San Francisco, CA

Salary
$200,000–$230,000
Posted
Jul 24, 2026
Location
San Francisco, CA
Last confirmed open
Jul 25, 2026

What this job asks for AI summary

A security engineering role focused on owning application-level and CI/CD security for an AI gateway platform. Day-to-day work involves hunting and remediating vulnerabilities, hardening the software supply chain, and embedding security practices across development and deployment pipelines. Best suited to someone with hands-on offensive or white-hat security experience, ideally from a startup environment, with a track record of security projects or CTF participation.

Senior level · Remote · Full-time

Must have (4)
application securityCI/CD securityoffensive securityvulnerability assessment
Nice to have (3)
GitHubPythonLLMs

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

Roughly 11,700 people nationally plausibly meet what this posting asks for (information security analysts). range 3,450–17,600

Applicant volume Heavy — This req sits in a large pool with little in its requirements to thin it, and auto-apply tools fire at everything in the occupation. Applying early and leading with the rare skills below is what gets read.

What won't set you apart
vulnerability assessment45%application security40%

Most people in this occupation already list these. Still required — just not what gets you shortlisted.

What the occupation pays Median $132,021 (middle half $99,961–$167,095).

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.

Why we read it this way (6)

Location is not specified anywhere in the posting; CBSA and state fields are left blank. The role appears fully remote given the absence of any office or location requirement.

No explicit years-of-experience requirement is stated at the role level.

The posting is notably light on named technologies. The concrete tools/platforms mentioned are limited to CI/CD (as a security domain), GitHub (as a place to showcase projects), and Python/LLMs (from the company description of their product stack) — none of these are stated as hard gates in a requirements section.

Application security, CI/CD security, offensive security, and vulnerability assessment are treated as hard gates based on the 'What We're Looking For' section, which uses firm language ('Strong background', 'Demonstrated experience').

CTF wins are listed as a signal of offensive security aptitude ('Evidence of winning past CTFs') but name no specific platform or tool, so no skill entry was created.

No compensation figures are provided beyond a mention of 'competitive salary and benefits.'

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗