Braintrust
Application Security Engineer
San Francisco
Sponsorship not specifiedDetected 76 days ago
JavaScriptPythonData EngineeringLLMsResearch
About the role
- We're looking for an Application Security Engineer who lives in the code.
Responsibilities
- Drive secure design across the platform: lead threat models for new features, review architecture proposals, and partner with product and backend engineers to ship features that are secure by default
- Build the paved road: authn/authz primitives, RBAC and tenancy isolation patterns, secret handling, safe data pipelines, and sandboxed code execution for user-supplied JavaScript and Python snippets
- Own our SAST, DAST, SCA, and secret-scanning tooling end-to-end, keeping signal-to-noise high enough that engineers actually fix what you ship
- Partner with our open source maintainers on the security of libraries that get embedded inside customer applications
- Track record of building secure-by-default libraries, frameworks, or services that other engineers actually adopt
Requirements
- 5+ years in application security, product security, or backend engineering with a security focus - you've shipped real code and reviewed a lot of it
- Deep knowledge of common web and API vulnerability classes and the architectural patterns that prevent them - not just OWASP Top 10 trivia
- Hands-on experience with authn/authz design, multi-tenant data isolation, and secrets/key management at scale
Nice to have
- prior experience with LLM red-teaming, agent sandbox research, or shipping security-focused open source libraries
- A clear point of view on AI/LLM security - prompt injection, agent abuse, tool-use sandboxing, model proxy threats - and ideally hands-on experience defending against them
- Daily user of agentic coding tools and excited to push the frontier of how AppSec gets done with them
Skills
- prompt injection, agent sandbox escapes, tool-use abuse, and the new attack surface that comes with LLM-native applications.
Compensation
- Competitive salary and equity
Benefits
- Medical, dental, and vision insurance
- Flexible time off
- Competitive salary and equity
Company info
- Braintrust is the AI observability platform.
- By connecting evals and observability in one workflow, Braintrust gives builders the visibility to understand how AI behaves in production and the tools to improve it.
- Teams at Notion, Stripe, and Vercel use Braintrust to compare models, test prompts, and catch regressions - turning production data into better AI with every release.
- Lead AI-specific security work: prompt injection defenses, model proxy abuse detection, agent and tool-use sandboxing, data-exfiltration controls in multimodal pipelines, and security for the eval workflows our customers run
Equal opportunity
- Braintrust is an equal opportunity employer.
- All applicants will be considered for employment without attention to race, color, religion, sex, sexual orientation, gender identity, national origin, veteran or disability status.
Apply directly at Braintrust →Create a free account for alerts like thisView Braintrust immigration profile
This listing is sourced directly from Braintrust's careers page and normalized into a canonical job model.