← Back to jobs

Staff Security Engineer

Company
Jellyfish
Location
Remote - United States
Work type
Full Time
Posted
2026-10-08

Job description

What you’ll do:
Define Security Strategy & Roadmap: Own and drive the strategic security roadmap, aligning overarching security initiatives with executive business objectives and mitigating top-tier organizational risks.

Architectural Leadership: Own, design, and mandate scalable, resilient security architectures across our core infrastructure, platform, and product ecosystem.

Own the SDLC: Define, implement, and govern the Secure Development Lifecycle (SDLC) company-wide, pioneering automated threat modeling, continuous risk assessments, and secure development practices.

Secure AI Development & Governance: Partner closely with engineering and data science teams to establish and enforce secure development lifecycle (SDLC) practices specifically for both internal AI tools and customer-facing AI features.

AI Threat & Risk Modeling: Lead comprehensive threat modeling and continuous risk assessments tailored to artificial intelligence and machine learning ecosystems, mitigating unique risks such as prompt injection, data poisoning, and sensitive data leakage.

Drive Automation at Scale: Spearhead the overarching strategy and development for automated remedial workflows, comprehensive vulnerability management, and advanced software composition analysis solutions.

Mentorship & Cross-Functional Influence: Act as the definitive security leader, mentoring engineers, advising executive leadership on security posture, and cultivating a pervasive culture of security and inclusion.

Lead Threat & Incident Management: Direct the organizational response for critical security incidents, oversee manual and automated threat modeling, and dictate the strategy for pentesting and bug bounty programs.

About you:
Extensive, proven track record of owning, building, and scaling application security programs in a SaaS or fast-paced startup environment.

Deep technical expertise in software engineering (e.g., Python, JavaScript/TypeScript, Rust, C/C++) combined with architectural-level understanding of reliability, safety, and security.

Deep understanding of the unique security challenges presented by Artificial Intelligence and Large Language Models (LLMs), with practical experience securing both internal AI infrastructure and customer-facing AI applications.

A forward-thinking approach to AI risk management, possessing the ability to balance rapid AI product innovation with rigorous security, compliance, and data privacy standards.

Demonstrated ability to drive cross-functional consensus, influence engineering leadership, and execute large-scale performance, testing, and security initiatives.

You possess strong business acumen, naturally balancing the needs of the user, product velocity, and enterprise security when dictating solutions.

You are a recognized expert who loves tackling complex research in computer security and sharing your knowledge through technical talks and engineering-wide education.

You thrive in autonomous environments, adept at identifying gaps, setting the direction, and executing with a distributed team.

You are eligible to work in the U.S. for any employer.

Located in EST or CST time zone (preferred).

Original source