The opportunity
WRITER is where the world's leading enterprises orchestrate AI-powered work. Our vision is to expand human capacity through superintelligence.
What you'll do
Build security into the DNA of our AI platform by conducting threat modeling: sessions with product teams, designing secure architectures for new features, and ensuring security considerations shape product decisions from day one—not after the fact
Own and evolve our application security program including establish and: maintain SAST/DAST scanning in CI/CD pipelines, conducting security code reviews for critical changes, and building automation that catches vulnerabilities before they reach production
Partner with engineering teams to establish and champion secure coding: standards, creating reusable security patterns and libraries that make it easier for developers to build securely by default
Design and recommend security features and products that help secure customer: environments. You are the advocate and the vision for how we protect and secure customers..
Integrate and leverage AI agents to help increase velocity for the security: team and the overarching engineering org to ensure that we are proactive in minimizing risk while we build products
Lead security assessments and penetration testing of WRITER's applications,: AI services, and APIs, identifying vulnerabilities across our tech stack and working collaboratively with teams to remediate issues at scale
What they're looking for
- Design and implement security controls for protecting data pipelines, model: training environments, and customer-facing AI agents
- Stay ahead of emerging threats in the AI/ML security landscape, researching: attack vectors specific to LLMs and generative AI, and proactively building defenses against novel risks
- Minimum 4 years of hands-on experience in application security engineering,: with a proven track record of securing large-scale production systems—bonus points if you've worked in fast-growing startups or high-growth environments
- Understanding of developer experience and developer workflows for shipping: features and products. You care deeply about reducing risk while considering velocity of engineers.