Senior Security Engineer

Stelle nicht auf LinkedIn

🕒 vor 4 Tagen

🇺🇸 Vereinigte Staaten – Remote

💵 $220.000 - $260.000 / Jahr

⏰ Vollzeit

🟠 Senior

👮‍♂️ IT-Sicherheitsingenieur

🗣️🇺🇸🇬🇧 Englisch erforderlich

Jetzt Bewerben
Ähnliche Remote-Jobs finden

📊 Überprüfen Sie Ihre Lebenslauf-Bewertung für diese Stelle

Verbessern Sie Ihre Chancen auf ein Vorstellungsgespräch, indem Sie Ihre Lebenslauf-Bewertung vor der Bewerbung überprüfen.

Logo of LiteLLM AI Gateway

LiteLLM AI Gateway

11 - 50 Mitarbeiter

Gegründet 2023

🤖 Künstliche Intelligenz

🔌 API

🏢 Unternehmen

💰 Seed im 2023-07

Artificial Intelligence • API • Enterprise

LiteLLM AI Gateway ist ein selbst gehostetes, isoliertes Gateway-Produkt, das den Zugriff auf große Sprachmodelle, Agenten und Modellsteuerungsplattformen für Plattformteams zentralisiert und kontrolliert. Es bietet eine einzige OpenAI-kompatible API und einen einzigen Login (SSO), um Anfragen an über 140 Anbieter und mehr als 1. 800 Modelle zu leiten, Schlüssel und Geheimdienstverwaltung zu verwalten, Governance durchzusetzen, Kosten und Nutzung zu beobachten und zu optimieren sowie den Austausch von Backend-Modellen ohne Codeänderungen zu ermöglichen. Das Produkt legt Wert auf Unternehmensfunktionen wie Zugriffssteuerungen, Routing, Beobachtbarkeit, Kostengrenzen und sofortige Unterstützung für neue Modelle, sodass Organisationen interne, fein abgestimmte und selbst gehostete Modelle hinter einem Schlüssel zusammenführen können.

Beschreibung

• Conduct deep security reviews of LiteLLM’s Python proxy, APIs, authentication systems, and enterprise features. • Identify and remediate vulnerabilities involving authentication, authorization, secrets, tenant isolation, injection, and data exposure. • Partner directly with engineers throughout design, implementation, code review, and release—not only after code is shipped. • Build application-security tooling into the development lifecycle, including SAST, DAST, dependency scanning, and secrets detection. • Perform internal red teaming and adversarial testing against LiteLLM’s APIs, proxy, and LLM-specific attack surfaces. • Threat-model new products and architecture changes before they reach production. • Create secure coding guidelines and train engineers on common vulnerabilities and defensive practices. • Harden LiteLLM’s Docker images, PyPI packages, GitHub Actions workflows, and release infrastructure. • Detect dependency confusion, poisoned packages, compromised dependencies, exposed secrets, and unsafe build practices. • Implement SBOMs, signed builds, provenance checks, and reproducible-build practices. • Design secure-by-default configurations for cloud and self-hosted deployments, including authentication, IAM, secrets management, and key rotation. • Review cloud infrastructure, network boundaries, access controls, and production deployment patterns. • Strengthen employee identity, device, SaaS, and internal access controls. • Build monitoring and anomaly detection for suspicious API, model, authentication, and routing activity. • Lead security incident response, vulnerability assessment, remediation, post-mortems, and stakeholder communication. • Establish formal vulnerability intake, CVE triage, disclosure, and remediation processes. • Maintain threat models as LiteLLM’s product and architecture evolve.

🎯 Anforderungen

• A strong security generalist who can work across application security, IT, CI/CD, cloud infrastructure, and the software supply chain. • Deep application-security expertise, including manually auditing production Python code and working with engineers to remediate vulnerabilities. • Strong understanding of authentication, authorization, tenant isolation, SSRF, injection, deserialization, secrets management, and common web and API vulnerabilities. • Experience using and configuring tools such as Semgrep, Bandit, CodeQL, Burp Suite, and other SAST or DAST tooling. • Previous experience at an early-stage security startup during its 0→1 journey. • Experience securing containers, GitHub Actions, build pipelines, packages, and software dependencies. • Familiarity with SBOMs, Sigstore, Cosign, Snyk, Grype, Trivy, or equivalent tooling. • Strong knowledge of OAuth2, JWT, mTLS, IAM, and high-throughput API authentication. • Familiarity with prompt injection, LLM data exfiltration, tool abuse, and the OWASP Top 10 for LLM Applications. • Experience with incident response, CVSS scoring, vulnerability management, CVE triage, and coordinated disclosure. • Experience competing in CTFs during college or independently pursuing vulnerability research, reverse engineering, bug bounties, or security projects. • A genuine interest in security outside your day job—you regularly explore new attack techniques, build security projects, or contribute to the security community. • Bachelor’s or Master’s degree in Computer Science or a related field, or equivalent practical experience.

🏖️ Vorteile

• Competitive salary and health, dental, and vision benefits

Jetzt Bewerben

Ähnliche Jobs

🕒 vor 4 Tagen

CareOregon

501 - 1000

🏥 Gesundheitswesen

📦 Logistik

🛡️ Versicherung

Information Security Engineer III responsible for managing corporate security and developing solutions for CareOregon. Collaborating with business leaders and implementing IS policies and systems.

🇺🇸 Vereinigte Staaten – Remote

💵 $113.940 - $139.260 / Jahr

⏰ Vollzeit

🟡 Mittelstufe

🟠 Senior

👮‍♂️ IT-Sicherheitsingenieur

🦅 H1B-Visum-Sponsor

info

🗣️🇺🇸🇬🇧 Englisch erforderlich

🕒 vor 4 Tagen

eMoney Advisor

501 - 1000

💸 Finanzen

☁️ SaaS

🤝 B2B

Senior Cyber Security Engineer at eMoney Advisor, leading detection and prevention of cyber security events. Collaborating with various teams to protect client assets and improve fraud detection capabilities.

🇺🇸 Vereinigte Staaten – Remote

💵 $122.600 - $158.000 / Jahr

⏰ Vollzeit

🟠 Senior

👮‍♂️ IT-Sicherheitsingenieur

🗣️🇺🇸🇬🇧 Englisch erforderlich

Cyber Security

Python

Splunk

SQL

🕒 vor 4 Tagen

OKSI

51 - 200

🎖️ Verteidigung

🚀 Luft- und Raumfahrt

🤖 Künstliche Intelligenz

Product Security Engineer at Opto-Knowledge Systems Inc owning security across hardware and software systems. Leading threat modeling and compliance for product portfolio with collaboration across teams.

🇺🇸 Vereinigte Staaten – Remote

💵 $154.000 - $210.000 / Jahr

💰 €206.500 Grant - Opto-Knowledge Systems im 2024-01

⏰ Vollzeit

🟠 Senior

🔴 Experte

👮‍♂️ IT-Sicherheitsingenieur

🗣️🇺🇸🇬🇧 Englisch erforderlich

Cyber Security

Linux

RTOS

🕒 vor 4 Tagen

Humana

10.000+ Mitarbeiter

🏥 Gesundheitswesen

🛡️ Versicherung

⚕️ Krankenversicherung

Lead of Red Team at Humana responsible for managing red team operations and adversary emulation campaigns. Directing the development of AI-enhanced security practices and establishing red team methodologies.

🗣️🇺🇸🇬🇧 Englisch erforderlich

🕒 vor 4 Tagen

Valiant Solutions

201 - 500

💼 Beratung

🎖️ Verteidigung

🔒 Cybersecurity

Security Architect leading the development of security architecture guidance for on-premise and cloud platforms at Valiant Solutions. Supporting cybersecurity design for a large government agency.

🇺🇸 Vereinigte Staaten – Remote

💵 $150.000 - $160.000 / Jahr

⏰ Vollzeit

🟠 Senior

🔴 Experte

👮‍♂️ IT-Sicherheitsingenieur

🗣️🇺🇸🇬🇧 Englisch erforderlich