xAI· Information Security· Palo Alto, CA
Application Security Engineer
Comp$200,000 – $340,000
Classified Tasks (10)
Automate 0%Augment 90%Human-Only 10%
Augment (9)
AI assists, human decides
Ensure the security and integrity of cloud-native applications and systems throughout the software development lifecycle, focusing on code security, CI/CD pipelines, and emerging AI technologies
technical
Conduct in-depth code reviews and static analysis to identify and mitigate security vulnerabilities in applications
technical
Design and implement secure coding guidelines and best practices for development teams
leadership
Collaborate with development teams to integrate security practices throughout the CI/CD pipeline
operational
Perform threat modeling and risk assessments for applications and develop mitigation strategies for identified risks
analytical
Manage vulnerability tracking and remediation efforts and provide guidance to development teams on fixes
operational
Monitor emerging security threats and trends in cloud-native technologies and AI and continuously enhance security measures
analytical
Evaluate and secure software supply chains and produce and maintain Software Bills of Materials (SBOMs)
technical
Address and remediate security concerns specific to AI and machine learning models, with emphasis on the OWASP LLM Top 10
technical
Human-Only (1)
Requires human judgment
Support and participate in incident response activities related to application security
operational
Job description
ABOUT xAI xAI’s mission is to create AI systems that can accurately understand the universe and aid humanity in its pursuit of knowledge. Our team is small, highly motivated, and focused on engineering excellence. This organization is for individuals who appreciate challenging themselves and thrive on curiosity. We operate with a flat organizational structure. All employees are expected to be hands-on and to contribute directly to the company’s mission. Leadership is given to those who show initiative and consistently deliver excellence. Work ethic and strong prioritization skills are important. All employees are expected to have strong communication skills. They should be able to concisely and accurately share knowledge with their teammates. ABOUT THE ROLE: We are seeking a skilled and innovative Application Security Engineer to join our technology-driven company. In this role, you will be responsible for ensuring the security and integrity of our cloud-native applications and systems throughout the software development lifecycle, with a particular focus on code security, CI/CD pipelines, and emerging AI technologies. RESPONSIBILITIES: Conduct in-depth code reviews and static analysis to identify and mitigate security vulnerabilities in our applications Design and implement secure coding guidelines and best practices for development teams Collaborate closely with development teams to integrate security practices throughout the CI/CD pipeline Perform threat modeling and risk assessments for applications, developing mitigation strategies for potential risks Manage vulnerability tracking and remediation efforts, providing guidance to development teams Support incident response activities related to application security Stay current on emerging security threats and trends in cloud-native technologies and AI, continuously enhancing our security measures Evaluate and secure software supply chains, including producing and maintaining Software Bills of Materials (SBOMs) Address security concerns specific to AI and machine learning models, with a focus on the OWASP LLM Top 10 BASIC QUALIFICATIONS: Bachelor's degree in Computer Science, Cybersecurity, or a related field 3-5 years of experience in application security, with a strong focus on code security practices Deep understanding of secure coding practices, application security frameworks, and common vulnerabilities (e.g., OWASP Top 10) Proficiency in Python or Rust programming languages and experience with secure coding practices in these languages Experience securing CI/CD pipelines and implementing DevSecOps practices Familiarity with software supply chain security and SBOM generation tools Experience with security testing tools (e.g., Burp Suite, OWASP ZAP) and static/dynamic code analysis Understanding of AI/ML security implications, particularly those outlined in the OWASP LLM Top 10 Excellent communication skills, able to explain complex security issues to both technical and non-technical audiences PREFERRED SKILLS AND EXPERIENCE: Experience with cloud platforms (e.g., GCP, AWS, Azure) and their security features Relevant security certifications (e.g., CSSLP, OSWE) Background in data privacy and compliance regulations relevant to cloud-native applications and AI systems Exp