Jobs · Engineering · California

Software Engineer, Security

Zof AI · San Francisco, CA · 1 wk ago
EngineeringFull-time

San Francisco, CA • Full-time • Mid to Senior • On-site

About This Role

Zof AI is seeking a Security Engineer to own the security posture of a platform that reads, executes, and modifies customer source code. This role covers isolation between agent workloads and tenants, secrets and credential handling, supply chain security, and the enterprise controls that buyers audit before they trust us with a repository. If you have worked as an Application Security Engineer, Product Security Engineer, Cloud Security Engineer, or Infrastructure Security Engineer, this is that discipline at Zof AI. The ideal candidate thinks in threat models, ships controls instead of policy documents, and treats customer code as the most sensitive asset we hold.

Responsibilities

  • Own the security posture of a platform that reads, executes, and modifies customer source code.
  • Harden the sandbox, tenant, and workload isolation boundaries agents run inside.
  • Design secrets management, credential handling, and least privilege access across the platform.
  • Secure the software supply chain from dependencies through build and deploy.
  • Build the technical controls behind SOC 2 and enterprise security requirements.
  • Teach our agent fleets to find, prove, and remediate real vulnerabilities in customer code.
  • Run threat modeling, design reviews, and incident response as a regular practice.
  • Partner with engineering and sales to clear enterprise security reviews and questionnaires.

Requirements

  • Experience securing production software systems or cloud infrastructure.
  • Strong software engineering foundation and comfort shipping code, not just reviewing it.
  • Working knowledge of application security and common vulnerability classes.
  • Experience with cloud security, identity, and access control.
  • Familiarity with compliance frameworks such as SOC 2.
  • Clear written and verbal communication.
  • Comfort operating in a fast-moving environment.
  • High ownership of security outcomes, not just findings.

Nice to have

  • Experience with sandboxing, container isolation, or multi-tenant architecture.
  • Experience with LLM or agent security, including prompt injection and tool use risk.
  • Experience with static analysis, fuzzing, or automated vulnerability detection.
  • Experience leading enterprise security reviews or SOC 2 audit readiness.

What we provide in San Francisco

  • MacBook Pro
  • Premium AI development tools: Cursor Ultra, Claude Code Ultra, OpenAI Codex Max or equivalent advanced AI tooling
  • Access to a high-performance AI product environment
  • Close collaboration with leadership, engineering, and customers
  • Opportunity to work in the San Francisco AI ecosystem
  • Wellness and productivity support where applicable
  • Competitive startup environment with high ownership and direct product impact

Similar jobs