SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Cohere is a security-first enterprise AI company building cutting-edge foundation models and end-to-end products for businesses. As a Senior Product Security Engineer, you will work on novel security challenges specific to AI-powered systems that enterprises depend on for mission-critical workflows.
You will lead security reviews of architecture, code, and security-sensitive changes across the product organization. Your focus will be on AI-specific risks including prompt injection, unsafe tool use, identity and delegation failures, excessive agency, data exposure, tenant isolation, and sandbox escapes. You will threat model new capabilities before implementation, identifying trust boundaries and high-impact failure modes, then translate findings into practical mitigations.
This is a hands-on engineering role. You will perform security testing, develop proofs of concept, assess exploitability and impact, and partner directly with engineers through remediation. You will also build scalable guardrails—secure defaults, approved patterns, reusable controls, and automated checks—that reduce recurring risks across teams. A key part of the role is strengthening engineering capability by pairing with engineers, documenting practical guidance, and helping product teams develop durable security expertise. You will communicate technical findings, business impact, and remediation options clearly to engineers, product leaders, and executives.
Cohere is remote-friendly with offices in Toronto, London, New York City, San Francisco, Montreal, Paris, Berlin, and Seoul. The company offers a weekly lunch stipend, full health and dental benefits, RRSP/401K matching, 100% parental leave top-up for up to 6 months, 6 weeks of paid vacation, annual enrichment benefits (arts & culture, fitness, education stipend), a $500 home office stipend, and budget for traveling to other offices if remote.
REQUIREMENTS:
- Strong software engineering fundamentals; ability to independently understand, test, and contribute fixes to production codebases
- Proficiency in at least one of: Python, Go, or TypeScript
- Demonstrated experience leading security reviews or threat models for complex production systems with measurable design or risk improvements
- Understanding of common vulnerability classes and their underlying design failures: injection, authorization flaws, IDOR, SSRF, unsafe deserialization, race conditions, cryptographic misuse, software supply-chain risks
- Knowledge of modern application architecture: web applications, APIs, OAuth/OIDC, cloud platforms, containers, Kubernetes, CI/CD systems
- Ability to reason rigorously about untrusted input, authorization, isolation, identity, delegation, and data boundaries
- Track record of driving security improvements across multiple engineering teams, demonstrating influence without formal authority
- Clear communication with both technical and non-technical audiences
NICE TO HAVE:
- Experience building or operating security tooling (SAST, DAST, SCA, custom linters, policy-as-code)
- Experience securing multi-tenant SaaS, enterprise software, or systems processing sensitive customer data
- Offensive security experience (penetration testing, red teaming, security research)
- Experience operating or participating in vulnerability disclosure or bug bounty programs
- Contributions to open-source security projects, published research, conference talks, or credited vulnerability discoveries
- Direct experience with agentic AI systems (valuable but not required)
About Cohere
AI / Data / Infrastructure — enterprise generative AI models and tooling for businesses.