Unknown Company

Senior Security Engineer

wilmington, de • Posted 2 days ago
Remote Full Time IT & Technology

Senior Security Engineer (BBBH ) USA

Salary: USD - USD per annum + PTO + Benefits + Equity

Senior Security Engineer (AI DevTool Start-Up)

$220,000 – $260,000 + Equity + Benefits + 401(k)

Remote

Are you a security generalist who genuinely enjoys the craft outside of work, through CTFs, vulnerability research, or independent experimentation? Do you have the depth to manually audit production Python code and work directly with engineers to close what you find, rather than just filing a report and moving on?

This is an opportunity to join a fast-growing, profitable startup at the forefront of AI infrastructure, building the compliance and reliability layer that enterprise customers like Adobe, Netflix, and NASA depend on in production. They’re profitable, with 8-figure ARR and you’d be joining them with seed-level equity ahead of a Series A raise.

Backed by top-tier investors, the team has built the world's most widely used LLM Gateway, a unified platform that gives developers secure, scalable access to every major LLM provider. Now, they're looking for their first Security Engineer to help secure the application, infrastructure, and software-delivery pipeline behind it.

As a hands‑on security generalist, you'll spend most of your time reviewing and hardening the Python codebase, identifying new attack surfaces, and making secure development practices part of how the team builds, alongside owning security across IT, CI/CD, cloud infrastructure, and the software supply chain.

If you're looking for a role where deep security expertise directly shapes how an open-source product used by enterprises around the world gets built, whilst benefiting from strong equity in an already profitable company before they raise their Series A, this is an outstanding opportunity.

The Role

  • Conduct deep security reviews of the Python proxy, APIs, authentication systems, and enterprise features
  • Identify and remediate vulnerabilities across authentication, authorization, secrets, tenant isolation, and injection
  • Build application-security tooling into the dev lifecycle, including SAST, DAST, and dependency scanning
  • Perform internal red teaming against APIs, proxy, and LLM‑specific attack surfaces
  • Harden Docker images, PyPI packages, GitHub Actions workflows, and release infrastructure
  • Lead security incident response, vulnerability assessment, and remediation

The Person

  • Strong security generalist across application security, IT, CI/CD, cloud, and supply chain
  • Deep application‑security expertise, including manually auditing production Python code
  • Experience at an early‑stage security startup during its 0?1 journey
  • Strong grasp of OAuth2, JWT, mTLS, IAM, and high‑throughput API authentication
  • Familiarity with prompt injection, LLM data exfiltration, and the OWASP Top 10 for LLM Applications
  • CTF, bug bounty, or independent vulnerability research background

#J-18808-Ljbffr
Back to Job Search