SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: CAD 154,000 - 154,000 / annual
Coinbase is seeking a Product Security Engineer to join the Application Security team within Security. This role bridges traditional penetration testing with next-generation AI-augmented offensive security, directly accelerating the ability to protect products and customers.
You will pioneer how Coinbase uses frontier AI models to scale vulnerability discovery, red team AI systems, and automate security workflows. You'll own the development of AI-driven security tooling and collaborate across Vulnerability Management, Offensive Security, and Incident Response to fundamentally shift how the organization operates.
Key responsibilities include:
- Build, deploy, and maintain custom security scanners that leverage frontier models to detect vulnerabilities at scale across Coinbase's product surface
- Lead red teaming efforts against internal AI systems, including jailbreak testing, prompt injection analysis, and tool abuse simulation
- Develop AI-driven automation for vulnerability triage, validation, and remediation workflows to accelerate bug bounty and vulnerability response pipelines
- Partner with engineering teams to prioritize, remediate, and verify fixes for critical vulnerabilities discovered through AI-augmented and manual testing
- Mentor junior security engineers on integrating AI into offensive security workflows to scale team capabilities
Required experience includes 3+ years in application security, penetration testing, or offensive security with demonstrated ability to build custom security tooling. You must have hands-on experience using LLMs or frontier models to automate security tasks, scale vulnerability research, or build security scanners. Demonstrated experience red teaming AI-based systems (prompt injection, jailbreak testing, tool abuse) is essential. Deep understanding of common vulnerability classes (OWASP Top 10, SANS Top 25) and proven track record identifying and exploiting them in production environments required. Proficiency in at least one programming language (Python, Go, or similar) with experience writing production-grade security tooling is mandatory. You should utilize generative AI responsibly, maintaining human oversight to deliver business-ready outputs and drive measurable improvements in workflow efficiency, cost, and quality.
Coinbase is a remote-first company with quarterly in-person working sessions called "surges." The company is uncompromising on its mission to increase economic freedom with a high bar and intense environment.