About this Senior Product Security Engineer role at LanceDB
About LanceDB
AI advances at the speed of its research, and research moves at the speed of its data. LanceDB is the AI-native Multimodal Lakehouse: one system where a researcher curates petabytes of video, audio, and every signal derived from them with a few lines of Python, and the next training run starts as fast as the next idea. Customers like Runway, Midjourney, and Netflix build the future of AI on LanceDB, from frontier and world models to robots and autonomous vehicles.
About the Role
Our first product security-focused engineer
Takes high-level direction (e.g., “identify top five security-related gaps for AX”) and drives to results
Success looks like a LanceDB platform that follows security-related best practices, and an ongoing partnership with other engineers to continuously enhance our security posture in all areas of the product
What You’ll Do
Drive new security-related functionality such as key rotation, user-managed API credentials, RBAC, and the like
Select, deploy and tune security tooling across all relevant repos and environments, ensuring full coverage
Apply relevant industry trends, best practices, and specific vulnerabilities to our product
What We’re Looking For
8+ years as a software engineer, with a significant portion of that time working on appsec-related work
Experience working on large-scale data platforms (e.g., databases, data infra, ML/AI systems), including work on concurrency and multitenancy
Demonstrated ability to code in Rust and/or C++
Experience building encryption, authentication, and/or authorization features for shipping products at high throughput
Previous experience working at an early-stage startup
Demonstrated ownership of ambiguous projects with minimal guidance
Strong written and verbal communication (can drive alignment across teams)
Comfortable using data (metrics, experiments, usage) to guide decisions
Experience contributing to or working with open source communities
Please apply for this role only if you meet all of the above qualifications, and agree with the day-to-day responsibilities. Of particular note: qualified candidates for this role will have day-to-day coding responsibilities - this is an appsec and devsecops role, not an infosec or platform security role.