Jobs Companies Braintrust Application Security Engineer

Sobre este puesto de Application Security Engineer en Braintrust

Braintrust · Presencial · San Francisco

About the company

Braintrust is the agent observability platform. By actively applying intelligence to agent traces and automatically surfacing the most critical patterns, Braintrust gives teams the visibility to understand how agents behave in production and the tools to improve them.

Teams at Notion, Stripe, Box, OpenAI, and Cloudflare use Braintrust to trace their agents, find the issues in their observability data, and run evals that tell them how to improve.

About the role

We're looking for an Application Security Engineer who lives in the code. Braintrust is a real-time, high-availability data platform that runs in both SaaS and self-hosted environments, with open source libraries embedded inside thousands of customer applications and a model proxy in front of OpenAI, Anthropic, Gemini, and other major model providers.

This is a hands-on IC role. You'll review code, build threat models, ship paved-road libraries, and lead AI-specific security work: prompt injection, agent sandbox escapes, tool-use abuse, and the new attack surface that comes with LLM-native applications. If you reach for agentic coding tools as your default workflow and can hold your own in a design review with a backend or systems engineer, we'd love to work with you.

What you'll do

  • Drive secure design across the platform: lead threat models for new features, review architecture proposals, and partner with product and backend engineers to ship features that are secure by default

  • Review code across our TypeScript, Python, and Go services, our open source tracing libraries, and our model proxy — and find the bugs others miss

  • Build the paved road: authn/authz primitives, RBAC and tenancy isolation patterns, secret handling, safe data pipelines, and sandboxed code execution for user-supplied JavaScript and Python snippets

  • Own our SAST, DAST, SCA, and secret-scanning tooling end-to-end, keeping signal-to-noise high enough that engineers actually fix what you ship

  • Run our vulnerability management program and triage external bug bounty reports; close the loop with durable fixes, not point patches

  • Lead AI-specific security work: prompt injection defenses, model proxy abuse detection, agent and tool-use sandboxing, data-exfiltration controls in multimodal pipelines, and security for the eval workflows our customers run

  • Partner with our open source maintainers on the security of libraries that get embedded inside customer applications

  • Use agentic coding workflows to scale yourself: automated code review, exploit prototyping, control validation, and IR triage

Ideal candidate credentials

  • 5+ years in application security, product security, or backend engineering with a security focus — you've shipped real code and reviewed a lot of it

  • Strong code reading and writing skills in at least two of TypeScript/Node.js, Python, Go, or Rust

  • Deep knowledge of common web and API vulnerability classes and the architectural patterns that prevent them — not just OWASP Top 10 trivia

  • Track record of building secure-by-default libraries, frameworks, or services that other engineers actually adopt

  • Hands-on experience with authn/authz design, multi-tenant data isolation, and secrets/key management at scale

  • Comfortable with the realities of a high-availability data platform: real-time pipelines, ingestion at scale, semi-structured data, Postgres, Redis, AWS

  • A clear point of view on AI/LLM security — prompt injection, agent abuse, tool-use sandboxing, model proxy threats — and ideally hands-on experience defending against them

  • Daily user of agentic coding tools and excited to push the frontier of how AppSec gets done with them

  • Clear communicator who documents decisions, writes tickets engineers want to pick up, and lifts the team's security awareness without becoming a bottleneck

  • Bonus: prior experience with LLM red-teaming, agent sandbox research, or shipping security-focused open source libraries

Benefits include

  • Medical, dental, and vision insurance

  • Daily lunch, snacks, and beverages

  • Flexible time off

  • Competitive salary and equity

  • Wifi & cellphone stipend

Equal opportunity

Braintrust is an equal opportunity employer. All applicants will be considered for employment without attention to race, color, religion, sex, sexual orientation, gender identity, national origin, veteran or disability status.

¿Listo para postularte en Braintrust?
Postúlate en Braintrust

Empleos similares

VE
Product Security Engineer
Vercel
⚡ Postúlate pronto Hybrid - San Francisco, New Yo... Híbrido $208,000–$312,000
● Nuevo 👁 Visto ✓ Postulado hace 14h
Astranis
Senior Product Security Engineer (Applications)
Astranis
⚡ Postúlate pronto San Francisco Híbrido $180,000–$285,000
● Nuevo 👁 Visto ✓ Postulado hace 16h
Astranis
Product Security Engineer
Astranis
⚡ Postúlate pronto San Francisco Presencial $130,000–$215,000
● Nuevo 👁 Visto ✓ Postulado hace 16h
Faire
Staff Engineer - Product Security
Faire
⚡ Postúlate pronto Kitchener-Waterloo, ON; Toront... Presencial $395,200–$395,200
● Nuevo 👁 Visto ✓ Postulado hace 17h
Faire
Senior Staff Engineer - Product Security
Faire
⚡ Postúlate pronto Los Angeles, CA; New York City... Presencial $268,000–$368,500
● Nuevo 👁 Visto ✓ Postulado hace 17h
Faire
Staff Engineer - Product Security
Faire
⚡ Postúlate pronto Los Angeles, CA; New York City... Presencial $480,480–$480,480
● Nuevo 👁 Visto ✓ Postulado hace 17h
Navan
Staff Product Security Engineer
Navan
⚡ Postúlate pronto Palo Alto, CA or San Francisco... Presencial $135,000–$300,000
● Nuevo 👁 Visto ✓ Postulado hace 3d
Collective
Product Security Engineer
Collective
⚡ Postúlate pronto San Francisco Híbrido $170,000–$200,000
● Nuevo 👁 Visto ✓ Postulado hace 3d
Pinterest
Sr. Security Software Engineer, Application Security
Pinterest
⚡ Postúlate pronto Chicago, IL, US; Remote, US · restringido por ubicación $155,584–$320,320
● Nuevo 👁 Visto ✓ Postulado hace 3d

Regístrate para recibir sugerencias adaptadas a los empleos que abres y las búsquedas que guardas.

Más empleos en Braintrust

Ver todos los empleos en Braintrust →

Postúlate ahora
🤖

Un momento — para

JobsRadar se creó para personas reales que están pasando un mal momento en su búsqueda de empleo — no para solicitudes automatizadas. Estás haciendo clic demasiado rápido y ahora estás bloqueado temporalmente.

Vuelve más tarde. Si de verdad estás buscando empleo, cuentas con nosotros — solo compórtate como una persona.

Catch your next role the second it’s posted.

Create a free account and we’ll watch the boards for you — the instant a job matches your search, it lands in your inbox or Telegram. No digging, no refreshing.

Create free account

Free forever · takes 30 seconds · already have one?

Toma ventaja en tu búsqueda de empleo.

Únete a nuestro canal de Telegram para lo que te ayuda a conseguir el puesto — referencias salariales, el pulso semanal del mercado y avisos de nuevas funciones. Sin spam, solo señal.

Únete al canal — es gratis