Cohere·Canada·11 сент.
Product Security Engineer, North Security
Ориентир по рынку≈ 1 093 000 – 1 953 000 ₽наша приблизительная оценка по 16 вакансиям этой роли и грейда, у работодателя вилка не указана
🏢 ОфисMiddleПолная занятость
Работа расписана подробно. Но вилки нет, про деньги придётся договариваться с нуля.
Вакансия на английскомПереведёт заголовок и описание вакансии на русский
Наша компания
Who are we? Cohere is the leading security-first enterprise AI company. We build cutting-edge foundation AI models and end-to-end products that are designed to solve real-world business problems.
О роли
We’re training and deploying frontier models for enterprises who are building AI systems. We believe that our work is instrumental to the widespread adoption of AI and we are looking for folks that want to be part of that. We obsess over what we build. Each one of us is responsible for contributing to increasing the capabilities of our models and the value they drive for our customers. Cohere is a
Чем предстоит заниматься
Lead security reviews. Review architecture, code, and security-sensitive changes. Identify both individual vulnerabilities and the recurring design patterns behind them
Secure AI-powered products. Evaluate risks such as prompt injection, unsafe tool use, identity and delegation failures, excessive agency, data exposure, tenant isolation, and sandbox escapes
Threat model new capabilities. Identify trust boundaries, abuse cases, and high-impact failure modes before implementation. Translate findings into practical, prioritized mitigations
Perform hands-on testing. Investigate suspected vulnerabilities, develop proofs of concept, assess exploitability and impact, and partner with engineers through remediation
Build scalable guardrails. Develop secure defaults, approved patterns, reusable controls, review requirements, and automated checks that reduce recurring risks
Strengthen engineering capability. Pair with engineers, document practical guidance, and help product teams develop durable security expertise
Influence risk decisions. Explain technical findings, business impact, and remediation options clearly to engineers, product leaders, and executives
Наши требования
Experience building or operating security tooling such as SAST, DAST, SCA, custom linters, or policy-as-code
Experience securing multi-tenant SaaS, enterprise software, or systems that process sensitive customer data
Offensive security experience through penetration testing, red teaming or security research
Experience operating or participating in a vulnerability disclosure or bug bounty program
Contributions to open-source security projects, published research, conference talks, or credited vulnerability discoveries
Мы предлагаем
A weekly lunch stipend of $75/£75 or equivalent in your local currency for lunch
Full health and dental benefits, including a separate budget for mental health
RRSP matching, 401K, Pension Scheme
100% Parental Leave top-up for up to 6 months, for either parent
Annual enrichment benefits
Arts & culture, fitness/wellness, quality time, and a workspace improvement credit
Education & learning stipend for conferences, courses, and coaching
6 weeks of paid vacation (30 working days!)
Budget for traveling to other offices if you are remote, plus an annual company offsite
Дополнительно
You have strong software engineering fundamentals and can independently understand, test, and contribute fixes to production codebases
You are proficient in at least one of Python, Go, or TypeScript
You have led security reviews or threat models for complex production systems and can point to meaningful design or risk improvements that resulted
You understand common vulnerability classes and their underlying design failures, including injection, authorization flaws, IDOR, SSRF, unsafe deserialization, race conditions, cryptographic misuse, and software supply-chain risks
You understand modern application architecture, including web applications, APIs, OAuth/OIDC, cloud platforms, containers, Kubernetes, and CI/CD systems
You can reason rigorously about untrusted input, authorization, isolation, identity, delegation, and data boundaries. Direct experience with agentic AI systems is valuable but not required
You have driven security improvements involving multiple engineering teams, including situations where influence mattered more than authority
You communicate clearly with both technical and non-technical audiences
Cohere is remote-friendly, but we also have offices in Toronto, London, New York City, San Francisco, Montreal, Paris, Berlin and Seoul with more opening soon
For those in the office: a daily lunch program, plenty of snacks, and regular community and social events
For those not near an office: a co-working benefit so you can work alongside others in your city
Everyone receives a $500 home office stipend to set up your workspace properly
If any of the above doesn’t line up exactly with your experience, we still encourage you to apply
We may use AI-enabled tools to screen and assess applicants against the criteria for this position. This helps our recruiters identify potentially qualified candidates, but it doesn't limit the applications our recruiters may review or consider
Beware of Scams: Cohere will never ask for payment or third-party services (e.g., CV writing) as part of our hiring process. All legitimate roles are listed on the Cohere careers page and LinkedIn only, with all communications from Cohere employees coming from an .com or @cw.cohere email alias. If jobs are viewed on other sites then please verify these through our official careers page