Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
JobTailor Logo

See all jobs on JobTailor

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Cohere

Product Security Engineer

Cohere

Product Security Engineer securing Cohere’s enterprise AI products and foundation models. Reviewing architecture, threat modeling capabilities, and testing vulnerabilities across production systems.

Posted 9/11/2026full-timeRemote • 🇨🇦 CanadaMid-LevelSenior💰 CA$260,000 - CA$385,000 per yearWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in leading security reviews and threat modeling for complex production systems, with a strong foundation in software engineering and proficiency in Python, Go, or TypeScript. Capable of translating technical findings into actionable mitigations while effectively communicating with both technical and non-technical stakeholders.

Highest-signal resume keywords
Security Review LeadershipThreat ModelingPython ProficiencyWeb Application SecurityVulnerability Assessment

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Software Engineering FundamentalsThreat ModelingInjection Flaws UnderstandingAuthorization Flaws UnderstandingCryptographic Misuse UnderstandingSASTDASTCI/CD SystemsPenetration TestingVulnerability Disclosure
Soft Skills
Clear CommunicationCollaboration
Tools & Technologies
KubernetesCloud PlatformsAPIsOAuth/OIDCContainers
Industry Keywords
Multi-Tenant SaaSEnterprise SoftwareSecurity ResearchBug Bounty ProgramsOpen-Source Security Contributions

Tech Stack

Tools & technologies
CloudGoKubernetesPythonTypeScript

About the role

Key responsibilities & impact
  • Lead security reviews of architecture, code, and security-sensitive changes
  • Evaluate risks in AI-powered products, including prompt injection, unsafe tool use, identity and delegation failures, excessive agency, data exposure, tenant isolation, and sandbox escapes
  • Threat model new capabilities by identifying trust boundaries, abuse cases, and high-impact failure modes
  • Translate findings into practical, prioritized mitigations
  • Investigate suspected vulnerabilities and develop proofs of concept
  • Assess exploitability and impact and partner with engineers through remediation
  • Develop secure defaults, approved patterns, reusable controls, review requirements, and automated checks
  • Pair with engineers and document practical security guidance
  • Help product teams develop durable security expertise
  • Explain technical findings, business impact, and remediation options to engineers, product leaders, and executives

Requirements

What you’ll need
  • Strong software engineering fundamentals and ability to independently understand, test, and contribute fixes to production codebases
  • Proficiency in at least one of Python, Go, or TypeScript
  • Experience leading security reviews or threat models for complex production systems
  • Understanding of injection, authorization flaws, IDOR, SSRF, unsafe deserialization, race conditions, cryptographic misuse, and software supply-chain risks
  • Understanding of web applications, APIs, OAuth/OIDC, cloud platforms, containers, Kubernetes, and CI/CD systems
  • Ability to reason about untrusted input, authorization, isolation, identity, delegation, and data boundaries
  • Experience driving security improvements involving multiple engineering teams
  • Clear communication with technical and non-technical audiences
  • Experience with SAST, DAST, SCA, custom linters, or policy-as-code (nice to have)
  • Experience securing multi-tenant SaaS, enterprise software, or systems processing sensitive customer data (nice to have)
  • Offensive security experience through penetration testing, red teaming, or security research (nice to have)
  • Experience with vulnerability disclosure or bug bounty programs (nice to have)
  • Open-source security contributions, published research, conference talks, or credited vulnerability discoveries (nice to have)

Benefits

Comp & perks
  • A weekly lunch stipend of $75/£75 or equivalent in your local currency for lunch
  • Full health and dental benefits, including a separate budget for mental health
  • RRSP matching, 401K, Pension Scheme
  • 100% Parental Leave top-up for up to 6 months, for either parent
  • Annual enrichment benefits: arts & culture, fitness/wellness, quality time, and a workspace improvement credit
  • Education & learning stipend for conferences, courses, and coaching
  • 6 weeks of paid vacation (30 working days)
  • Budget for traveling to other offices if you are remote, plus an annual company offsite
  • Co-working benefit for those not near an office
  • $500 home office stipend
  • Daily lunch program, snacks, and regular community and social events for those in the office