Senior Security Engineer
Job Description
Key Skills Required
Master these to land this role
Want to know if you're a match for this job?
About The Role
As a Senior Security Engineer at Jasper, you'll be the first true generalist on our Security Engineering team—someone equally comfortable securing and building AI agents and platforms as they are automating GRC controls or hardening cloud infrastructure. This role sits at the center of a fast-moving security function, partnering closely with Engineering, GRC, Product, and IT to protect the systems and AI products Jasper builds.
You'll set technical direction on AI security while still being hands-on across infrastructure, product security, and compliance engineering—a true jack-of-all-trades role that flexes across the full security spectrum as priorities shift. This is a force-multiplier position on a small team where your work will have outsized impact on how Jasper builds securely at scale.
This fully remote role reports to the Director, Security and is open to candidates located anywhere in the US.
What you will do at Jasper
- Lead the security design, implementation, and controls for Jasper’s AI infrastructure and AI-powered internal workflows—building the guardrails that govern how AI systems access, process, and handle sensitive data at every layer
- Own threat modeling for AI-specific risks, including the attack surfaces that don’t map cleanly onto traditional application security, and design controls for validating, logging, and auditing AI outputs where accuracy and data protection are non-negotiable
- Build security tooling and automated checks that let internal teams adopt AI capabilities without slowing down
- Collaborate, design, and influence the direction of the Security program at Jasper
- Work with the GRC team to build and maintain GRC-related engineering—automating evidence collection, control monitoring, and compliance workflows (ie. via Vanta or similar) so the team spends less time on manual audit prep
- Strengthen infrastructure security across GCP and AWS: identity and access management, network segmentation, secrets management, and secure-by-default infrastructure patterns
- Own and improve GitHub security controls—branch protection, required reviews, secret scanning, dependency/SCA policies, and CI/CD pipeline security
- Operate and tune Wiz (or equivalent CSPM/CNAPP tooling) to continuously identify and drive remediation of cloud misconfigurations and vulnerabilities
- Use AI tools heavily in your own workflow (code review, triage, detection engineering, documentation) and help the broader security and engineering org do the same safely, while partnering cross-functionally with Engineering, Legal, Product, IT, and GRC to translate security and compliance requirements into practical, low-friction engineering solutions
What you will bring to Jasper
- AI fluency—a working understanding of core AI concepts (LLMs, agents, copilots, tokens, credits, context windows, RAG, data governance, etc.), applied in the context of security engineering, with demonstrated enthusiasm for using AI tools to work faster and more effectively day to day
- 8+ years in security engineering, with hands-on experience across at least two of: AI/ML security, cloud infrastructure security, and/or GRC compliance engineering
- Practical experience securing AI systems—LLM applications, agents, or ML pipelines—including familiarity with common AI-specific threats (prompt injection, data leakage, model abuse, insecure tool use)
- Deep understanding of security principles, best practices, and common vulnerabilities, including strong security judgment under ambiguity
- A proactive mindset, with the ability to identify, prioritize, and address security gaps or inefficiencies through automation and tooling
- Expertise and curiosity about using frontier models and agents to effectively solve security challenges
- Demonstrated ability to build security programs, processes, or standards from scratch rather than inheriting a mature playbook
- Strong working knowledge of GCP and AWS security services and IAM models
- Experience with GitHub security controls (branch protection, secret scanning, Actions/CI security) and secure software supply chain practices
- Hands-on experience with Wiz or a comparable CSPM/CNAPP platform
- Comfort building automation and tooling (scripting, APIs, infrastructure-as-code) rather than relying solely on point-and-click console work
- Strong cross-functional collaborator who can communicate security and compliance tradeoffs clearly to both engineers and non-technical stakeholders
- Direct experience building or securing AI agent frameworks, agent tool-calling systems, or internal AI platforms
- Experience supporting SOC 2 / ISO 27001 or similar compliance frameworks and working with GRC platforms (e.g., Vanta, Drata)
- Background in detection engineering or building internal security tooling
- Experience being an early or first specialized hire on a small security team, comfortable with ambiguity and shifting priorities
- Experience working in AI infrastructure platforms (e.g., Modal, CoreWeave, etc.)
How would you rate this job post?
See what other professionals think about this role.
Similar Opportunities
More Openings at Jasper
Explore Top Companies in this Space
Jasper
View Company ProfileJasper is an enterprise-grade, AI-powered marketing and content creation platform built for modern marketing teams and agencies. The company provides a comprehensive suite of AI tools and specialized agents that help businesses automate and scale the production of blog posts, social media campaigns, ad copy, emails, and website content. A core differentiator of Jasper is its focus on enterprise trust, security, and advanced brand control; its "Brand Voice" feature ensures that all AI-generated content adheres to a company's specific tone, style, and brand guidelines. By offering customizable workflows, campaign planning tools, and robust team collaboration features, Jasper enables organizations to execute go-to-market strategies faster and more efficiently while maintaining high-quality, on-brand messaging.
Safety First
- Never pay for a job application.
- Do not share sensitive bank info.
- Verify the client before starting work.



