Principal / Staff Security Engineer - AI Platform & DevSecOps
$210k - $270kAiDASH, Inc.
About AiDASH AiDASH is an enterprise AI company and the leading provider of vegetation risk intelligence for electric utilities. Powered by proprietary VegetationAI™ technology, AiDASH delivers a unified remote grid inspection and monitoring platform that uses a SatelliteFirst approach to identify and address vegetation and other threats to the grid. With a prevention-first strategy to mitigate wildfire risk and minimize storm impacts, AiDASH helps more than 140 utilities reduce costs, improve reliability, and lower liability across their networks. AiDASH exists to safeguard critical utility infrastructure and secure the future of humanAIty™. Learn more at We are a Series C growth company backed by leading investors, including Shell Ventures, National Grid Partners, G2 Venture Partners, Duke Energy, Edison International, Lightrock, Marubeni, among others. We have been recognized by Forbes two years in a row as one of "America's Best Startup Employers." We are also proud to be one of the few software companies in Time Magazine's "America's Top GreenTech Companies 2024". Deloitte Technology Fast 500™ recently ranked us at No. 12 among San Francisco Bay Area companies, and No. 59 overall in their selection of the top 500 for 2024.
Join us in Securing Tomorrow! The Role
AiDASH protects the critical infrastructure that delivers power to tens of millions of people. We are SOC 2 Type II certified today, and we're working toward ISO 27001 and ISO 42001 certifications in 2027. As we embed GenAI more deeply into our SaaS products (RAG pipelines, agentic / MCP services) and roll out AI-assisted development internally, the threat landscape is shifting fast. Autonomous adversaries, Mythos-class threat actors, prompt injection, model exfiltration, and vibe-coded internal apps spun up by non-engineers are now part of the daily attack surface.
We're hiring a Principal or Staff Security Engineer to be our deepest technical voice on security - covering DevSecOps, AI/LLM security, cloud and endpoint defense, IT-Security, and the governance work that will land us ISO 27001 and 42001 certifications in 2027. You'll architect the strategy, pick the right tools where gaps exist, run the audits, and grow the function. You will report to senior leadership and partner with platform, ML, DevOps, and IT leadership across the company.
If you've been waiting for a chance to lead the security program at a Series C AI company that ships production AI to critical infrastructure operators, this is that role.
The Team
You'll partner with our existing security and compliance team based in India - a security engineer plus two compliance specialists, currently within the DevOps organization - and serve as the most senior security IC at AiDASH and the company's authority on AI/LLM security. This role represents the next phase of our security investment: bringing senior-IC depth, AI-native security leadership, and modern detection engineering to a program that has so far been operated alongside DevOps.
How you'll make an impact:
We offer a competitive base pay range for this full-time position, which is between $210,000 and $270,000 per year. This range reflects the anticipated base salary for new hires. In addition, this role is also eligible for an annual performance bonus and equity. We strive to ensure our compensation packages are equitable and aligned with industry standards. Your recruiter can share more about compensation during the hiring process.
We are committed to providing an inclusive and accessible interview experience for all candidates. Please let us know if you require any accommodation during the interview process, and we will make every effort to meet your needs. Read our Privacy Policy here:
Join us in Securing Tomorrow! The Role
AiDASH protects the critical infrastructure that delivers power to tens of millions of people. We are SOC 2 Type II certified today, and we're working toward ISO 27001 and ISO 42001 certifications in 2027. As we embed GenAI more deeply into our SaaS products (RAG pipelines, agentic / MCP services) and roll out AI-assisted development internally, the threat landscape is shifting fast. Autonomous adversaries, Mythos-class threat actors, prompt injection, model exfiltration, and vibe-coded internal apps spun up by non-engineers are now part of the daily attack surface.
We're hiring a Principal or Staff Security Engineer to be our deepest technical voice on security - covering DevSecOps, AI/LLM security, cloud and endpoint defense, IT-Security, and the governance work that will land us ISO 27001 and 42001 certifications in 2027. You'll architect the strategy, pick the right tools where gaps exist, run the audits, and grow the function. You will report to senior leadership and partner with platform, ML, DevOps, and IT leadership across the company.
If you've been waiting for a chance to lead the security program at a Series C AI company that ships production AI to critical infrastructure operators, this is that role.
The Team
You'll partner with our existing security and compliance team based in India - a security engineer plus two compliance specialists, currently within the DevOps organization - and serve as the most senior security IC at AiDASH and the company's authority on AI/LLM security. This role represents the next phase of our security investment: bringing senior-IC depth, AI-native security leadership, and modern detection engineering to a program that has so far been operated alongside DevOps.
How you'll make an impact:
- DevSecOps & AppSec
- Operate and mature our AppSec toolchain across CI/CD - SAST, DAST, SCA, secrets scanning, and IaC policy-as-code. Deepen coverage and evaluate additional tooling where gaps are real
- Run threat modeling and secure-design reviews; champion shift-left so security is part of every PR, not a gate at the end
- Operate the AIBOM / SBOM toolchain; enforce risk-tiered dependency controls and extend SLSA practices to model artifacts
- AI & LLM Security
- Harden production GenAI deployments on AWS (managed model APIs, agentic / MCP services) - IAM, VPC routing, prompt-layer guardrails, output filtering, rate/cost controls
- Codify OWASP LLM Top 10 and MITRE ATLAS controls into the SDLC; introduce LLM eval-as-gate in CI
- Govern internal AI-assisted developer tooling - DLP for what egresses to external model providers, sensitive-data discovery in prompts, and acceptable-use telemetry
- Stand up controls for vibe-coded apps and shadow AI: discover, classify, gate with sane defaults, and bring under the SDLC
- ISO 27001 / 42001 & Security Governance
- Lead the company's path to ISO 27001 and ISO 42001 (AI Management System) certifications in 2027 - scope the management systems, run gap assessments, build the control sets, and steer the audit cycles
- Maintain our SOC 2 Type II posture; manage the evidence pipeline, control mappings, and external auditor relationships
- Maintain alignment with the NIST AI RMF and translate emerging AI regulation (EU AI Act, US state AI laws, utility-sector mandates) into concrete engineering requirements
- Cloud, Endpoint & IT-Security
- Operate our endpoint, cloud, identity, and SIEM platforms end-to-end. Own detection engineering, tuning, and integration with the rest of the stack
- Harden AWS posture across accounts (Organizations, SCPs, Control Tower); mature Kubernetes security (admission controllers, runtime visibility, pragmatic hardening)
- Stand up zero-trust privileged access - short-lived, audited sessions for production infra, databases, and Kubernetes
- Lead IT-Security: device posture, identity (SSO, MFA, SCIM), network segmentation, SaaS posture, and offboarding hygiene
- Detection, Response & Resilience
- Build and tune detections in our SIEM; own the on-call rotation, runbooks, and IR retainer relationships
- Run tabletop exercises across Eng, Legal, and Exec; lead post-incident reviews with blameless write-ups
- Translate AI threat research - prompt injection, data poisoning, model inversion, agent hijacking - into detections and controls that ship with every release
- 10+ years in security engineering, with 3+ years owning a DevSecOps or platform-security program in a cloud-native environment (AWS strongly preferred)
- AppSec depth: shipped and operated SAST/DAST/SCA (e.g., Codacy, Semgrep, CodeQL, Snyk, Veracode, or equivalents) at production scale
- AI security: hands-on hardening of a production LLM deployment (AWS Bedrock, Azure OpenAI, Vertex AI, or equivalent) - IAM, VPC routing, guardrails, eval gating. RAG-demo experience alone does not meet the bar
- EDR/XDR + cloud security platform operator: production experience administering CrowdStrike Falcon (Insight/XDR, Cloud Security CNAPP/CSPM, Identity Protection, or Next-Gen SIEM), SentinelOne, Microsoft Defender XDR, or equivalent, including custom detection authoring
- Zero-trust access: experience standing up or operating a privileged-access broker (e.g., Teleport, StrongDM, BeyondTrust, CyberArk, HashiCorp Boundary)
- SBOM/AIBOM tooling: operated Interlynk, Anchore, Dependency-Track, or equivalent at production scale
- Vulnerability management: production experience with Trivy, Aqua, Wiz, Orca, Lacework, or equivalent across containers, IaC, and SCA
- IaC & policy-as-code: Terraform plus production policy-as-code (OPA/Rego, Checkov, Kyverno, tfsec, or equivalent) in a live pipeline
- Container & Kubernetes security: production experience with admission controllers (Kyverno, Gatekeeper), runtime visibility (Falco or equivalent), and pragmatic Kubernetes hardening (gVisor, Kata where it earns its keep)
- DLP experience: real-world sensitive-data discovery across SaaS or developer tooling, including AI-assisted environments
- Compliance fluency: has personally driven SOC 2 Type II or ISO 27001 controls to audit, and can read a control map without flinching.
- Bay Area based; able to work hybrid (3 days/week in office)
- Hands-on MCP work - design, hardening, or auth - even early-stage
- ISO 42001 implementation experience; ISO/IEC 42001 Lead Implementer or Lead Auditor certification, or comparable AI-governance leadership
- Familiarity with NIST AI RMF and the EU AI Act's high-risk system requirements
- Prompt-layer DLP and AI runtime guardrails (e.g., Nightfall, Lakera Guard, Cyberhaven, Harmonic Security, Protect AI, NVIDIA NeMo Guardrails)
- LLM eval-as-gate in CI (e.g., Promptfoo, Garak, DeepEval, Giskard) and AI red-teaming experience
- Modern PAM / zero-trust rollouts (Teleport, StrongDM) and SaaS posture management (e.g., AppOmni, Obsidian)
- Experience securing SaaS products sold into regulated sectors (utilities, energy, financial services, healthcare)
- Public signals: conference talks (fwd:cloudsec, DEF CON AI Village, BSides) or open-source contributions in CI/CD, MCP, or LLM-deployment security
- Leadership of incident response for a material security event
- Comfort working with remote, distributed engineering teams across US/India time zones
- Comprehensive Medical, Dental, and Vision Coverage: 100% coverage for employees and 80% for their spouses and children
- Health Reimbursement Account (HRA): 100% funded by AiDASH to cover medical deductibles
- 401(k) Plan: Begin contributing after three months of employment to prepare for your future. Currently, no company match is offered
- Parental Leave: Supportive parental leave with 16 weeks for primary caregivers and 4 weeks for secondary caregivers
- Generous Vacation Policy: Accrue 20 vacation days per year, plus enjoy an additional flex holiday to celebrate whatever feels most important to you!
- Winter Break: From December 25th through January 1st, we give everyone time off to recharge and enjoy time with family and friends!
We offer a competitive base pay range for this full-time position, which is between $210,000 and $270,000 per year. This range reflects the anticipated base salary for new hires. In addition, this role is also eligible for an annual performance bonus and equity. We strive to ensure our compensation packages are equitable and aligned with industry standards. Your recruiter can share more about compensation during the hiring process.
We are committed to providing an inclusive and accessible interview experience for all candidates. Please let us know if you require any accommodation during the interview process, and we will make every effort to meet your needs. Read our Privacy Policy here:
Vacancy posted 16 hours ago
Similar jobs that could be interesting for youBased on the Principal / Staff Security Engineer - AI Platform & DevSecOps in Palo Alto, CA vacancy
- ...Principal / Staff Security Engineer - AI Platform & DevSecOps Palo Alto, California, United States AiDASH is an enterprise AI company and the leading provider of vegetation risk intelligence for electric utilities. Powered by proprietary VegetationAI™ technology,...PrincipalRemote workShift work
$280k - $350k
...oriented research lab of top AI researchers and engineers, developing best-in-class... ...realtime orchestration platform optimized for thousands... ...Join our team as a Staff / Principal Platform Engineer and take... ...end ownership of building, securing, and scaling our AI products...PrincipalFull timeWork at officeRelocation$229k - $314.8k
...seeking an exceptional and strategic Sr. Staff Security Engineer, Incident Response to join our Incident... ...data. We leverage Databricks' own platform for near-real-time log analytics, alerting... ...analysis tools. Skilled in leveraging AI and automation technologies to enhance...SuggestedFor contractorsRemote workWorldwide$140.6k - $175.8k
...and a desire to protect it for future generations. Role Summary As a Security Engineer at Rivian, you will spearhead the adversarial evaluation of our AI-enabled features and internal platforms. This role will operate across Offensive Security, Secure Architecture,...SuggestedFull timeContract workTemporary workPart timeLocal areaShift work$189k - $274k
...accessible for all. We're searching for a Staff Security Engineer to join our Enterprise Security... ...designing, building, and owning the platforms, integrations, and automation that... ...management. Familiarity with securing AI/ML platforms or applications built on...SuggestedWork at officeLocal area3 days per weekEarly shift$188k - $275k
...Staff Security Engineer, Vulnerability Management Livingston, NJ / New York,... ...is The Essential Cloud for AI™. Built for pioneers by pioneers, CoreWeave delivers a platform of technology, tools, and teams... ...) Strong DevOps, DevSecOps, or SRE background with deep...Permanent employmentTemporary workCasual workWork at officeRemote workFlexible hours$204.25k - $285k
...shape the future of cloud platform engineering. As a Principal Software Engineer, you'll... ...platforms that power our data and AI initiatives. You'll... ...deliver solutions that are secure, reliable, and scalable.... ...shift-left methodologies, and DevSecOps processes. Strong...PrincipalWork at officeShift work- Senior/Staff Security Engineer About Zettabyte At Zettabyte , we’re building the infrastructure layer for the AI-first world. Our mission is to make AI compute ubiquitous, seamless,... ...t a support function here—it’s a core platform capability . Why this role exists Zettabyte...
$245k - $306.5k
...Enterprise Security Architect Box (NYSE:BOX) is the... ...Management. Our platform enables organizations... ...workflows with enterprise AI. We help companies thrive... ...reducing risk. As a Staff Engineer, you will operate with... ...CI/CD pipelines, and DevSecOps practices ~ Understanding...Live inWork at officeImmediate startShift work3 days per week$240k - $280k
Founded in 2017, Obsidian Security was created to close a critical... ...modern business happens—platforms like Microsoft 365,... ...secured—in the era of agentic AI. Today, Obsidian is... ...future of SaaS security! Staff Enterprise Security Engineer Overview We are seeking...Work from homeFlexible hours- ...is uncharted. By combining our expertise across connectivity, AI, security and more, we'll map a new way forward. Working together, we'll... ...sustainable for everyone. Role Summary: As the Product Security Engineer, you will work closely with the product security organization,...Full timeContract work
- ATX Venture Partners seeks a Principal Engineer to drive technology initiatives and create scalable solutions. You'll develop systems in a highly... ...both front-end and back-end technologies, particularly in AI domains. The ideal candidate has over 10 years of experience in...Principal
- A leading financial institution is seeking a Senior Principal Software Engineer to provide engineering expertise within the Commercial & Investment... .... The ideal candidate will have extensive experience in AI/ML engineering, a strong track record in leading technical...Principal
- ...Principal Software Engineer - Credit Card Core Platforms Brazil, Belo Horizonte; Brazil, Campinas; Brazil, Rio de Janeiro... ...Palo Alto; USA, Washington DC Sr Staff Software Engineer - CC Core... ...transformation: leveraging Generative AI to automate complex operational tasks...Principal
$180k
...Security Engineer - Platform Security Palo Alto, CA About XAI XAI's mission is to create AI systems that can accurately understand the universe and aid humanity in its pursuit of knowledge. Our team is small, highly motivated, and focused on engineering excellence...Permanent employmentTemporary work$220.5k - $300k
SpaceX is looking for a Principal Security Software Engineer for its Starshield program in Palo Alto, CA. This role involves leading the development of security-focused AI agents and automating security efforts while ensuring safe integration of AI systems. Required qualifications...Principal$261.5k - $353.5k
Intuit Inc. is looking for a Principal Software Engineer in Mountain View, California, to lead the technology... ...and architecture for its Fintech Risk Platform. This critical role requires expertise... ...distributed systems, and leveraging AI/ML for risk intelligence. The ideal...Principal$220k - $300k
...MTS - Backend Engineer (Principal/Staff) This role is based in Palo... ...a large-scale SaaS platform at an early-stage company... ...the Application Security platform for the software... ...written by humans or AI, and whether it's 40-... ...with AppSec, DevSecOps, or software supply chain...Principal$151.5k - $245.03k
...Integrity, and Inclusion. We weave AI into the fabric of everything... ...Job Summary As a Staff InfoSec Engineer, you will design, implement, and automate scalable security solutions for multi-cloud environments... .... Solid understanding of DevSecOps principles, CI/CD pipelines,...Full timeWork at officeVisa sponsorshipWork visa$260k - $300k
...Founded in 2017, Obsidian Security was created to close a critical... ...modern business happens-platforms like Microsoft 365,... ...secured-in the era of agentic AI. Today, Obsidian... ...future of SaaS security! Principal Product Security Engineer Position Overview...PrincipalWork from homeFlexible hours$130k - $260k
Geico is seeking a Senior Staff Engineer to enhance our software engineering efforts. This pivotal role involves architecting scalable infrastructure... ...and mentoring engineering teams while applying cutting-edge AI solutions. The ideal candidate should have over 10 years of...$210k - $295k
...ultimate goal of enabling human life on Mars. PRINCIPAL SOFTWARE ENGINEER (PLATFORM TEAM) The Platform Team builds the foundational tooling and security infrastructure that empowers every team at SpaceX to harness AI effectively. This team creates secure, scalable...PrincipalPermanent employmentTemporary work$127.6k - $206.53k
...Integrity, and Inclusion. We weave AI into the fabric of... ...The Team Information Security - We're not your ordinary Information... .... Job Summary As a Staff Network Security Engineer on our Enterprise Security... ..., firewalls, and cloud platforms to design secure, scalable...Full timeWork at officeVisa sponsorshipWork visa- ...About Inworld Inworld is a product-oriented research lab of top AI researchers and engineers, developing best-in-class realtime multimodal models and the only realtime orchestration platform optimized for thousands of queries per second. We’ve raised more than $12...PrincipalFull timeWork at officeRelocation package
$220.5k - $298.5k
Intuit Inc. in Mountain View is seeking a Senior Staff Machine Learning Engineer to drive advanced AI research and innovation for the Intuit Business Platform. This role requires deep expertise in Generative AI and related fields, with a focus on prototyping and building...$220.5k - $300k
...with the ultimate goal of enabling human life on Mars. PRINCIPAL SECURITY SOFTWARE ENGINEER, APPLIED COMPUTING (STARSHIELD) Starshield leverages... ...Principal Security Software Engineer, you will leverage AI to automate security-related efforts and ensure safe AI integration...PrincipalPermanent employmentTemporary workImmediate startFlexible hoursWeekend work- Google Inc. is looking for a passionate Senior Security Engineer specializing in Google Photos AI Security. You will develop security strategies, conduct threat assessments, and collaborate with teams to enhance user security. This role offers the chance to work on impactful...
$147k - $237.5k
...Software Engineer At Palo Alto Networks®, we're united by a shared... ...Integrity, and Inclusion. We weave AI into the fabric of everything... ...Vulnerability Experience Platform team is expanding, and we're looking... ...and remediating the posture security problems (vulnerabilities,...PrincipalFull timeWork at office$1,000 - $2,030 per month
...and decrease delivery headaches. What you'll do As a Staff Backend Engineer on Integrations, you will architect the systems that... ...middleware" that allows a menu update to propagate to 50+ external platforms instantly, or an order from an external source to inject...Full timeTemporary workWork at officeFlexible hours$188k - $275k
...Staff Security Engineer, PKI & Secrets Livingston, NJ / New York, NY / Sunnyvale, CA / Bellevue, WA/ San Francisco... ...CA CoreWeave is The Essential Cloud for AI™. Built for pioneers by pioneers, CoreWeave delivers a platform of technology, tools, and teams that enables...Temporary workCasual workWork at officeRemote workFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Principal / Staff Security Engineer - AI Platform & DevSecOps. Be the first to apply!
Related searches
- director data engineering Palo Alto, CA
- senior civil engineer project manager Palo Alto, CA
- principal cloud engineer Palo Alto, CA
- engineering director Palo Alto, CA
- principal infrastructure engineer Palo Alto, CA
- principal network engineer Palo Alto, CA
- chief engineer Palo Alto, CA
- data center chief engineer Palo Alto, CA
- principal data engineer Palo Alto, CA
- principal developer Palo Alto, CA

