About the job
Join Scale AI as a highly skilled Security Engineer in our Product Security team, where you will play a pivotal role in safeguarding the security and integrity of our products and services. This position involves conducting comprehensive code reviews, implementing security best practices, and shaping our overarching security strategy. Your proficiency in TypeScript, Python, AWS, CI/CD, SAST, DAST, and Terraform orchestration will be vital in detecting and addressing potential security threats. You will have the opportunity to analyze complex issues, identify root causes independently, and articulate the complexities and implications of security vulnerabilities, including their potential for exploitation and impact.
Your responsibilities will include:
- Utilizing extensive product security knowledge to design and maintain software tools that secure every layer of the modern AI/ML software ecosystem.
- Conducting thorough code reviews to identify and rectify security vulnerabilities.
- Assessing and improving the security of our product offerings through RFC and service evaluations.
- Establishing and sustaining CI/CD pipelines with a strong emphasis on security.
- Executing Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) to uncover vulnerabilities in production code.
- Employing Terraform orchestration to maintain secure and efficient infrastructure management.
- Advising engineering teams on developing robust, long-term solutions that prioritize security and privacy.
- Clearly communicating the mechanics and significance of security vulnerabilities, including their exploitability and potential consequences.
- Contributing to the security strategy and direction of the team, advocating for best practices and ongoing enhancements.
Ideal candidates will possess:
- A proven track record of independently driving multi-month security initiatives, from problem identification to execution, with minimal oversight.
- Significant experience as a Security Engineer with an emphasis on product security.
- Proficiency in NodeJS, TypeScript, Python, and/or Kubernetes.
- A strong grasp of modern JavaScript application design.
- Practical experience in operating and securing AWS infrastructure at scale.
- Hands-on experience with SAST and DAST tools and methodologies.
- Familiarity with Terraform orchestration for managing infrastructure.
- Capability to analyze complex problems and identify root causes independently, providing actionable insights without managerial input.
- Exceptional communication skills, enabling clear presentation of technical concepts to diverse audiences.

