About the Role
Cohere is the leading security-first enterprise AI company, building cutting-edge foundation AI models and end-to-end products to solve real-world business problems. They are training and deploying frontier models for enterprises, contributing to the widespread adoption of AI. The team consists of passionate researchers, engineers, and designers focused on increasing model capabilities and customer value. Headquartered in Toronto, Cohere has key offices globally. Enterprises entrust Cohere with sensitive data and integrate models into critical workflows, necessitating advanced security solutions. This role addresses industry challenges like authorization for agent actions, containment of tools consuming untrusted input, and tenant boundary integrity with steerable models. The established security playbooks are insufficient. Cohere is hiring a Senior Product Security Engineer to tackle these problems alongside product engineers. This involves architecture and code reviews, threat modeling, testing, and developing security defaults. This is a hands-on engineering role, not advisory.
Responsibilities
- Lead security reviews. Review architecture, code, and security-sensitive changes. Identify both individual vulnerabilities and the recurring design patterns behind them.
- Secure AI-powered products. Evaluate risks such as prompt injection, unsafe tool use, identity and delegation failures, excessive agency, data exposure, tenant isolation, and sandbox escapes.
- Threat model new capabilities. Identify trust boundaries, abuse cases, and high-impact failure modes before implementation. Translate findings into practical, prioritized mitigations.
- Perform hands-on testing. Investigate suspected vulnerabilities, develop proofs of concept, assess exploitability and impact, and partner with engineers through remediation.
- Build scalable guardrails. Develop secure defaults, approved patterns, reusable controls, review requirements, and automated checks that reduce recurring risks.
- Strengthen engineering capability. Pair with engineers, document practical guidance, and help product teams develop durable security expertise.
- Influence risk decisions. Explain technical findings, business impact, and remediation options clearly to engineers, product leaders, and executives.
Requirements
- Strong software engineering fundamentals and can independently understand, test, and contribute fixes to production codebases.
- Proficient in at least one of Python, Go, or TypeScript.
- Led security reviews or threat models for complex production systems and can point to meaningful design or risk improvements that resulted.
- Understand common vulnerability classes and their underlying design failures, including injection, authorization flaws, IDOR, SSRF, unsafe deserialization, race conditions, cryptographic misuse, and software supply-chain risks.
- Understand modern application architecture, including web applications, APIs, OAuth/OIDC, cloud platforms, containers, Kubernetes, and CI/CD systems.
- Can reason rigorously about untrusted input, authorization, isolation, identity, delegation, and data boundaries.
- Driven security improvements involving multiple engineering teams, including situations where influence mattered more than authority.
- Communicate clearly with both technical and non-technical audiences.
Qualifications
- Direct experience with agentic AI systems is valuable but not required.
- Experience building or operating security tooling such as SAST, DAST, SCA, custom linters, or policy-as-code.
- Experience securing multi-tenant SaaS, enterprise software, or systems that process sensitive customer data.
- Offensive security experience through penetration testing, red teaming or security research.
- Experience operating or participating in a vulnerability disclosure or bug bounty program.
- Contributions to open-source security projects, published research, conference talks, or credited vulnerability discoveries.
Benefits
- A weekly lunch stipend of $75/£75 or equivalent in your local currency for lunch.
- Full health and dental benefits, including a separate budget for mental health.
- RRSP matching, 401K, Pension Scheme.
- 100% Parental Leave top-up for up to 6 months, for either parent.
- Annual enrichment benefits: Arts & culture, fitness/wellness, quality time, and a workspace improvement credit. Education & learning stipend for conferences, courses, and coaching.
- 6 weeks of paid vacation (30 working days!)
- Budget for traveling to other offices if you are remote, plus an annual company offsite.
- Daily lunch program, plenty of snacks, and regular community and social events (for those in the office).
- Co-working benefit (for those not near an office).
- $500 home office stipend.