AI Security Engineer - Taiwan
Obsidian Security AI Security Engineer - Taiwan
Summary
Obsidian Security is hiring an AI Security Engineer in Taipei to research emerging AI and agentic threats and build the backend services, APIs, and data pipelines that secure enterprise SaaS platforms like Copilot, ChatGPT Enterprise, and Gemini. Core work spans threat modeling, detection engineering, and telemetry analysis using backend languages like Python or Go, SQL, and OAuth.
Obsidian Security is the leading SaaS security platform, trusted by global enterprises like Snowflake, T-Mobile, and Algolia. We protect 200+ organizations across North America, Europe, the Middle East, Southeast Asia, Australia, and New Zealand, including many of the world’s largest Fortune 1000 and Global 2000 companies.
Founded in 2017 and backed by top investors like Greylock, Obsidian was built to close a critical gap: securing SaaS apps where business happens—Microsoft 365, Salesforce, and hundreds more. The company does this by offering a complete SaaS security platform to reduce risk, detect and respond to threats, and prevent breaches at the source. Obsidian was built by leaders who redefined endpoint and identity security at CrowdStrike, Okta, Cylance, and Carbon Black. Now, they’re transforming how SaaS is secured.
With AI driving rapid SaaS growth and complexity, agentic AI tools gain privileged access to sensitive data through integrations, creating new risks most security tools miss. Obsidian uniquely detects anomalous OAuth token activity and manages integration risks. Major announcements are on the horizon. Recognizing that SaaS security needs to evolve, Obsidian enables growing organizations to start with a lightweight, prevention-focused browser extension and expand coverage over time.
With global momentum, a growing partner ecosystem including SentinelOne, Databricks, and Google Cloud, and a major fundraise ahead, Obsidian is scaling rapidly toward long-term growth and IPO readiness.
About the Role
AI is becoming the fastest-moving attack surface in the enterprise. Copilot, ChatGPT Enterprise, Gemini, Claude, and a growing wave of agentic tools are being connected to corporate SaaS applications faster than many security teams can evaluate them. These systems introduce broad OAuth scopes, opaque data flows, sensitive data exposure, and non-human identities that can act on behalf of employees.
Obsidian Security sits directly in the path of this shift.
As an AI Security Engineer in Taiwan, you will help define how Obsidian discovers, understands, and mitigates risks across AI and agentic platforms. You will research emerging threats, develop security and data models, and build highly available products that protect enterprise customers.
This is a hands-on role at the intersection of security research, data engineering, and product development. You will work directly with security telemetry and production systems because, in this rapidly evolving space, security judgment, data analysis, and engineering execution are inseparable.
You will collaborate closely with Security Research, Detection Engineering, Product Management, Data Platform, and Site Reliability Engineering teams across Taiwan, the US, the UK, and Australia.
What You’ll Do
- Develop deep expertise in how enterprise AI platforms—including ChatGPT Enterprise, Microsoft Copilot, Gemini, Claude, Glean, and agentic frameworks—authenticate, access data, request permissions, and interact with corporate SaaS applications.
- Research emerging AI security threats, including prompt injection, tool and agent misuse, RAG poisoning, insecure plugins, excessive agency, data leakage, over-permissioned integrations, and compromised non-human identities.
- Develop threat models for AI applications, agents, models, integrations, identities, permissions, tools, and data flows.
- Design data models that represent AI assets, identities, access relationships, permissions, activities, risks, and attack paths.
- Prototype and deliver production-grade AI security products and capabilities.
- Build backend services and APIs for AI asset discovery, security analysis, risk assessment, detection, investigation, and remediation.
- Build scalable pipelines that ingest, normalize, enrich, correlate, and analyze high-volume security telemetry.
- Write queries and analysis logic that transform raw activity and configuration data into actionable security findings.
- Develop detection rules and behavioral models for suspicious AI and agentic activity.
- Evaluate APIs, audit logs, authentication mechanisms, OAuth permissions, and security controls provided by AI platforms.
- Work with Product Management and customers to understand emerging use cases and turn ambiguous security problems into practical product capabilities.
- Partner with Detection Engineering and Security Research to validate threat hypotheses and improve detection coverage.
- Collaborate with platform and SRE teams to ensure services are secure, observable, highly available, and operationally efficient.
- Improve engineering productivity, pipeline performance, development velocity, and cloud cost efficiency.
- Contribute to technical designs, code reviews, testing strategies, operational readiness, and engineering standards.
- Share research and technical knowledge with engineering teams and help shape Obsidian’s long-term AI security strategy.
What We’re Looking For
- Strong software engineering experience building production-quality backend services, cloud-native applications, data platforms, or security products.
- Hands-on programming experience in one or more languages such as Python, Go, Java, Kotlin, or a comparable backend language.
- Experience designing and building scalable APIs, distributed systems, or data-processing pipelines.
- Strong data analysis skills and the ability to investigate complex behavior using SQL or other query languages.
- Familiarity with cloud infrastructure, SaaS platforms, identity systems, authentication, authorization, and OAuth.
- Understanding of security fundamentals, including identities, permissions, access controls, vulnerabilities, attack techniques, and risk assessment.
- Ability to translate ambiguous security risks into clear threat models, data requirements, and production capabilities.
- Strong engineering judgment across scalability, reliability, security, performance, maintainability, and cost.
- Curiosity and a willingness to rapidly learn unfamiliar AI platforms, APIs, security models, and attack techniques.
- Ability to work independently while collaborating effectively with security researchers, product managers, and engineers.
- Strong written and verbal communication skills in English.
Nice to Have
- Experience building cybersecurity, identity security, SaaS security, threat detection, SIEM, EDR, XDR, or security analytics products.
- Experience researching or developing protections for AI applications, large language models, copilots, or autonomous agents.
- Familiarity with AI security risks such as prompt injection, RAG poisoning, insecure tool use, model abuse, excessive agency, and sensitive-data disclosure.
- Experience with LLM application frameworks, agent protocols, tool integrations, vector databases, or retrieval-augmented generation systems.
- Experience working with SaaS audit logs, identity telemetry, OAuth grants, application configurations, or security events.
- Experience developing detection rules, behavioral analytics, risk models, or attack-path analysis.
- Experience with large-scale streaming or batch-processing technologies.
- Experience using machine learning or generative AI to analyze security data or automate investigations.
- Contributions to security research, open-source projects, technical publications, or responsible vulnerability disclosures.
- Experience collaborating with globally distributed engineering teams.
- Mandarin proficiency.
What Success Looks Like
- Obsidian gains deep, actionable visibility into enterprise AI applications, agents, integrations, identities, permissions, and activities.
- Emerging AI threats are translated quickly into scalable product capabilities and effective detections.
- Customers receive accurate, explainable, and actionable findings about their AI security risks.
- AI security services and data pipelines operate reliably at enterprise scale while maintaining strong cost efficiency.
- Research, product, detection, and engineering teams work through a clear and repeatable process for developing AI security capabilities.
- You help establish Obsidian as a technical leader in securing enterprise AI and agentic systems.
As published by greenhouse
First Name, Last Name, Email, Phone, Resume/CV, Cover Letter
- Preferred First Name optional
- LinkedIn Profile
- Will you now or in the future require visa sponsorship to work in the country where this role is based? choose one
- Are you based in or around Ho Chi Minh City? choose one
- Do you have relatives that currently work at Obsidian Security? choose one
