Conversational AI Security EngineerLead the application security strategy and implementation for Decagon AI's conversational platform that serves enterprise customers at scale. You'll partner with engineering teams to build security directly into our AI-powered applications, ensuring protection against application-layer threats while maintaining the performance and reliability our customers expect. This role offers the opportunity to apply deep application security expertise to AI systems and shape security practices across our rapidly growing engineering organization.In this role, you will:Design and implement application security controls across our AI agent platform, including secure coding practices, threat modeling, and vulnerability management.Collaborate closely with product engineering teams to integrate security throughout the software development lifecycle, from design, coding, PR, and deploymentEstablish application security testing programs including static analysis (SAST), dynamic analysis (DAST), and interactive testing (IAST) tailored for AI applicationsLead security code reviews and architecture assessments for new features, with special focus on AI model integration points and customer data handlingBuild security tooling and automation to enable developers to identify and remediate vulnerabilities quickly while maintaining development velocityRespond to security incidents involving application vulnerabilities, coordinating remediation efforts and post-incident improvementsYour background looks something like this:Have 3-5 years of hands-on application security engineering experienceExpertise in secure software development practices, including threat modeling, secure code review, and vulnerability assessmentStrong software engineering background with ability to review code across multiple languages and frameworks commonly used in AI/ML applicationsExperience implementing application security testing tools and integrating security into CI/CD pipelinesKnowledge of OWASP Top 10, common application vulnerabilities, and modern application security frameworksProven track record working with engineering teams to remediate security findings while balancing security and business requirementsEven better:Experience securing AI/ML applications, including prompt injection, model extraction, and adversarial input protectionsBackground with large-scale, multi-tenant SaaS applications handling sensitive customer dataFamiliarity with Google Cloud application security services and container security best practicesKnowledge of enterprise compliance requirements (SOC 2, ISO 27001, GDPR) from an application security perspectiveExperience with modern security tools like Semgrep, CodeQL, Cursor Bug Bot, XBOW, or similarCompensation: $200K – $330K + Offers EquityBenefits:Medical, Dental, and Vision benefits for you and your familyLife Insurance and Disability BenefitsRetirement Plan (e.g., 401K, pension)Parental LeaveFertility and family building benefits through CarrotMonthly stipend to support your wellness, lifestyle, and work-life balanceDaily lunches and snacks in the office to keep you at your bestTake what you need vacation policy (subject to local requirements; UK employees receive 25 days of statutory leave)These benefits are described in more detail in Decagon's policies, may vary by location, and can change at any time according to applicable compensation and benefits plans.