Secure software engineering craft: You have 8-10+ years of experience designing, building, or securing complex software systems, and you are comfortable working in production code with product and platform engineers
Security architecture judgment: You can look at a complex system and reason about where the permissions, data flow, or trust boundaries are likely to get weird, and help re-design it to make them better
Security product strategy: You can turn a complex security risk you see into a product design or architecture that can be built
Builder mindset: You’d rather leave behind a useful tool, test, library, or pattern than a task or project for someone else to pick up later
Experience building or securing products with tool use, retrieval, workflow automation, content writes, or complex permission boundaries
Hands-on experience with prompt-injection testing, red teaming, model behavior evaluation, or abuse-resistant application design
Experience with enterprise SaaS security models: permissions, sharing, audit logs, data residency, encryption, compliance, or customer-facing trust guarantees
Experience building developer tooling, CI checks, coding-agent workflows, MCP integrations, or internal frameworks that shape how engineers build software
Public security research, vulnerability writeups, conference talks, or open-source work related to product security or secure developer infrastructure
A NOTE ON AI
You don’t need deep AI expertise for every role, but we do expect every Notino to be intellectually curious, drawn to tinkering and discovery, and excited to use AI as a real collaborator in their work. For some roles, AI fluency is a core requirement — when that’s the case, we'll say so explicitly in the qualifications. People who thrive here don’t treat AI as a novelty. They use it to think better, and make their work easier for others to build on