges introduced by large language models, retrieval-augmented generation architectures, and agentic systems. Understanding of RAG pipeline vulnerabilities, vector store security, embedding privacy concerns, and data lineage tracking for AI workloads.
Modern Enterprise Security Tools
Working knowledge of SIEM platforms, EDR/XDR solutions, cloud security posture management tools, and API security gateways. Experience with incident response platforms, threat intelligence integration, and forensic analysis tools used in enterprise security operations.
Education
Bachelor's Degree in Computer Science or Related Field
Bachelor's degree in Computer Science, Information Security, Cybersecurity, Engineering, or equivalent technical discipline required. Equivalent professional security experience may substitute for formal degree requirement.
Security Certifications (Preferred)
Professional security certifications preferred including GCIA (GIAC Certified Incident Handler), GCIH (GIAC Certified Incident Handler), GCSA (GIAC Certified Security Architect), GDAT (GIAC Certified Data Analyst), CISSP (Certified Information Systems Security Professional), or cloud provider certifications (AWS Security Specialty, Azure Security Engineer, GCP Professional Cloud Security Engineer).
Experience
5+ Years Information Security Experience
Minimum five years of professional information security experience with primary focus on incident response, security engineering, or product/application security. Background should demonstrate progression from individual contributor through technical leadership roles.
Incident Response Program Development
Experience actively building or leading incident response and/or application security programs. Demonstrated ability to establish response procedures, build security engineering practices, and drive organizational maturity in security operations.
AI/ML Security Program Building
Documented experience securing AI and machine learning systems with clear point of view on architectural patterns, threat modeling approaches, and security controls for AI platforms. Experience evaluating or securing systems using large language models, vector databases, or agentic frameworks.
Security Testing and Vulnerability Assessment
Hands-on experience conducting threat modeling, security assessments, and red team exercises targeting complex system architectures. Background in identifying and validating AI-specific attack vectors through testing and research.
Large-Scale SaaS and Enterprise Platform Security
Background securing high-scale, multi-tenant SaaS or enterprise data platforms. Experience understanding customer security requirements, compliance obligations, and the operational complexity of incident response in customer-impacting scenarios.
Skills
Required
Incident Response Leadership
Incident command, triage, coordination, escalation management, and post-incident review facilitation for product security events
AI/LLM Security
Understanding of LLM attack vectors, RAG security, prompt injection, model abuse, agent hijacking, and emerging AI-specific threat landscape
Security Architecture and Threat Modeling
Ability to design security controls, conduct architecture reviews, and identify threats in complex AI system designs
Python Programming
Proficiency building security automation, detection tools, and monitoring solutions
SQL and Data Analysis
Querying security logs, forensic analysis, and building detection logic
Cloud Platform Security
Security experience across AWS, Azure, and/or GCP with understanding of cloud-native threat models
Technical Communication
Translating complex security concepts into actionable guidance for engineering teams without impeding development velocity
Preferred
AI/ML Infrastructure Security
Nice to haveExperience securing model serving platforms, vector databases, embedding pipelines, API gateways, and LLM-integrated application architectures
Agentic System Security
Nice to haveExperience with multi-agent frameworks, agent orchestration security, and building agentic incident response capabilities
Adversarial ML and AI Attacks
Nice to haveUnderstanding of adversarial machine learning techniques, jailbreaking methods, and emerging attacker tactics targeting AI systems
CI/CD and Secure Release Engineering
Nice to haveExperience integrating security into continuous integration and deployment pipelines with emphasis on AI feature pipeline security
Vector Database and RAG Security
Nice to haveHands-on experience evaluating and securing vector store technologies, RAG pipeline architectures, and retrieval-augmented generation security concerns
Security Certifications
Nice to haveGCIA, GCIH, GCSA, GDAT, CISSP/GISP, AWS Security Specialty, Azure Security Engineer, or GCP Professional Cloud Security Engineer certifications
Offensive Security Background
Nice to haveRed team, penetration testing, or security research experience evaluating AI system security posture
Developer Empathy
Nice to haveDemonstrated commitment to developer experience and enabling secure-by-default practices without introducing friction in software development workflows
Compensation
Pay and benefits.
Base·USD 176,000 – 253,000
Equity·Stock options
Benefits
Competitive Health and Wellness Benefits
Comprehensive medical, dental, and vision coverage with options for employees and dependents. Mental health support, wellness programs, and fitness benefits to support overall health.
Retirement and Financial Planning
Competitive 401(k) plan with company match. Financial wellness resources and planning assistance for long-term financial security.
Generous Time Off
Flexible paid time off policy, company holidays, and paid parental leave. Sabbatical opportunities for eligible employees to pursue professional development or personal goals.
Professional Development and Learning
Budget for professional development, conference attendance, and security certifications. Access to training platforms, technical mentorship, and career growth opportunities in emerging AI security domain.
Equity Participation
Competitive stock options as part of comprehensive compensation package, allowing employees to participate in company growth.
Flexible Work Arrangements
Flexibility in work location and schedule. Snowflake supports remote work options and flexible arrangements to enable work-life balance.
Innovation and Impact Opportunity
High-visibility role shaping security strategy for AI systems trusted by thousands of enterprises. Direct influence on how Snowflake responds to novel AI threats and direct impact on customer trust and security outcomes.
Collaborative Security Culture
Opportunity to work alongside world-class AI and security engineering teams. Access to cutting-edge AI infrastructure and emerging security research at the frontier of LLM and agentic system security.
Full posting
Original listing.
At Snowflake, we are powering the era of the agentic enterprise. To usher in this new era, we seek AI-native thinkers across every function who are energized by the opportunity to reinvent how they work. You don’t just use tools; you possess an innate curiosity, treating AI as a high-trust collaborator that is core to how you solve problems and accelerate your impact. We look for low-ego individuals who thrive in dynamic and fast-moving environments and move with an experimental mindset — who rapidly test emerging capabilities to discover simpler, more powerful ways to deliver results. At Snowflake, your role isn't just to execute a function, but to help redefine the future of how work gets done.
We are hiring a Senior Security Engineer, dedicated to Product Security Incident Response. In this role, you will lead and architect Snowflake's product-integrated Incident Response strategy, with a primary focus on AI and LLM security. You'll design, plan, and drive the implementation of incident response capabilities across Snowflake's AI product surface - including Cortex AI, Cortex Agents, Snowflake Intelligence, and the data pipelines that power them.
AS A SENIOR SECURITY ENGINEER, AI INCIDENT RESPONSE AT SNOWFLAKE, YOU WILL:
Lead incident response for product-level security events, with deep focus on AI-specific threat vectors including prompt injection, model abuse, agent hijacking, and data exfiltration through AI workloads.
Integrate IR into AI product pipelines - work directly with teams shipping Cortex features, Snowflake Intelligence, and AI-powered developer experiences to embed security requirements from design through deployment.
Develop and codify our AI abuse response strategy - defining detection, containment, and remediation playbooks for LLM misuse, adversarial inputs, and AI-assisted attacks targeting Snowflake customers.
Address tech debt across the AI product stack, ensuring that new Cortex and agentic architectures meet IR readiness requirements from the ground up.
Represent the IR team to cloud engineering, AI platform teams, corporate security, and customer-facing business units.
Secure modern AI-native codebases operating across multi-cloud environments - including container-based inference services, RAG pipelines, vector stores, and agent orchestration layers.
Partner with world-class AI and security engineering teams, providing expert guidance on secure architecture for high-impact AI features and customer-facing AI capabilities.
Design and manage response capabilities built into Snowflake's AI operational infrastructure - from model serving endpoints to Cortex Search indexes and Snowpark ML pipelines.
Lead with data, code, and automation - build tooling that accelerates detection and response for product security incidents at Snowflake scale.
Drive meaningful security outcomes for the customers and enterprises trusting Snowflake with their most sensitive data and AI workloads.
OUR IDEAL SENIOR SECURITY ENGINEER WILL HAVE:
5+ years of experience in information security, primarily in incident response, security engineering, or product/application security (preferred).
Direct experience serving as incident commander for product focused security incidents.
Experience leading or actively building an application or security engineering program, with a clear point of view on securing AI/ML systems.
Experience with threat modeling and security testing across AI attack surfaces, including prompt injection, indirect injection, model inversion, embedding extraction, and supply chain attacks on AI dependencies.
Familiarity with the unique data governance and security challenges introduced by LLMs, RAG architectures, and agentic systems.
Working knowledge of cloud-native environments (AWS, Azure, GCP) and the threat landscape specific to SaaS and AI platforms.
SQL proficiency, plus experience building automation and tools with common programming languages (Python preferred).
Strong communication skills, with the ability to translate security risk into actionable guidance for product teams.
Empathy for developer experience, helping AI engineers ship securely rather than slowing them down.
Bachelor's degree in Computer Science or a related field, or equivalent experience.
BONUS POINTS FOR THE FOLLOWING:
Experience securing AI/ML infrastructure, including model serving, vector databases, embedding pipelines, API gateways, and LLM-integrated application architectures.
Experience building agentic incident response capabilities, including skills, agents, and pipelines.
Understanding of current attacker TTPs, including emerging AI-specific techniques such as adversarial ML, agent manipulation, and LLM jailbreaking in enterprise contexts.
Familiarity with CI/CD and secure release lifecycle patterns, with an emphasis on building security into AI feature pipelines.
Preferred certifications: GCIA, GCIH, GCSA, GDAT, CISSP/GISP, or cloud certifications (AWS, Azure, GCP).
WHY JOIN OUR SECURITY INCIDENT RESPONSE TEAM AT SNOWFLAKE?
This is a chance to do incident response at the frontier of AI security, on products that thousands of enterprises rely on. You will work alongside strong AI and security engineering teams, shape how Snowflake responds to novel LLM and agentic threats, and build the tooling and playbooks that define response for AI-native systems. The work is high-impact and highly visible, with direct influence on the trust customers place in Snowflake's AI capabilities.
Snowflake is growing fast, and we’re scaling our team to help enable and accelerate our growth. We are looking for people who share our values, challenge ordinary thinking, and push the pace of innovation while building a future for themselves and Snowflake.
How do you want to make your impact?
For jobs located in the United States, please visit the job posting on the Snowflake Careers Site for salary and benefits information: careers.snowflake.com
Redirects to Snowflake's application page.
Other roles
More at Snowflake.
Software Engineer AI Team
Mid
Sr Manager, Applied Field Engineering - AI/ML
Manager
Staff/Principal AI Software Engineer - Snowflake CoWork
Principal
Principal Data Platform Architect
Principal
Senior Software Engineer - NatSec
Senior