Remote job
Security Engineer, Platform
Job details
About this role
Role overview
This role owns the security of a credential vault that stores customer-provided API keys for external AI providers, plus everything around it: authentication, sessions, internal access, audit logging, and the controls an enterprise security review expects. The work combines application security with platform engineering in a TypeScript codebase.
Responsibilities
- Own credential storage, key rotation, and the key-encryption-key lifecycle - Harden authentication and authorization for customers and staff, including MFA, session handling, and role-based access - Run threat modeling and security review for new features and follow through on what is found - Build detection for leaked keys and abusive traffic, and write the runbooks that responders use - Prepare the platform and its documentation for independent audits and customer security questionnaires
Requirements
- 4+ years in application or product security with hands-on engineering in a production codebase - Practical cryptography knowledge including authenticated encryption, key management, and an instinct for what not to build yourself - Experience with web authentication (OAuth, sessions, cookies, CSRF, CORS) and secure API design - Ability to write and review TypeScript
Nice to have
- Experience preparing for SOC 2 or ISO 27001 audits - Cloud security experience on Cloudflare, AWS, or GCP - Background in multi-tenant SaaS isolation