Software Engineer, Security
- Location
- San Francisco, CA
- Track
- AI Security
- Salary
- $230K–$390K / yr
- Posted
- January 7, 2026
- Source
- Ashby
Job description
About us
Software Engineer, Security
Security Engineering builds the foundations that let Sierra deliver powerful AI agents while protecting customer data and trust. We partner across product and platform to make security, privacy, and safety core product capabilities and secure defaults.
What you’ll do
Our work spans several security domains. You’ll go deep where your strengths and interests are strongest, with opportunities to explore new areas alongside the team.
Build the Foundations of Trust.
Design and ship systems that make Sierra’s platform secure by default — spanning agent safety/security, privacy, identity, authentication, authorization, and data security. You’ll work across all layers of production (agents, infrastructure, backend, frontend) to embed security-conscious design into the core of our product.
Own Cross-Cutting Systems.
Partner with product and platform teams to implement and evolve Sierra’s trust primitives: identity management, access control, auditability, and data lifecycle management. You’ll make pragmatic design trade-offs between usability, performance, and security.
Secure Agentic AI Systems.
Build controls that ensure AI agents can't leak customer data, execute unauthorized actions, or be manipulated into unintended behavior. Design runtime policy enforcement for tool use, implement safe agent sandboxing, and create boundaries that protect data while keeping agents powerful and useful.
Automate and Scale Security-Adjacent Workflows.
Create developer-friendly tooling to reduce risk and friction — whether through automating security checks in CI/CD, enforcing privacy boundaries through schema validation, or instrumenting runtime monitoring for sensitive events.
What you’ll bring
Strong Software Engineering Skills.
Experience building and maintaining production systems. You’re comfortable designing APIs, integrating with authentication or identity frameworks, and thoughtfully using AI-assisted development tools to build, test, and ship high-quality code faster without lowering the quality bar.
Security Mindset.
You think like a security engineer — considering how data flows, where it’s stored, who can access it, and how to design for least privilege and transparency.
Product and Platform Mindset.
You care about building secure scalable systems that enable , not block, innovation. You work closely with product teams to make trade-offs clear and help them move quickly without sacrificing trust.
Curiosity and Ownership.
You take ambiguous, cross-cutting problems from first principles to production and go deep when needed: tracing an authorization decision from agent intent through policy enforcement and downstream effects, or following sensitive data across model context, logs, storage, and tenant boundaries. You define the problem, align partners, ship the solution, and own it in production.
Even better if…
- You’ve worked on privacy , identity , trust & safety , authN/authz , or data protection systems.
- You’ve built security frameworks, libraries, or tooling that developers actually use or integrated security automation into CI/CD pipelines.
- You have exposure to AI systems or care about designing secure-by-default LLM applications .
- You think like an attacker — you naturally ask "what could go wrong?" when reviewing designs or while building systems. You've found or fixed real security issues in production systems.
- You thrive in 0→1 environments , where foundational systems have to balance speed, reliability, and trust.