Software Engineer - AI Security Product

Obsidian Security

  • Palo Alto, CA
  • 30+ days ago

    Highlights

    Copilot, ChatGPT Enterprise, Gemini, Claude, and a wave of agentic tools are being wired into corporate SaaS faster than security teams can keep up - with broad OAuth scopes, opaque data flows, and non-human identities acting on behalf of employees. Deep knowledge of AI and SaaS security- OWASP LLM Top 10, MITRE ATLAS, prompt injection, agent/tool-use risks, OAuth abuse, and identity models across major AI and SaaS platforms.

    Numbers & Facts

    LocationPalo Alto, CA

    Description

    About the Role

    AI is the fastest-moving attack surface in the enterprise. Copilot, ChatGPT Enterprise, Gemini, Claude, and a wave of agentic tools are being wired into corporate SaaS faster than security teams can keep up - with broad OAuth scopes, opaque data flows, and non-human identities acting on behalf of employees. Obsidian sits directly in the path of this shift.

    As a software engineer working on AI Security, you'll define how Obsidian understands, identifies, and mitigates risk in AI and agentic platforms. You'll own the threat models and data modeling that protect customers - and you'll work in the data yourself, because in this space, the security judgment and the query are inseparable.

    What You'll Do

    • Develop deep expertise in how AI platforms (ChatGPT Enterprise, Copilot, Gemini, Claude, Glean, agentic frameworks) authenticate, what scopes they request, and where risk concentrates.
    • Research emerging AI attack techniques - prompt injection, tool/agent misuse, RAG poisoning, over-permissioned integrations
    • Prototype and ship highly available AI Agent security products.
    • Build and improve data pipelines for high efficiency, development velocity and low cost.

    Requirements

    • 1-3 years of software engineering experience shipping and owning production backend systems, with proficiency in a modern language (Python, Go, or similar).
    • Experience with- AWS/GCP, containers, CI/CD, observability, and production ownership.
    • Hands-on experience with LLM APIs and agentic patterns (tool/function calling, MCP, agent frameworks), or a demonstrated ability to ramp up fast.
    • Hands-on experience with a modern data stack (dbt, and a columnar warehouse or query engine such as ClickHouse, Snowflake, BigQuery, or Databricks).
    • Clear communicator across engineers, PMs, and customer security teams.
    • Comfortable operating with ambiguity in a fast-moving problem space.

    Nice to Have

    • Strong grasp of how SaaS platforms (Google Workspace, Microsoft 365, Salesforce, Okta) expose data- APIs, event schemas, permissions, auth flows.
    • Deep knowledge of AI and SaaS security- OWASP LLM Top 10, MITRE ATLAS, prompt injection, agent/tool-use risks, OAuth abuse, and identity models across major AI and SaaS platforms.
    • Experience in building a cybersecurity product.
    • Strong grasp of identity and access control concepts- OAuth flows, scopes, tokens, and non-human identities.

    Similar Jobs

    See more jobs