SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Anyscale is building the commercial platform around Ray, an open-source distributed computing framework used by OpenAI, Uber, Spotify, and others to scale machine learning workloads. The company has raised $250+ million from top-tier investors and is growing rapidly as customers demand stronger security postures.
As Senior Product Security Engineer, you will own Anyscale's secure software development lifecycle (SSDL) and serve as engineering's security partner. Reporting to the Head of Security, you'll operate at high ownership and seniority, embedding security into how the company ships product.
Key responsibilities include:
- Design and operate a scalable SSDL that enables rather than gates engineering velocity, covering threat modeling, secure design practices, and automated scanning.
- Partner with engineering teams on security architecture and secure-by-design features from early design through implementation.
- Conduct security reviews of existing systems and new initiatives, translating findings into prioritized, actionable work.
- Own vulnerability management end-to-end: enumerate software components, map known vulnerabilities (CVE/CVSS), and produce accurate posture reporting on demand.
- Drive vulnerabilities to resolution against defined SLAs, working closely with engineering.
- Operate software composition analysis, secret scanning, and SAST tooling across product repositories; set the bar for secure-development checks.
- Mentor engineers and raise the security bar across the organization.
You bring 8+ years in product or application security with senior-level depth, ideally at a high-growth startup. You have demonstrated ownership of an SSDL at scale, including threat modeling and secure design review. You're hands-on, partnering with engineering on security features and architecture—not just reporting findings. You have deep experience with SCA, secret scanning, SAST, and secure-development tooling in real repositories. You understand software supply chain security, SBOM approaches, and how to enumerate what an organization ships. You can triage vulnerabilities using CVSS and business context, drive them to resolution, and communicate with the seniority to set direction and raise the bar.
Nice-to-have skills include experience producing vulnerability or security posture reporting for enterprise/regulated customers, familiarity with container artifact security (image scanning, signing, SBOM generation), experience building or maturing an SSDL program at scale, and background in AI/ML platforms or distributed systems.
About Anyscale
AI / Data / Infrastructure — distributed computing and AI workload platform built around Ray.