Jobs › Companies › Yahoo › Paranoids Senior Corporate Product Assurance Engineer

Sobre este puesto de Paranoids Senior Corporate Product Assurance Engineer en Yahoo

Yahoo · Presencial · United States of America
Yahoo serves as a trusted guide for hundreds of millions of people globally, helping them achieve their goals online through our portfolio of iconic products. For advertisers, Yahoo Advertising offers omnichannel solutions and powerful data to engage with our brands and deliver results.

A Little About Us


When you impact millions of people every day, you become a large target for adversaries of all types within all layers of the stack. Our job is to keep our users safe and make Yahoo one of the safest places on the Internet. We are the information security team at Yahoo; known as "The Paranoids".


Within the Paranoids, Corporate Product Assurance is the review function for everything employees use to get their work done. Every new third-party product, SaaS integration, vendor connection, AI/LLM tool, and agentic connection entering the corporate environment comes through us before it touches Yahoo data, and we own the baseline configuration reviews and the annual check-in program for the products already in place. Intake and architecture review, MCP and agentic connection review, identity and access review - this is where a business owner who needs a tool today meets a corporate attack surface that has to stay governed.



A Lot About You


As a Paranoids Corporate Product Assurance Engineer, you own a review queue end to end - you take an intake request, understand the system and its trust boundaries, decide what the security requirements are, and close the review to a documented disposition inside an SLA. You will spend as much effort making reviews faster as you spend performing them, because rubrics, precedent, risk tiering, and agentic triage are how this function scales.


Responsibilities


  • Own Paranoid Security Reviews for corporate systems end to end - new third-party SaaS, vendor integrations, employee-facing tools, cloud migrations, and AI/LLM products - from intake through documented disposition, holding review SLAs rather than accumulating an open queue.
  • Review MCP and agentic connections as an extension of each connected data source's security perimeter: authentication and authorization, scope and consent, token issuance and rotation, audit coverage, and what an agent may act on without human authorization.
  • Assess AI and LLM integrations for prompt injection, insecure output handling, sensitive data exposure through model inputs and outputs, and data retention and residency in vendor-hosted inference.
  • Run baseline configuration reviews and the annual corporate-product check-in program, surfacing products that have aged past the review cycle threshold and reconciling the SaaS inventory against actual review history.
  • Evidence data-classification, encryption, logging, and access-control (MFA/Okta) gates on completed reviews against Paranoids standards and industry frameworks (NIST, OWASP, CIS).
  • Write dispositions a stakeholder can act on - what was observed, what it means, whether it blocks, who owns it, and what closes it.
  • Build and tune the triage and first-pass review layer: risk tiering, precedent lookup against review history, enrichment, and the guardrails that decide what an agent may close and what escalates to a person.
  • Verify AI-assisted and agent-drafted review output before it becomes a disposition, so every approval is explainable and nothing closes on an unverified model claim.
  • Partner across queue boundaries with Third-Party Risk, Privacy, Legal, Enterprise Identity, Cloud Security, Network Security, and the MCP Gateway team so cross-domain reviews are not silently skipped in handoff.
  • Drive down per-review effort through rubrics, templates, reusable control sets, and automation, so throughput improves without proportional headcount.
  • Cross-train peers so every review type has at least two capable reviewers and the function carries no single-person dependency.

Basic Qualifications


  • 6+ years of experience in product, application, or corporate/enterprise security, including 2+ years owning security reviews or an assurance function end to end.
  • Demonstrated ownership of a review queue at volume - triage, prioritization, and closing reviews to a documented disposition under a service level, not only producing findings for someone else to resolve.
  • Strong grasp of third-party and SaaS security assessment: tenant configuration, SSO and provisioning integration (SAML, OAuth 2.0, OIDC, SCIM), data flows across trust boundaries, subprocessors, and vendor data-handling commitments.
  • Working knowledge of AI/LLM application security - prompt injection, insecure output handling, sensitive data exposure through model inputs and outputs, and the OWASP Top 10 for LLM Applications.
  • Practical experience reviewing agentic and tool-use architectures (e.g., Model Context Protocol), including scope and consent, credential and token lifecycle, audit logging, and blast radius when an agent is compromised or misbehaves.
  • Hands-on identity and access review experience with Okta or a comparable IdP: MFA enforcement, provisioning and deprovisioning, service accounts and non-human identity, and least-privilege grant review.
  • Understanding of enterprise and collaboration infrastructure at scale - productivity suites, source control, ticketing, HR and finance platforms - and the data exposure patterns specific to each.
  • Familiarity with industry security frameworks (NIST CSF, NIST AI RMF, OWASP, CIS Benchmarks) and the ability to apply them as a control-based critique rather than a checklist.
  • Proven ability to turn a technical description into a control-based risk decision, and to write it so a non-security stakeholder can act on it.
  • Comfort scripting and automating review workflow (e.g., Python) and working against the APIs of the systems under review.
  • Strong stakeholder skills - able to hold a requirement under delivery pressure, and to say plainly what would change the answer.
  • Bachelors Degree in a relevant field or equivalent work experience



Preferred Qualifications


  • Experience standing up or materially improving a security review intake - routing, risk tiering, triage - and measuring the result.
  • Hands-on experience with AI-assisted review tooling (LLM-powered triage, review agents, agent-drafted first-pass review) and an understanding of their limitations and failure modes.
  • Experience defining guardrail policy for automated or agentic decisions: what may close without human touch, what must escalate, and how the decision is made explainable.
  • Familiarity with SaaS Security Posture Management (SSPM) tooling, SaaS inventory reconciliation, and tenant configuration drift.
  • Cloud-native security depth (AWS/GCP) for corporate workloads and vendor-hosted environments.
  • Exposure to open-weight model hosting and agent harness controls - restricting what a model can act on without authorization.
  • Experience with vendor security questionnaires and third-party risk cycles aligned to procurement renewal.
  • Familiarity with model supply chain security - model and dataset provenance, weight integrity, and risks of third-party models and embeddings.
  • Awareness of emerging AI security frameworks such as MITRE ATLAS and ISO/IEC 42001.
  • Certifications such as CISSP, CCSP, CCSK, GWAPT, or CSSLP a plus, but not required.

The material job duties and responsibilities of this role include those listed above as well as adhering to Yahoo policies; exercising sound judgment; working effectively, safely and inclusively with others; exhibiting trustworthiness and meeting expectations; and safeguarding business operations and brand integrity.

At Yahoo, we offer flexible hybrid work options that our employees love! While most roles don’t require regular office attendance, you may occasionally be asked to attend in-person events or team sessions. You’ll always get notice to make arrangements. Your recruiter will let you know if a specific job requires regular attendance at a Yahoo office or facility. If you have any questions about how this applies to the role, just ask the recruiter!

Yahoo is proud to be an equal opportunity workplace. All qualified applicants will receive consideration for employment without regard to, and will not be discriminated against based on age, race, gender, color, religion, national origin, sexual orientation, gender identity, veteran status, disability or any other protected category. Yahoo will consider for employment qualified applicants with criminal histories in a manner consistent with applicable law. Yahoo is dedicated to providing an accessible environment for all candidates during the application process and for employees during their employment. If you need accessibility assistance and/or a reasonable accommodation due to a disability, please submit a request via the Accommodation Request Form (www.yahooinc.com/careers/contact-us.html) or call +1.866.772.3182. Requests and calls received for non-disability related issues, such as following up on an application, will not receive a response.

We believe that a diverse and inclusive workplace strengthens Yahoo and deepens our relationships. When you support everyone to be their best selves, they spark discovery, innovation and creativity. Among other efforts, our 11 employee resource groups (ERGs) enhance a culture of belonging with programs, events and fellowship that help educate, support and create a workplace where all feel welcome.

The compensation for this position ranges from $128,250.00 - $266,875.00/yr and will vary depending on factors such as your location, skills and experience.The compensation package may also include incentive compensation opportunities in the form of discretionary annual bonus or commissions. Our comprehensive benefits include healthcare, a great 401k, backup childcare, education stipends and much (much) more.

Currently work for Yahoo? Please apply on our internal career site.

¿Listo para postularte en Yahoo?
Postúlate en Yahoo

Sobre Yahoo

Yahoo serves as a trusted guide for hundreds of millions of people globally, helping them achieve their goals online through our portfolio of iconic products. For advertisers, Yahoo Advertising offers omnichannel solutions and powerful data to engage with our brands and deliver results.

Ver todos los empleos en Yahoo →

Empleos similares

Yahoo
Principal Software App Engineer - Yahoo Mail
Yahoo
⚡ Postúlate pronto India Presencial
● Nuevo 👁 Visto ✓ Postulado hace 17h
Yahoo
Principal Software Engineer - Backend or Data
Yahoo
⚡ Postúlate pronto Ireland Híbrido €92,850–€154,750
● Nuevo 👁 Visto ✓ Postulado hace 1d
Yahoo
Paranoids Corporate System Security Engineer II
Yahoo
⚡ Postúlate pronto United States of America Presencial $111,000–$231,250
● Nuevo 👁 Visto ✓ Postulado hace 1d
Yahoo
Paranoids Endpoint Security Engineer
Yahoo
⚡ Postúlate pronto United States of America Presencial $111,000–$231,250
● Nuevo 👁 Visto ✓ Postulado hace 1d
Yahoo
Global Opex Finance Manager
Yahoo
⚡ Postúlate pronto United States of America Presencial $90,750–$188,750
● Nuevo 👁 Visto ✓ Postulado hace 1d
Yahoo
Senior Social Video Producer, Yahoo News
Yahoo
⚡ Postúlate pronto United States of America Presencial $90,750–$188,750
● Nuevo 👁 Visto ✓ Postulado hace 2d
Yahoo
Senior Software Apps Engineer - Yahoo Mail
Yahoo
⚡ Postúlate pronto India Presencial
● Nuevo 👁 Visto ✓ Postulado hace 2d
Yahoo
Sr. Software Dev Engineer
Yahoo
⚡ Postúlate pronto India Presencial
● Nuevo 👁 Visto ✓ Postulado hace 2d
Yahoo
Privacy Technologist
Yahoo
⚡ Postúlate pronto United States of America Presencial $129,210–$281,305
● Nuevo 👁 Visto ✓ Postulado hace 2d

Regístrate para recibir sugerencias adaptadas a los empleos que abres y las búsquedas que guardas.

Más empleos en Yahoo

Ver todos los empleos en Yahoo →

Postúlate ahora
🤖

Un momento — para

JobsRadar se creó para personas reales que están pasando un mal momento en su búsqueda de empleo — no para solicitudes automatizadas. Estás haciendo clic demasiado rápido y ahora estás bloqueado temporalmente.

Vuelve más tarde. Si de verdad estás buscando empleo, cuentas con nosotros — solo compórtate como una persona.

Catch your next role the second it’s posted.

Create a free account and we’ll watch the boards for you — the instant a job matches your search, it lands in your inbox or Telegram. No digging, no refreshing.

Create free account

Free forever · takes 30 seconds · already have one?

Toma ventaja en tu búsqueda de empleo.

Únete a nuestro canal de Telegram para lo que te ayuda a conseguir el puesto — referencias salariales, el pulso semanal del mercado y avisos de nuevas funciones. Sin spam, solo señal.

Únete al canal — es gratis