StackAI Logo

StackAI

Product Security Engineer

Posted 7 Days Ago
Remote or Hybrid
Hiring Remotely in United States
248K-282K Annually
Mid level
Remote or Hybrid
Hiring Remotely in United States
248K-282K Annually
Mid level
Design, build, and harden security-critical systems: manage KMS and key management, protect PHI/PII, secure storage and tenant isolation, embed security in SDLC and CI/CD, lead threat modeling, and improve security scanning and compliance.
The summary above was generated by AI
About the Company

StackAI (by Asana) is a no-code AI workflow platform that empowers companies to build, deploy, and scale AI-powered workflows easily. With thousands of users and rapidly growing enterprise adoption, our mission is to democratize access to LLMs and bring AI into the hands of every business operator, not just developers. An Asana Company, we're building the foundational platform for the AI-driven future of work

About the role


At StackAI, security is how we earn the trust of the enterprises building AI assistants on our platform. We're hiring a hands-on (Senior) Product Security Engineer to design, build, and harden the secure architecture at the core of the product, working as a technical partner to our Core engineering lead.


This is a hands-on engineering role. You'll write production code and own the security-critical systems the whole platform depends on: encryption and key management, customer data protection, and how security is built into the way every team ships.
If you want deep ownership of these systems and the chance to harden and scale them as the platform grows, we'd love to meet you.


What you'll do
  • Own encryption and signing. Take ownership of our KMS, key management, BYOK, envelope encryption, and signing pipeline across both cloud and on-prem deployments—operating, hardening, and evolving them as the platform scales.

  • Protect the most sensitive customer data. Extend our PHI/PII scrubbing and strengthen the data-protection foundations that regulated enterprises already rely on.

  • Secure the storage layer. Own encryption at rest and tenant isolation.

  • Keep security the default in how we ship. Maintain and expand the secure-by-default templates and reference implementations embedded in our SDLC—the ones engineers actually want to adopt.

  • Threat-model the platform. Lead threat modeling on the seams between systems (the execution engine, connector trust boundaries, and multi-tenant isolation), using modern, AI-assisted threat-modeling tooling.

  • Raise the bar on tooling. Push our scanning further on coverage, signal, and CI enforcement, so critical findings never reach production.

  • Be the technical point of contact for security standards. Translate audit, compliance, and incident-response requirements into real implementation in our codebase.

What we're looking for
  • 4+ years building security-critical systems in production, with significant time spent implementing, not only reviewing or assessing.

  • Practical depth in cryptography and key management: encryption, KMS, secrets handling, and signing in real systems.

  • Secure architecture judgment: you can design and reason about secure systems and hold your own as a technical peer with senior engineers.

  • Multi-tenant SaaS isolation experience, including the data-isolation guarantees regulated customers require.

  • Strong secure-coding skills in our stack: Python on the backend, TypeScript/Node.js on the product surfaces.

  • Comfortable wiring security checks and gates into CI/CD so security is enforced automatically in the pipeline.

Security engineering is broad. If you're strong on most of this and excited to grow into the rest, we'd like to hear from you, even if you don't check every box.
Bonus points

  • Cloud and API security fundamentals on GCP, Azure, or AWS.

  • Securing on-prem, self-hosted, or air-gapped deployments.

  • Experience in regulated domains (healthcare/PHI, finance, etc.).

  • Familiarity with AI/LLM platform security: agent execution, connector trust boundaries, prompt and tool-call risk.

  • Startup or growth-stage experience.

Similar Jobs

2 Days Ago
Remote or Hybrid
USA
120K-180K Annually
Entry level
120K-180K Annually
Entry level
Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Designs and engineers secure network and cloud architectures across AWS, GCP, Azure, and physical data centers. Responsibilities include threat modeling, network segmentation, monitoring, alerting, automation, attack-surface reduction, and secure connection patterns. The role drives strategic security improvements, partners with product and infrastructure teams, communicates architectural decisions, and mentors engineers. Candidates need deep hybrid networking and cloud security expertise, protocol knowledge, scripting ability, independent problem-solving skills, and strong communication.
Top Skills: AIApplied CryptographyAWSAzureCi/CdDnsGCPGoHttp/SHybrid Cloud NetworkingPrivate EndpointsPythonService MeshesShell ScriptingTcp/IpTlsTransit GatewaysVpcsZero Trust Architecture
2 Days Ago
Remote or Hybrid
182K-288K Annually
Senior level
182K-288K Annually
Senior level
Healthtech • Social Impact • Software
Build and advance application and product security across the engineering organization. Responsibilities include establishing secure defaults, CI guardrails, security requirements, threat modeling, risk assessments, penetration testing, vulnerability remediation, secure coding education, roadmap ownership, and hands-on code review. The role partners closely with product, engineering, DevOps, and services teams to secure applications, microservices, and AI features while enabling efficient development.
Top Skills: Ci/CdDastMicroservicesPenetration TestingSastSbomThreat Modeling
2 Days Ago
Remote or Hybrid
USA
100K-145K Annually
Entry level
100K-145K Annually
Entry level
Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Secure CrowdStrike’s software supply chain, open-source dependencies, GitHub organizations, repositories, and source-code environments. Assess risks, implement repository guardrails and secret scanning, investigate malicious packages and dependency threats, automate security checks, and guide engineering teams on secure coding and open-source compliance. The role also contributes to cross-team security initiatives, CI/CD and cloud security integrations, monitoring, and AI-enabled vulnerability triage.
Top Skills: Ai TechnologiesAmazon S3Argo CdArtifactoryBitbucketCi/CdDatadogGitGithub ActionsGitlabGoJavaScriptJenkinsLinuxLogscalePrometheusPythonShellSoftware Composition Analysis (Sca)SplunkUnix

What you need to know about the Austin Tech Scene

Austin has a diverse and thriving tech ecosystem thanks to home-grown companies like Dell and major campuses for IBM, AMD and Apple. The state’s flagship university, the University of Texas at Austin, is known for its engineering school, and the city is known for its annual South by Southwest tech and media conference. Austin’s tech scene spans many verticals, but it’s particularly known for hardware, including semiconductors, as well as AI, biotechnology and cloud computing. And its food and music scene, low taxes and favorable climate has made the city a destination for tech workers from across the country.

Key Facts About Austin Tech

  • Number of Tech Workers: 180,500; 13.7% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Dell, IBM, AMD, Apple, Alphabet
  • Key Industries: Artificial intelligence, hardware, cloud computing, software, healthtech
  • Funding Landscape: $4.5 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Live Oak Ventures, Austin Ventures, Hinge Capital, Gigafund, KdT Ventures, Next Coast Ventures, Silverton Partners
  • Research Centers and Universities: University of Texas, Southwestern University, Texas State University, Center for Complex Quantum Systems, Oden Institute for Computational Engineering and Sciences, Texas Advanced Computing Center

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account