Decagon
Security Engineer
About this role
Decagon is seeking a Security Engineer to build and scale security foundations for its conversational AI platform serving enterprise customers. You'll implement security controls, develop automation tooling, and defend against AI-enabled threats while maintaining compliance standards.
What you'll do
- Implement security controls across application and infrastructure layers
- Build security tooling, automated remediation pipelines, and detection systems integrated with CI/CD
- Partner with engineering teams on authentication, secrets management, and access control design
- Create detection pipelines handling millions of daily AI agent interactions
- Support security incident response while maintaining service availability
What they're looking for
- Security engineering (3+ years)
- Application security (authentication, authorization, vulnerability assessment)
- Production-quality code development
- Cloud security fundamentals (Google Cloud preferred)
- Enterprise compliance (SOC 2, ISO 27001, GDPR)
- Static analysis tools (Semgrep, CodeQL)
- AI/ML security awareness
- Infrastructure as code (Terraform)
Benefits
- Competitive salary: $200K–$330K
- Equity offers
- Flexible vacation policy
- In-office work in downtown San Francisco
- Work with industry-leading security team
Opens the application — the Jobs AI extension fills it for you. Set up autofill
Opens the official application on the employer’s site. No login required.
Decagon
Decagon builds enterprise-grade conversational AI platforms that enable organizations to deploy AI agents for business impact. The company is hiring Strategic Solutions Engineers, Customer Engineers, Platform Engineers, and systems-focused engineers to deliver AI implementations, build internal infrastructure, and establish security practices across their growing platform.
View all jobs at DecagonLikely interview questions
- Walk us through a time you built security automation or tooling from scratch. What problem were you solving, and how did you approach the implementation?
- How have you approached securing authentication or access control systems in a production environment? What were the key design decisions?