Job Closed
This listing is no longer active.
Our security platform combines AI and domain expertise, enabling teams to ship code faster with higher confidence.
Staff Security Product Engineer
Location
North America
Posted
60 days ago
Salary
0
Seniority
Lead
Job Description
Staff Security Product Engineer
Cantina
• Build product capabilities across application security, security operations, and agent security • Turn real security workflows into product experiences and platform primitives • Design systems that ingest, correlate, triage, and act on security signals • Help define safe patterns for agents, tools, permissions, memory, and execution boundaries • Identify hidden risks and failure modes that only someone with real security experience would see • Partner with product and engineering to make strong tradeoffs between speed, usability, and security • Contribute to evaluation, testing, observability, and guardrails for agentic behavior • Raise the team’s overall understanding of security architecture, operations, and AI risk
Job Requirements
- Deep experience in one or more of: security engineering, application security, detection engineering, incident response, security operations, or security platform engineering
- Strong hands-on experience building and shipping software—you write code, not just review it
- The ability to reason clearly in ambiguous spaces and surface risks early
- Highly valued but learnable here: Experience with AI/LLM application architecture, agent frameworks, or orchestration systems
- Product judgment—translating messy technical workflows into usable product decisions
- Comfort working across technical and non-technical teams
Benefits
- Remote work options
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
• Advise clients on information security and IT security topics • Analyze and assess IT architectures • Support the development of security architectures and concepts • Produce security documentation • Conduct security tests • Interview client contacts to document internal processes • Independently support and manage audits
• Establishing and further developing the Cybersecurity practice in Stuttgart • Advising on governance, compliance and regulatory requirements (e.g., DORA, NIS2, ISO 27001) • Planning and conducting penetration tests • Vulnerability management and re-testing within the EU • Supporting projects with architecture reviews and secure-coding coaching • Collaborating within an international delivery model with teams in DACH, Sweden and Egypt • Developing methods, templates and best practices for sustainable ways of working • Supporting presales activities with proposals and client presentations
• Define priority reporting and analytics use cases (360 participant view, pension calculations, compliance analytics, inactive population communications) and map them to data, security, and tooling requirements • Establish the Data Hub governance framework: data classification, stewardship roles, approval workflows, retention rules, and incident/breach support aligned with OEB and Federal Reserve policies • Map regulatory obligations (HIPAA, applicable state benefits laws) to concrete controls, policies, monitoring processes, and evidence expectations within the Data Hub operating model • Recommend and oversee cataloging, lineage, and access-control approaches (Unity Catalog, AWS Glue Data Catalog, RBAC/ABAC) to support discoverability, traceability, and least-privilege access • Define fine-grained security patterns: RBAC/ABAC, encryption, key management, logging, and monitoring for highly sensitive data • Produce audit-ready evaluation reports summarizing compliance posture, risks, mitigations, and supporting evidence for internal audits and external reviews • Partner with Architecture/Ingestion lead and IV&V lead to ensure governance and security requirements are built into ingestion patterns, data models, and testing from the outset.
Information Security Engineer
G-PFind, hire and manage teams in days instead of months with the #1 Global Growth Platform.™
• Participate in threat modeling exercises with engineering team members • Triage SCA/SAST/DAST/CSPM findings by eliminating false positives and providing well-vetted vulnerabilities to engineering teams • Support vulnerability management efforts for networks and infrastructure • Partner with engineering teams ensuring timely remediation of security findings • Perform security assessments, reviews, and internal penetration tests • Support application security programs and security team initiatives • Develop scripts and tools to automate repetitive security tasks, such as log analysis, patch management, and incident detection. • Build custom solutions to integrate security tools with existing systems using languages like Python, JavaScript, or Go.




