Staff Engineer - Security
Emergent
Emergent
Emergent is revolutionizing software development with autonomous coding agents that generate, test, and deploy applications from natural language. Our AI-driven platform operates at global scale, powering millions of real-world applications and serving over 10 million users worldwide. We are backed by prominent investors and led by a team of experienced founders and industry leaders.
We are focused on solving the complex challenges of AI-driven software creation, ensuring correctness, reliability, security, and scalability in production environments. Join us to build the future of software with ownership, speed, and impact.
As a Staff Security Engineer, you will be instrumental in securing Emergent's massive, multi-tenant AI execution environment. You will own security across the entire stack, from AI-generated applications and pipelines to the cloud infrastructure and runtime environments.
Key responsibilities include: - Securing AI-generated applications by defining patterns, building secure frameworks, and identifying vulnerabilities. - Protecting cloud and runtime infrastructure by designing secure multi-tenant environments, implementing isolation, and hardening cloud resources. - Conducting end-to-end threat modeling for systems involving AI agents, applications, APIs, and infrastructure. - Building robust security detection and defense capabilities, including monitoring, alerting, and red-teaming. - Securing CI/CD and agent pipelines to prevent supply-chain attacks and ensure artifact integrity. - Developing essential security engineering primitives like authentication, authorization, and secure SDKs/APIs.
We are seeking an experienced Security Engineer with 8-15+ years of hands-on expertise in both Application/Product Security and Cloud/Infrastructure Security. Proficiency in coding and automation using Python, JavaScript/TypeScript, or backend systems is essential.
Essential qualifications include: - Deep understanding of application security fundamentals, including OWASP Top 10, authentication/authorization, API security, injection vulnerabilities, secure development, and threat modeling. - Strong cloud and infrastructure security experience across AWS/GCP, Kubernetes, containers, IAM, secrets management, network security, container security, runtime protection, and multi-tenant environments. - Proven experience designing and securing systems that execute untrusted or user-generated code. - Ability to collaborate across application, infrastructure, and platform layers, driving security initiatives from architecture to implementation.
What sets you apart: - Experience securing AI/LLM or agentic systems, including prompt injection and AI-specific threat models. - Familiarity with sandboxed or ephemeral execution environments and building security systems rather than just identifying vulnerabilities.
Emergent
AI / Machine Learning