CybersecurityJobs.io
← Back to all jobs

Job Description

Listen Labs is building an AI-native product where sensitive user data must stay protected by design. In this role, you will help shape secure-by-default engineering practices, guardrails for LLM-related failure modes, and the authentication, authorization, and API protections that keep multi-tenant systems dependable.

Based in San Francisco, CA (onsite), the annual salary range is USD 180,000 to 300,000. Actual compensation may vary based on skill set, experience, and work location.

What you’ll do

  • Design protections for sensitive data that are built into the product, including encryption, access boundaries, retention, and abuse resistance.
  • Validate that boundaries between tenants, roles, and studies hold up, and identify gaps before they become incidents.
  • Threat-model AI-native attack surfaces such as prompt injection, data exfiltration through model outputs, tool and agent permissions, and new failure modes introduced when LLMs are inside the trust boundary.
  • Help implement designs from the first version for authentication, authorization, and API surfaces used by both programmatic and agentic callers.
  • Build secure-by-default libraries and patterns, with SAST/DAST/SCA and secrets scanning integrated into CI, plus dependency and supply chain hygiene for fast feedback and fewer vulnerabilities reaching production.
  • Partner on reviews with engineers by examining architecture and pull requests, and frequently implement the fix yourself.
  • Close the loop by shipping the guardrail, library, pipeline check, or patch that turns review findings into durable prevention.

What we’re looking for

  • Junior-level development skills or better, with an engineering mindset that matters more than any single language.
  • Comfort working in a modern backend stack. You can read and write production code and hold your own in code review. (Listen Labs uses TypeScript and Terraform.)
  • A strong grasp of the OWASP Top 10 as real failure patterns that result from design decisions, not a checklist.
  • Ability to explain why an authorization bug happens and not only identify that it occurred.
  • Natural thinking in terms of trust boundaries, threat models, and blast radius.
  • Experience across authentication and authorization (OAuth/OIDC, sessions, RBAC), plus foundational cloud and infrastructure security, secrets management, secure API design, and common vulnerability classes in web and backend systems.
  • Interest in learning how LLM systems fail and helping define best practices in an evolving field.
  • A root-cause approach when something breaks, with an emphasis on complete solutions over partial ones.
  • Clear writing and independent work style. The team meets once per week, so you will use written communication to justify tradeoffs, explain risk to engineers, and help prioritize fixes.
  • Ownership of scoping and decisions with strong awareness of customers and their trust.

Tools you’ll use

  • TypeScript, Terraform
  • OAuth/OIDC, sessions, RBAC
  • SAST, DAST, SCA, CI, LLMs

Benefits

  • Full medical, dental, and vision, with FSA/HSA and life insurance options.
  • Meaningful equity ownership and competitive compensation aligned with the role’s impact.
  • Annual Learning Stipend for books, courses, conferences, coaching, language lessons, and similar development.
  • Annual Wellness Stipend for gym memberships, race fees, massages, ergonomic gear, and more.
  • Monthly Stipend for AI tools to support software and GPU credits for faster progress.
  • Fed, daily: a private chef serves lunch and dinner in the SF office; NYC and London teams receive a daily meal credit.
  • Flexible time off with a take-what-you-need policy.
  • Company offsites and events, including the annual holiday party.
  • As an early team member, you will own end-to-end processes from scratch and grow alongside the company.

Quick summary: You will build security into a complex AI-native product by writing production-grade protections, shipping guardrails and pipeline checks, and partnering directly with engineers to ensure authentication, authorization, and AI-specific threat models are implemented correctly from the start.

Similar Jobs