freehire launches on Product Hunt on 26 August.

Follow →

Senior Security Engineer, AI Incident Response

Summary

Lead Snowflake’s AI-focused security incident response, designing detection and remediation playbooks for LLM threats like prompt injection and agent hijacking across Cortex AI and Snowflake Intelligence.

At Snowflake, we are powering the era of the agentic enterprise. To usher in this new era, we seek AI-native thinkers across every function who are energized by the opportunity to reinvent how they work. You don’t just use tools; you possess an innate curiosity, treating AI as a high-trust collaborator that is core to how you solve problems and accelerate your impact. We look for low-ego individuals who thrive in dynamic and fast-moving environments and move with an experimental mindset — who rapidly test emerging capabilities to discover simpler, more powerful ways to deliver results. At Snowflake, your role isn't just to execute a function, but to help redefine the future of how work gets done.

We are hiring a Senior Security Engineer, dedicated to Product Security Incident Response. In this role, you will lead and architect Snowflake's product-integrated Incident Response strategy, with a primary focus on AI and LLM security. You'll design, plan, and drive the implementation of incident response capabilities across Snowflake's AI product surface - including Cortex AI, Cortex Agents, Snowflake Intelligence, and the data pipelines that power them.

AS A SENIOR SECURITY ENGINEER, AI INCIDENT RESPONSE AT SNOWFLAKE, YOU WILL:

  • Lead incident response for product-level security events, with deep focus on AI-specific threat vectors including prompt injection, model abuse, agent hijacking, and data exfiltration through AI workloads.

  • Integrate IR into AI product pipelines - work directly with teams shipping Cortex features, Snowflake Intelligence, and AI-powered developer experiences to embed security requirements from design through deployment.

  • Develop and codify our AI abuse response strategy - defining detection, containment, and remediation playbooks for LLM misuse, adversarial inputs, and AI-assisted attacks targeting Snowflake customers.

  • Address tech debt across the AI product stack, ensuring that new Cortex and agentic architectures meet IR readiness requirements from the ground up.

  • Represent the IR team to cloud engineering, AI platform teams, corporate security, and customer-facing business units.

  • Secure modern AI-native codebases operating across multi-cloud environments - including container-based inference services, RAG pipelines, vector stores, and agent orchestration layers.

  • Partner with world-class AI and security engineering teams, providing expert guidance on secure architecture for high-impact AI features and customer-facing AI capabilities.

  • Design and manage response capabilities built into Snowflake's AI operational infrastructure - from model serving endpoints to Cortex Search indexes and Snowpark ML pipelines.

  • Lead with data, code, and automation - build tooling that accelerates detection and response for product security incidents at Snowflake scale.

  • Drive meaningful security outcomes for the customers and enterprises trusting Snowflake with their most sensitive data and AI workloads.

OUR IDEAL SENIOR SECURITY ENGINEER WILL HAVE:

  • 5+ years of experience in information security, primarily in incident response, security engineering, or product/application security (preferred).

  • Direct experience serving as incident commander for product focused security incidents.

  • Experience leading or actively building an application or security engineering program, with a clear point of view on securing AI/ML systems.

  • Experience with threat modeling and security testing across AI attack surfaces, including prompt injection, indirect injection, model inversion, embedding extraction, and supply chain attacks on AI dependencies.

  • Familiarity with the unique data governance and security challenges introduced by LLMs, RAG architectures, and agentic systems.

  • Working knowledge of cloud-native environments (AWS, Azure, GCP) and the threat landscape specific to SaaS and AI platforms.

  • SQL proficiency, plus experience building automation and tools with common programming languages (Python preferred).

  • Strong communication skills, with the ability to translate security risk into actionable guidance for product teams.

  • Empathy for developer experience, helping AI engineers ship securely rather than slowing them down.

  • Bachelor's degree in Computer Science or a related field, or equivalent experience.

BONUS POINTS FOR THE FOLLOWING:

  • Experience securing AI/ML infrastructure, including model serving, vector databases, embedding pipelines, API gateways, and LLM-integrated application architectures.

  • Experience building agentic incident response capabilities, including skills, agents, and pipelines.

  • Understanding of current attacker TTPs, including emerging AI-specific techniques such as adversarial ML, agent manipulation, and LLM jailbreaking in enterprise contexts.

  • Familiarity with CI/CD and secure release lifecycle patterns, with an emphasis on building security into AI feature pipelines.

  • Preferred certifications: GCIA, GCIH, GCSA, GDAT, CISSP/GISP, or cloud certifications (AWS, Azure, GCP).

WHY JOIN OUR SECURITY INCIDENT RESPONSE TEAM AT SNOWFLAKE?

This is a chance to do incident response at the frontier of AI security, on products that thousands of enterprises rely on. You will work alongside strong AI and security engineering teams, shape how Snowflake responds to novel LLM and agentic threats, and build the tooling and playbooks that define response for AI-native systems. The work is high-impact and highly visible, with direct influence on the trust customers place in Snowflake's AI capabilities.

Every Snowflake employee is expected to follow the company’s confidentiality and security standards for handling sensitive data. Snowflake employees must abide by the company’s data security plan as an essential part of their duties. It is every employee's duty to keep customer information secure and confidential.

Snowflake is growing fast, and we’re scaling our team to help enable and accelerate our growth. We are looking for people who share our values, challenge ordinary thinking, and push the pace of innovation while building a future for themselves and Snowflake.

How do you want to make your impact?

For jobs located in the United States, please visit the job posting on the Snowflake Careers Site for salary and benefits information:

What this application asks

ashby

Full Name, Email, Resume, Location

  • Phone Number
  • LinkedIn Profile, if available optional
  • Will you require company sponsorship now or in the future to maintain or extend your current work authorization status?  yes / no
  • In office attendance is an essential function for this role and necessary to enable effective teamwork and collaboration. Do you currently reside within commuting distance or are you open to relocation to the local Snowflake office(s) designated in this post? yes / no
  • Additional Attachments upload · optional
  • Where have you most recently worked?
  • Have you worked at Snowflake in the past in a Full-time, Part-time, contractor or Intern capacity? yes / no
  • For Snowflake to anticipate possible immigration timelines and obligations, could you confirm you are currently authorized to work in the country to which you are applying? yes / no
  • A “U.S. person” is a citizen, legal permanent resident, or legal temporary resident (i.e., a refugee or asylee) of the United States. Which of the following best describes your “U.S. person” status? choose one
  • Due to SEC auditor independence requirements, please let us know whether you have previously worked at, or if currently working at PricewaterhouseCoopers (PwC), who is our independent auditor. choose one
  • Have you ever been directly employed by (1) any government or military entity, state-owned enterprise, or publicly-funded institution, or (2) a government contractor in a role that recommended Snowflake as part of Government procurement? yes / no
  • In any materials you submit, you may redact or remove age-identifying information such as age, date of birth, or dates of school attendance or graduation. You will not be penalized for redacting or removing this information. choose any
  • Snowflake will process your personal information in accordance with the Snowflake Candidate Privacy Notice. choose any

See also

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available