Senior Product Security Engineer
Job Description
Key Skills Required
Master these to land this role
Want to know if you're a match for this job?
Enterprises hand Cohere their most sensitive data and put our models inside workflows they can't afford to get wrong. Securing that means working on problems the industry hasn't settled yet, such as:
- What authorization means when an agent acts on a user's behalf
- How to contain tools that consume untrusted input
- Whether tenant boundaries hold when a model can be steered by the data it reads
We're hiring a Senior Product Security Engineer to tackle these challenges alongside engineers building the products. This role involves:
- Reviewing architecture, code, and security-sensitive changes to identify vulnerabilities and recurring design patterns
- Evaluating risks such as prompt injection, unsafe tool use, identity and delegation failures, excessive agency, data exposure, tenant isolation, and sandbox escapes
- Threat modeling new capabilities to identify trust boundaries, abuse cases, and high-impact failure modes before implementation
- Performing hands-on testing, including investigating vulnerabilities, developing proofs of concept, and assessing exploitability and impact
- Building scalable guardrails like secure defaults, approved patterns, reusable controls, review requirements, and automated checks
- Strengthening engineering capability by pairing with engineers, documenting guidance, and helping teams develop security expertise
- Influencing risk decisions by explaining technical findings, business impact, and remediation options to engineers, product leaders, and executives
You may be a good fit if you have:
- Strong software engineering fundamentals and experience independently understanding, testing, and contributing fixes to production codebases
- Proficiency in at least one of Python, Go, or TypeScript
- Experience leading security reviews or threat models for complex production systems, with measurable design or risk improvements
- Understanding of common vulnerability classes, including injection, authorization flaws, IDOR, SSRF, unsafe deserialization, race conditions, cryptographic misuse, and software supply-chain risks
- Knowledge of modern application architecture, including web applications, APIs, OAuth/OIDC, cloud platforms, containers, Kubernetes, and CI/CD systems
- Ability to reason rigorously about untrusted input, authorization, isolation, identity, delegation, and data boundaries. Experience with agentic AI systems is valuable but not required
- Experience driving security improvements across multiple engineering teams, where influence mattered more than authority
- Clear communication skills with both technical and non-technical audiences
Nice to have:
- Experience building or operating security tooling such as SAST, DAST, SCA, custom linters, or policy-as-code
- Experience securing multi-tenant SaaS, enterprise software, or systems processing sensitive customer data
- Offensive security experience through penetration testing, red teaming, or security research
- Experience operating or participating in a vulnerability disclosure or bug bounty program
- Contributions to open-source security projects, published research, conference talks, or credited vulnerability discoveries
How would you rate this job post?
See what other professionals think about this role.
Similar Opportunities
More Openings at Cohere
Explore Top Companies in this Space
Toloka AI
Artificial Intelligence
Deepgram
Artificial Intelligence
Kastle ai
Artificial Intelligence
Gradient AI
Artificial Intelligence
Cohere
View Company ProfileCohere is a cutting-edge artificial intelligence company that specializes in developing innovative language models and natural language processing technologies. With a strong focus on research and development, Cohere is committed to pushing the boundaries of what is possible with AI. The company's mission is to create a future where humans and machines can collaborate seamlessly, enabling new possibilities for creativity, productivity, and problem-solving. By harnessing the power of language models, Cohere aims to revolutionize the way we interact with technology and each other, making it easier to access information, generate new ideas, and build meaningful connections. With a team of expert researchers and engineers, Cohere is well-positioned to drive significant advancements in the field of AI and make a lasting impact on the world. As a leader in the AI industry, Cohere is dedicated to fostering a culture of innovation, collaboration, and continuous learning, and is poised to play a major role in shaping the future of technology and society.
Safety First
- Never pay for a job application.
- Do not share sensitive bank info.
- Verify the client before starting work.

