Senior Security Engineer, AI Incident Response

Security Engineer · Senior · Full Time

US-CA-Menlo ParkUSD 176k – 253k1w ago
Apply for this role

Opens Snowflake's application page

Role

What you'll do.

Senior Security Engineer leading AI-focused incident response strategy at Snowflake, architecting product-integrated security capabilities for LLM and agentic systems. This role combines deep incident command experience with AI security expertise to design detection, containment, and remediation playbooks for emerging threats like prompt injection and agent hijacking. Requires 5+ years in security with demonstrable incident response leadership and technical capability in threat modeling AI systems across cloud-native environments.

Responsibilities

  • Lead AI Security Incident Response: Command and coordinate product-level security incidents with deep specialization in AI-specific threat vectors including prompt injection, model abuse, agent hijacking, model inversion, and data exfiltration through AI workloads. Drive detection, investigation, containment, and remediation for LLM and agentic system compromises across Snowflake's customer base.
  • Integrate Security into AI Product Development: Embed incident response requirements directly into AI product pipelines including Cortex AI, Cortex Agents, Snowflake Intelligence, and associated data pipelines. Work cross-functionally with product engineering teams shipping Cortex features and AI-powered developer experiences to ensure security-by-design from initial architecture through production deployment.
  • Develop AI Abuse Response Strategy: Codify comprehensive playbooks for detecting, containing, and remediating LLM misuse, adversarial inputs, supply chain attacks on AI dependencies, and AI-assisted attacks targeting Snowflake customers. Establish metrics, escalation procedures, and stakeholder communication protocols for AI-specific security events.
  • Address Technical Debt in AI Infrastructure: Systematically remediate security gaps across the AI product stack, ensuring new Cortex and agentic architectures meet incident response readiness requirements from inception. Prioritize and resolve vulnerabilities in model serving endpoints, RAG pipelines, vector stores, and agent orchestration layers.
  • Secure Modern AI-Native Architectures: Apply security expertise to container-based inference services, retrieval-augmented generation pipelines, vector database integrations, and agent orchestration frameworks operating across multi-cloud environments. Evaluate and mitigate threats specific to LLM-integrated application architectures and embedded inference systems.
  • Build Detection and Response Automation: Design, develop, and deploy tooling that accelerates detection and response for product security incidents at enterprise scale. Create monitoring, alerting, and automated remediation capabilities integrated into Snowflake's AI operational infrastructure and incident response workflows.
  • Cross-Functional Security Advocacy: Represent the incident response team to cloud engineering, AI platform teams, corporate security, and customer-facing business units. Provide expert guidance on secure architecture patterns for high-impact AI features and translate security requirements into actionable developer guidance that doesn't impede shipping velocity.
  • Establish IR Readiness Standards: Define and enforce incident response readiness requirements for AI product launches. Design response capabilities built into operational infrastructure including monitoring, logging, forensic data collection, and recovery procedures tailored to Cortex Search indexes and Snowpark ML pipeline architectures.
  • Lead Data-Driven Security Operations: Establish metrics-driven incident response program leveraging automation and evidence-based decision making. Build dashboards and reporting that demonstrates security outcomes for customers and enterprises trusting Snowflake with sensitive data and AI workloads.

Qualifications

What we look for.

Technical

  • AI/LLM Security Expertise

    Demonstrated experience identifying and mitigating AI-specific security threats including prompt injection, indirect prompt injection, model inversion attacks, embedding extraction, adversarial ML techniques, agent manipulation, and LLM jailbreaking. Understanding of how these threats manifest in enterprise AI deployments and customer-facing AI capabilities.

  • Incident Command and Response Leadership

    Proven track record serving as incident commander for product-focused security incidents. Experience leading cross-functional response teams, making rapid triage decisions under pressure, and managing escalation protocols for high-severity events impacting production systems and customers.

  • Threat Modeling and Security Architecture

    Advanced capability in threat modeling AI attack surfaces, security architecture review, and application security assessment. Experience designing security controls and detection mechanisms for novel system architectures including vector databases, RAG systems, and multi-agent frameworks.

  • Cloud-Native Security

    Deep working knowledge of cloud-native threat landscapes across AWS, Azure, and GCP. Experience securing containerized inference services, serverless AI workloads, managed Kubernetes environments, and SaaS platform-specific security concerns including multi-tenancy isolation and data governance.

  • Programming and Automation

    Strong programming capability, particularly in Python, to build security automation, incident response tools, and monitoring solutions. SQL proficiency for querying security logs, performing forensic analysis, and automating detection logic. Experience with Infrastructure as Code and CI/CD security integration patterns.

  • Application and Product Security Engineering

    Experience building or leading application security programs with emphasis on shifting security left into development workflows. Understanding of secure software development lifecycle (SSDLC), secure coding practices, and security testing methodologies tailored to AI/ML systems.

  • Data Governance for LLM Systems

    Familiarity with unique data governance, privacy, and security challenges introduced by large language models, retrieval-augmented generation architectures, and agentic systems. Understanding of RAG pipeline vulnerabilities, vector store security, embedding privacy concerns, and data lineage tracking for AI workloads.

  • Modern Enterprise Security Tools

    Working knowledge of SIEM platforms, EDR/XDR solutions, cloud security posture management tools, and API security gateways. Experience with incident response platforms, threat intelligence integration, and forensic analysis tools used in enterprise security operations.

Education

  • Bachelor's Degree in Computer Science or Related Field

    Bachelor's degree in Computer Science, Information Security, Cybersecurity, Engineering, or equivalent technical discipline required. Equivalent professional security experience may substitute for formal degree requirement.

  • Security Certifications (Preferred)

    Professional security certifications preferred including GCIA (GIAC Certified Incident Handler), GCIH (GIAC Certified Incident Handler), GCSA (GIAC Certified Security Architect), GDAT (GIAC Certified Data Analyst), CISSP (Certified Information Systems Security Professional), or cloud provider certifications (AWS Security Specialty, Azure Security Engineer, GCP Professional Cloud Security Engineer).

Experience

  • 5+ Years Information Security Experience

    Minimum five years of professional information security experience with primary focus on incident response, security engineering, or product/application security. Background should demonstrate progression from individual contributor through technical leadership roles.

  • Incident Response Program Development

    Experience actively building or leading incident response and/or application security programs. Demonstrated ability to establish response procedures, build security engineering practices, and drive organizational maturity in security operations.

  • AI/ML Security Program Building

    Documented experience securing AI and machine learning systems with clear point of view on architectural patterns, threat modeling approaches, and security controls for AI platforms. Experience evaluating or securing systems using large language models, vector databases, or agentic frameworks.

  • Security Testing and Vulnerability Assessment

    Hands-on experience conducting threat modeling, security assessments, and red team exercises targeting complex system architectures. Background in identifying and validating AI-specific attack vectors through testing and research.

  • Large-Scale SaaS and Enterprise Platform Security

    Background securing high-scale, multi-tenant SaaS or enterprise data platforms. Experience understanding customer security requirements, compliance obligations, and the operational complexity of incident response in customer-impacting scenarios.

Skills

Required

  • Incident Response Leadership

    Incident command, triage, coordination, escalation management, and post-incident review facilitation for product security events

  • AI/LLM Security

    Understanding of LLM attack vectors, RAG security, prompt injection, model abuse, agent hijacking, and emerging AI-specific threat landscape

  • Security Architecture and Threat Modeling

    Ability to design security controls, conduct architecture reviews, and identify threats in complex AI system designs

  • Python Programming

    Proficiency building security automation, detection tools, and monitoring solutions

  • SQL and Data Analysis

    Querying security logs, forensic analysis, and building detection logic

  • Cloud Platform Security

    Security experience across AWS, Azure, and/or GCP with understanding of cloud-native threat models

  • Technical Communication

    Translating complex security concepts into actionable guidance for engineering teams without impeding development velocity

Preferred

  • AI/ML Infrastructure Security

    Nice to have

    Experience securing model serving platforms, vector databases, embedding pipelines, API gateways, and LLM-integrated application architectures

  • Agentic System Security

    Nice to have

    Experience with multi-agent frameworks, agent orchestration security, and building agentic incident response capabilities

  • Adversarial ML and AI Attacks

    Nice to have

    Understanding of adversarial machine learning techniques, jailbreaking methods, and emerging attacker tactics targeting AI systems

  • CI/CD and Secure Release Engineering

    Nice to have

    Experience integrating security into continuous integration and deployment pipelines with emphasis on AI feature pipeline security

  • Vector Database and RAG Security

    Nice to have

    Hands-on experience evaluating and securing vector store technologies, RAG pipeline architectures, and retrieval-augmented generation security concerns

  • Security Certifications

    Nice to have

    GCIA, GCIH, GCSA, GDAT, CISSP/GISP, AWS Security Specialty, Azure Security Engineer, or GCP Professional Cloud Security Engineer certifications

  • Offensive Security Background

    Nice to have

    Red team, penetration testing, or security research experience evaluating AI system security posture

  • Developer Empathy

    Nice to have

    Demonstrated commitment to developer experience and enabling secure-by-default practices without introducing friction in software development workflows

Compensation

Pay and benefits.

Base·USD 176,000 – 253,000

Equity·Stock options

Benefits

  • Competitive Health and Wellness Benefits

    Comprehensive medical, dental, and vision coverage with options for employees and dependents. Mental health support, wellness programs, and fitness benefits to support overall health.

  • Retirement and Financial Planning

    Competitive 401(k) plan with company match. Financial wellness resources and planning assistance for long-term financial security.

  • Generous Time Off

    Flexible paid time off policy, company holidays, and paid parental leave. Sabbatical opportunities for eligible employees to pursue professional development or personal goals.

  • Professional Development and Learning

    Budget for professional development, conference attendance, and security certifications. Access to training platforms, technical mentorship, and career growth opportunities in emerging AI security domain.

  • Equity Participation

    Competitive stock options as part of comprehensive compensation package, allowing employees to participate in company growth.

  • Flexible Work Arrangements

    Flexibility in work location and schedule. Snowflake supports remote work options and flexible arrangements to enable work-life balance.

  • Innovation and Impact Opportunity

    High-visibility role shaping security strategy for AI systems trusted by thousands of enterprises. Direct influence on how Snowflake responds to novel AI threats and direct impact on customer trust and security outcomes.

  • Collaborative Security Culture

    Opportunity to work alongside world-class AI and security engineering teams. Access to cutting-edge AI infrastructure and emerging security research at the frontier of LLM and agentic system security.

Full posting

Original listing.

At Snowflake, we are powering the era of the agentic enterprise. To usher in this new era, we seek AI-native thinkers across every function who are energized by the opportunity to reinvent how they work. You don’t just use tools; you possess an innate curiosity, treating AI as a high-trust collaborator that is core to how you solve problems and accelerate your impact. We look for low-ego individuals who thrive in dynamic and fast-moving environments and move with an experimental mindset — who rapidly test emerging capabilities to discover simpler, more powerful ways to deliver results. At Snowflake, your role isn't just to execute a function, but to help redefine the future of how work gets done.

We are hiring a Senior Security Engineer, dedicated to Product Security Incident Response. In this role, you will lead and architect Snowflake's product-integrated Incident Response strategy, with a primary focus on AI and LLM security. You'll design, plan, and drive the implementation of incident response capabilities across Snowflake's AI product surface - including Cortex AI, Cortex Agents, Snowflake Intelligence, and the data pipelines that power them.

AS A SENIOR SECURITY ENGINEER, AI INCIDENT RESPONSE AT SNOWFLAKE, YOU WILL:

  • Lead incident response for product-level security events, with deep focus on AI-specific threat vectors including prompt injection, model abuse, agent hijacking, and data exfiltration through AI workloads.

  • Integrate IR into AI product pipelines - work directly with teams shipping Cortex features, Snowflake Intelligence, and AI-powered developer experiences to embed security requirements from design through deployment.

  • Develop and codify our AI abuse response strategy - defining detection, containment, and remediation playbooks for LLM misuse, adversarial inputs, and AI-assisted attacks targeting Snowflake customers.

  • Address tech debt across the AI product stack, ensuring that new Cortex and agentic architectures meet IR readiness requirements from the ground up.

  • Represent the IR team to cloud engineering, AI platform teams, corporate security, and customer-facing business units.

  • Secure modern AI-native codebases operating across multi-cloud environments - including container-based inference services, RAG pipelines, vector stores, and agent orchestration layers.

  • Partner with world-class AI and security engineering teams, providing expert guidance on secure architecture for high-impact AI features and customer-facing AI capabilities.

  • Design and manage response capabilities built into Snowflake's AI operational infrastructure - from model serving endpoints to Cortex Search indexes and Snowpark ML pipelines.

  • Lead with data, code, and automation - build tooling that accelerates detection and response for product security incidents at Snowflake scale.

  • Drive meaningful security outcomes for the customers and enterprises trusting Snowflake with their most sensitive data and AI workloads.

OUR IDEAL SENIOR SECURITY ENGINEER WILL HAVE:

  • 5+ years of experience in information security, primarily in incident response, security engineering, or product/application security (preferred).

  • Direct experience serving as incident commander for product focused security incidents.

  • Experience leading or actively building an application or security engineering program, with a clear point of view on securing AI/ML systems.

  • Experience with threat modeling and security testing across AI attack surfaces, including prompt injection, indirect injection, model inversion, embedding extraction, and supply chain attacks on AI dependencies.

  • Familiarity with the unique data governance and security challenges introduced by LLMs, RAG architectures, and agentic systems.

  • Working knowledge of cloud-native environments (AWS, Azure, GCP) and the threat landscape specific to SaaS and AI platforms.

  • SQL proficiency, plus experience building automation and tools with common programming languages (Python preferred).

  • Strong communication skills, with the ability to translate security risk into actionable guidance for product teams.

  • Empathy for developer experience, helping AI engineers ship securely rather than slowing them down.

  • Bachelor's degree in Computer Science or a related field, or equivalent experience.

BONUS POINTS FOR THE FOLLOWING:

  • Experience securing AI/ML infrastructure, including model serving, vector databases, embedding pipelines, API gateways, and LLM-integrated application architectures.

  • Experience building agentic incident response capabilities, including skills, agents, and pipelines.

  • Understanding of current attacker TTPs, including emerging AI-specific techniques such as adversarial ML, agent manipulation, and LLM jailbreaking in enterprise contexts.

  • Familiarity with CI/CD and secure release lifecycle patterns, with an emphasis on building security into AI feature pipelines.

  • Preferred certifications: GCIA, GCIH, GCSA, GDAT, CISSP/GISP, or cloud certifications (AWS, Azure, GCP).

WHY JOIN OUR SECURITY INCIDENT RESPONSE TEAM AT SNOWFLAKE?

This is a chance to do incident response at the frontier of AI security, on products that thousands of enterprises rely on. You will work alongside strong AI and security engineering teams, shape how Snowflake responds to novel LLM and agentic threats, and build the tooling and playbooks that define response for AI-native systems. The work is high-impact and highly visible, with direct influence on the trust customers place in Snowflake's AI capabilities.

Snowflake is growing fast, and we’re scaling our team to help enable and accelerate our growth. We are looking for people who share our values, challenge ordinary thinking, and push the pace of innovation while building a future for themselves and Snowflake.

How do you want to make your impact?

For jobs located in the United States, please visit the job posting on the Snowflake Careers Site for salary and benefits information: careers.snowflake.com

Redirects to Snowflake's application page.

Other roles

More at Snowflake.

View all 78 roles