Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Security Engineer image - Rise Careers
Job details

Security Engineer

About Decagon:

Decagon is building the most advanced conversational AI agents for the enterprise. Since starting the company, we've been on a tear, winning over customers like Duolingo, Notion, Rippling, Eventbrite, Webflow, BILT and many more. Our AI agents provide a human-like customer support experience that enables enterprises to better serve their customers and efficiently manage their customer experience organizations.

We've raised $100M in total funding from Bain Capital Ventures, Accel, a16z, BOND Capital, A*, Elad Gil, and notable angels, including the founders of Box, Airtable, Rippling, Okta, Lattice, and Klaviyo.

About the Role:

We’re looking for a Security Engineer to work with the founding team on building a category-defining AI product and scale it to massive enterprises and high-growth startups alike.

In this role, you will be responsible for building and maintaining the security infrastructure that protects our AI systems and enterprise customer data. Working closely with our founding team, you'll establish security best practices and frameworks as we scale our category-defining AI product.

You will be at the forefront of LLMs and AI Agents, tackling unique challenges associated with scaling and deploying AI applications.

You may be a good fit if you:

  • Have 3+ years of experience identifying and mitigating security vulnerabilities within software applications through building security tools, code reviews, penetration testing, and security assessments

  • Take ownership of problems from start to finish and are eager to learn whatever you need to succeed

  • Are passionate about ensuring secure coding practices are integrated throughout the software development lifecycle, preventing security risks before they emerge

  • You provide security guidance to developers and other stakeholders, fostering a culture of security awareness within the organization

Even better if you:

  • Have experience red-teaming AI products

  • Have been a startup founder or an early-stage engineer

Benefits:

  • Medical, dental, and vision benefits

  • Take what you need vacation policy

  • Daily lunches, dinners and snacks in the office to keep you at your best

Decagon Glassdoor Company Review
3.9 Glassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon Glassdoor star icon
Decagon DE&I Review
No rating Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon
CEO of Decagon
Decagon CEO photo
Unknown name
Approve of CEO

Average salary estimate

$135000 / YEARLY (est.)
min
max
$120000K
$150000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Security Engineer, Decagon

At Decagon, located in the vibrant city of San Francisco, we are trailblazing the future of conversational AI agents designed specifically for enterprises. As a Security Engineer in our innovative team, you will play a pivotal role in safeguarding our cutting-edge AI technologies and the sensitive customer data of our esteemed clients like Duolingo and Notion. We are looking for someone who thrives in a fast-paced environment and is ready to take ownership of security challenges from the ground up. You will design and maintain robust security infrastructure, ensuring best practices are woven into the fabric of our development processes. Your expertise in identifying vulnerabilities through security tools, code reviews, and penetration testing will help us preemptively tackle risks before they escalate. As you work directly with our founding team, your contributions will make a direct impact on the success of our AI product and our mission to revolutionize customer support experiences. If you have a passion for fostering a culture of security awareness and are eager to learn and grow in a collaborative atmosphere, Decagon might just be the perfect place for you to shine!

Frequently Asked Questions (FAQs) for Security Engineer Role at Decagon
What are the main responsibilities of a Security Engineer at Decagon?

As a Security Engineer at Decagon, you will be primarily responsible for building and maintaining security infrastructure for our AI systems. This includes identifying and mitigating vulnerabilities, conducting penetration tests, and integrating secure coding practices throughout the software development lifecycle. You'll work closely with our founding team to establish security best practices that protect both our AI products and our enterprise customer data.

Join Rise to see the full answer
What qualifications do I need for the Security Engineer position at Decagon?

To qualify for the Security Engineer role at Decagon, you should have at least 3 years of experience in identifying and mitigating security vulnerabilities in software applications. Additionally, experience in building security tools, conducting security assessments, and a thorough understanding of secure coding practices are crucial. If you've red-teamed AI products or have startup experience, that's even better!

Join Rise to see the full answer
How does Decagon support the professional growth of its Security Engineers?

Decagon places a high value on continuous learning and professional development. As a Security Engineer, you'll have the opportunity to collaborate with industry experts, partake in training sessions, and access resources that help you stay updated with the latest security trends. Moreover, our culture encourages ownership and initiative, allowing you to explore new security practices that align with your career goals.

Join Rise to see the full answer
What is the work culture like for Security Engineers at Decagon?

The work culture at Decagon is dynamic and collaborative. As a Security Engineer, you’ll be an integral part of a passionate team that thrives on innovation. We foster an environment of open communication and idea-sharing, which empowers you to contribute meaningfully to our security initiatives and encourages a proactive approach to security awareness across the organization.

Join Rise to see the full answer
What benefits does Decagon offer to its Security Engineers?

Decagon offers a comprehensive benefits package for its Security Engineers, including medical, dental, and vision coverage, alongside a flexible vacation policy that allows you to take the time you need to recharge. You'll also enjoy daily meals and snacks in our office to keep you fueled and at your best while working on pioneering AI solutions.

Join Rise to see the full answer
Common Interview Questions for Security Engineer
How do you approach identifying vulnerabilities within software applications as a Security Engineer?

When identifying vulnerabilities, I first conduct comprehensive security assessments using both automated tools and manual code reviews. I believe in a proactive approach, regularly updating the threat landscape and applying best practices to prevent potential risks. Engaging with development teams early in the coding process ensures that secure coding practices are integrated from the start.

Join Rise to see the full answer
Can you explain a time when you successfully mitigated a critical security threat?

In my previous role, I encountered a significant vulnerability during a routine code review. I promptly collaborated with the development team to patch the issue and implemented additional security protocols to monitor similar vulnerabilities in the future. This incident highlighted the importance of continuous security assessments, and we established a practice of regular vulnerability scans moving forward.

Join Rise to see the full answer
How do you ensure secure coding practices are followed during software development?

To ensure secure coding practices, I advocate for security training sessions with developers and provide them with resources on common vulnerabilities to avoid. Additionally, I implement security checklists into the development lifecycle and encourage regular code reviews, creating a culture of awareness around security risks within the team.

Join Rise to see the full answer
What tools do you commonly use for penetration testing?

I frequently use tools like Burp Suite for web application testing, Metasploit for exploitation, and OWASP ZAP for automated vulnerability scanning. Each tool plays a crucial role in identifying weaknesses, and I also apply manual testing techniques for a comprehensive evaluation of the security posture.

Join Rise to see the full answer
Describe your experience with red-teaming AI products.

Having been involved in red-teaming, I'm familiar with simulating attacks on AI products to discover potential vulnerabilities. I work within cross-functional teams to design scenarios that challenge the inherent security of AI systems, identifying points of failure in AI decision-making processes and recommending strategies to fortify them.

Join Rise to see the full answer
How do you stay updated with the latest security trends and vulnerabilities?

I stay current by regularly reading security blogs, attending webinars, and participating in community forums focused on cybersecurity. Networking with other professionals and contributing to open-source security projects also provides insights into emerging threats and effective mitigation strategies.

Join Rise to see the full answer
What is your experience with incident response and reporting?

In previous roles, I have developed and executed incident response plans that outline protocols for various types of incidents. This includes documenting processes, conducting post-incident reviews, and refining our approach based on the lessons learned to ensure organizational resilience against future incidents.

Join Rise to see the full answer
How would you assess the security posture of a company’s software?

I would start with a thorough review of the software architecture and deployment processes, followed by vulnerability assessments and penetration tests to examine security controls. Interviews with the development teams and operations staff would inform me about their security practices and culture, helping to identify gaps and areas of improvement.

Join Rise to see the full answer
What protocols do you recommend for data protection within AI systems?

For data protection within AI systems, I recommend employing data encryption during transmission and at rest, implementing strict access controls, and utilizing anonymization techniques to protect sensitive data. Regular audits of data practices also ensure compliance with data protection regulations.

Join Rise to see the full answer
What challenges do you foresee in securing AI systems, and how would you address them?

One significant challenge is the evolving nature of AI models, which can expose new vulnerabilities. To address this, continuous monitoring and updating of security protocols is crucial. Education and training for all team members about AI-specific risks also help in maintaining a proactive security posture.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Decagon Hybrid San Francisco
Posted 9 days ago
RahrBSG Hybrid Shakopee, Minnesota
Posted 4 days ago
Photo of the Rise User
Posted 3 days ago
Photo of the Rise User
Upwork Remote Manila, Metro Manila, Philippines
Posted 7 days ago
MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, on-site
DATE POSTED
January 8, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!