
Senior Security Engineer (Incident Response)
Snowflake
Job description
-
We are hiring a Senior Security Engineer, dedicated to Product Security Incident Response
-
In this role, you will lead and architect Snowflake’s product-integrated Incident Response strategy, with a primary focus on AI and LLM security
-
You’ll design, plan, and drive the implementation of incident response capabilities across Snowflake’s AI product surface - including Cortex AI, Cortex Agents, Snowflake Intelligence, and the data pipelines that power them
-
Lead incident response for product-level security events, with deep focus on AI-specific threat vectors including prompt injection, model abuse, agent hijacking, and data exfiltration through AI workloads
-
Integrate IR into AI product pipelines - work directly with teams shipping Cortex features, Snowflake Intelligence, and AI-powered developer experiences to embed security requirements from design through deployment
-
Develop and codify our AI abuse response strategy - defining detection, containment, and remediation playbooks for LLM misuse, adversarial inputs, and AI-assisted attacks targeting Snowflake customers
-
Address tech debt across the AI product stack, ensuring that new Cortex and agentic architectures meet IR readiness requirements from the ground up
-
Represent the IR team to cloud engineering, AI platform teams, corporate security, and customer-facing business units
-
Secure modern AI-native codebases operating across multi-cloud environments - including container-based inference services, RAG pipelines, vector stores, and agent orchestration layers
-
Partner with world-class AI and security engineering teams, providing expert guidance on secure architecture for high-impact AI features and customer-facing AI capabilities
-
Design and manage response capabilities built into Snowflake’s AI operational infrastructure - from model serving endpoints to Cortex Search indexes and Snowpark ML pipelines
-
Lead with data, code, and automation - build tooling that accelerates detection and response for product security incidents at Snowflake scale
-
Drive meaningful security outcomes for the customers and enterprises trusting Snowflake with their most sensitive data and AI workloads
Benefits
-
Comprehensive health insurance plans
-
Health savings accounts
-
Robust retirement plans
-
Life and disability insurance
-
Weekly online lunch and learns
-
Virtual workout classes
-
Ergonomic work-from-home equipment
-
On-demand mental health and wellness programs
-
Fertility benefits and family planning resources
-
Generous time-off and various leave plans
-
Onsite and Remote Work
-
Employee discounts and pre-tax selections
-
New hire equity + Employee Stock Purchase Plan (ESPP)
-
Quarterly bonus or commission program- Strong communication skills, with the ability to translate security risk into actionable guidance for product teams
-
Empathy for developer experience, helping AI engineers ship securely rather than slowing them down
-
SQL proficiency, plus experience building automation and tools with common programming languages (Python preferred)
-
Experience leading or actively building an application or security engineering program, with a clear point of view on securing AI/ML systems
-
Direct experience serving as incident commander for product focused security incidents
-
Working knowledge of cloud-native environments (AWS, Azure, GCP) and the threat landscape specific to SaaS and AI platforms
-
5+ years of experience in information security, primarily in incident response, security engineering, or product/application security (preferred)
-
Experience with threat modeling and security testing across AI attack surfaces, including prompt injection, indirect injection, model inversion, embedding extraction, and supply chain attacks on AI dependencies
-
Bachelor’s degree in Computer Science or a related field, or equivalent experience
-
Familiarity with the unique data governance and security challenges introduced by LLMs, RAG architectures, and agentic systems
-
Experience securing AI/ML infrastructure, including model serving, vector databases, embedding pipelines, API gateways, and LLM-integrated application architectures
-
Experience building agentic incident response capabilities, including skills, agents, and pipelines
-
Familiarity with CI/CD and secure release lifecycle patterns, with an emphasis on building security into AI feature pipelines
-
Understanding of current attacker TTPs, including emerging AI-specific techniques such as adversarial ML, agent manipulation, and LLM jailbreaking in enterprise contexts
-
Preferred certifications: GCIA, GCIH, GCSA, GDAT, CISSP/GISP, or cloud certifications (AWS, Azure, GCP)