Senior Product Security Engineer
Summary
Builds and maintains security features (key rotation, RBAC, API credentials) for LanceDB’s open-source vector database and AI data platform, using Rust/C++ and appsec best practices.
About LanceDB
AI advances at the speed of its research, and research moves at the speed of its data. LanceDB is the AI-native Multimodal Lakehouse: one system where a researcher curates petabytes of video, audio, and every signal derived from them with a few lines of Python, and the next training run starts as fast as the next idea. Customers like Runway, Midjourney, and Netflix build the future of AI on LanceDB, from frontier and world models to robots and autonomous vehicles.
About the Role
Our first product security-focused engineer
Takes high-level direction (e.g., “identify top five security-related gaps for AX”) and drives to results
Success looks like a LanceDB platform that follows security-related best practices, and an ongoing partnership with other engineers to continuously enhance our security posture in all areas of the product
What You’ll Do
Drive new security-related functionality such as key rotation, user-managed API credentials, RBAC, and the like
Select, deploy and tune security tooling across all relevant repos and environments, ensuring full coverage
Apply relevant industry trends, best practices, and specific vulnerabilities to our product
What We’re Looking For
8+ years as a software engineer, with a significant portion of that time working on appsec-related work
Experience working on large-scale data platforms (e.g., databases, data infra, ML/AI systems), including work on concurrency and multitenancy
Demonstrated ability to code in Rust and/or C++
Experience building encryption, authentication, and/or authorization features for shipping products at high throughput
Previous experience working at an early-stage startup
Demonstrated ownership of ambiguous projects with minimal guidance
Strong written and verbal communication (can drive alignment across teams)
Comfortable using data (metrics, experiments, usage) to guide decisions
Experience contributing to or working with open source communities
Please apply for this role only if you meet all of the above qualifications, and agree with the day-to-day responsibilities. Of particular note: qualified candidates for this role will have day-to-day coding responsibilities - this is an appsec and devsecops role, not an infosec or platform security role.
Skills
As published by ashby · 4 questions
Basics
Name, Email, Resume, Location
Short answers (1)
Pick from a list (3)
- Are you legally authorized to work in the United States for any employer?
- Will you now or in the future require employer sponsorship for employment auhorization (e.g., H-1B visa sponsorship)?
- Are you located in the United States/Canada?
Y Combinator 