Skip to content

Open nowPosted 17 days agoWe saw it 95 min after it went up

Staff Security Engineer [Remote-US]

Quanata12 open roles

Pay
$235,000 – $305,000 a year
Where
remote
Work mode
Remote
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowStaff Security Engineer [Remote-US]Quanata · remote
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Quanata's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.2% of postings close within 7 days. Measured by our own scanner across the market. Quanata postings stay open a median of 19 days.

Share of postings closed within
  1. 1.9%1 day
  2. 3.8%3 days
  3. 8.2%7 days
  4. 15.2%14 days
  5. 34.1%30 days
This job: posted 17 days ago

Quanata median: 19 days open

The posting

To help keep everyone safe, we encourage all applicants to pay close attention to protect themselves during their job search. When applying for a position online you are at risk of being targeted by malicious actors looking for personal data. Please be aware we will only reach out via email using the domain quanata.com. Anything that does not match those domains should be ignored and considered a security risk.

About Us

Quanata is on a mission to help ensure a better world through context-based insurance solutions. We are an exceptional, customer centered team with a passion for creating innovative technologies, digital products, and brands. We blend some of the best Silicon Valley talent and cutting-edge thinking with the long-term backing of leading insurer, State Farm.

Learn more about us and our work at quanata.com

Our Team

Quanata, LLC is an insurance technology innovation company that engineers advanced risk prediction and prevention solutions, develops risk-focused acquisition capabilities, and builds/supports a full-stack, flexible, digital & increasingly AI-native insurance platform. This helps our primary clients, State Farm and HiRoad Assurance Company, adapt to evolving market needs. Quanata, LLC is wholly owned and funded by State Farm.

As a company that prioritizes an inclusive and positive culture, we believe the core of our success is in hiring talented people — across disciplines — who want to help us make a quantifiable impact.

The Role

As a Staff Security Engineer, you’ll play a key role in securing the AI-enabled systems, applications, and platforms that power our organization. You’ll partner closely with engineering, product, infrastructure, and security teams to make security an integral part of how AI solutions are designed, built, deployed, and operated.

This is a hands-on technical leadership role for someone who is equally comfortable diving into architecture and threat models, evaluating emerging AI risks, and translating security requirements into practical engineering solutions. You’ll help secure everything from LLM applications and RAG pipelines to agentic AI workflows, third-party integrations, CI/CD pipelines, and AWS-native infrastructure.

Your impact will extend beyond AI. As a senior individual contributor, you’ll help shape our broader security strategy, establish scalable security patterns and standards, and influence technical decisions across the organization. You’ll have the autonomy to tackle complex security challenges and drive initiatives from strategy through implementation.

Your Day-to-Day

  • Partner with engineering and product teams to embed security into AI-enabled products, internal applications, APIs, services, and platforms throughout their lifecycle.
  • Lead threat modeling, security architecture reviews, and risk assessments for LLM applications, RAG pipelines, agentic workflows, MCP servers, model providers, third-party AI tools, plugins, automations, and AI-assisted development.
  • Define and implement secure AI engineering patterns, guardrails, standards, and reference architectures across identity, data protection, prompt and context handling, tool permissions, logging, monitoring, abuse prevention, and incident readiness.
  • Strengthen AWS-native infrastructure and CI/CD environments, including infrastructure-as-code, containerized workloads, secrets management, workload identity, deployment pipelines, and software supply chain controls.
  • Partner with security operations, detection engineering, incident response, and vulnerability management teams to improve AI-related detection, observability, telemetry, and response capabilities.
  • Evaluate AI applications, SaaS platforms, model providers, MCPs, agents, developer tools, and other third-party technologies for security, privacy, access, data exposure, logging, contractual, and operational risks.
  • Develop practical security guidance, training, and enablement materials that help engineering and business teams use AI safely and build secure solutions.
  • Lead cross-functional security-by-design initiatives, translate security objectives into technical requirements, influence architectural decisions, and take ownership of broader security projects and critical incident response efforts as organizational needs evolve.

About You

  • Bachelor’s degree in Computer Science, Cybersecurity, Engineering, Information Systems, or a related technical field; an equivalent combination of education and relevant experience; or equivalent relevant experience.
  • 8+ years of experience in full-stack security, product security, application security, cloud security, DevSecOps, infrastructure security, or software engineering with significant security responsibilities.
  • 5+ years of demonstrated experience working with AI, machine learning, LLM, GenAI, or AI-enabled application environments, including hands-on experience securing, assessing, building, integrating, or operating AI-enabled systems.
  • Proven experience conducting security architecture reviews, threat modeling, secure design reviews, code or configuration reviews, and risk assessments for modern applications, APIs, platforms, and distributed systems.
  • Experience evaluating and securing third-party SaaS platforms, AI tools, model providers, developer tools, APIs, integrations, and vendor-managed services.
  • Experience partnering across security operations, detection engineering, incident response, GRC, privacy, infrastructure, and product engineering teams.
  • Strong hands-on experience securing cloud-native environments, preferably AWS, including IAM, networking, logging, monitoring, secrets management, workload identity, infrastructure-as-code, and secure deployment practices.
  • Strong understanding of modern CI/CD pipelines, source control, build systems, artifact management, deployment automation, container security, software delivery workflows, and software supply chain risk.
  • Working knowledge of AI-specific security risks, including prompt injection, insecure tool use, excessive agency, data leakage, sensitive data exposure, RAG security risks, model and provider trust boundaries, plugin and MCP risks, insecure agent permissions, model extraction, model abuse, and AI supply chain concerns.
  • Ability to translate AI and cloud security risks into practical engineering requirements, compensating controls, standards, detections, and operational procedures.
  • Strong written and verbal communication skills, with the ability to explain complex technical risks, document standards, influence decisions, and drive remediation across technical and business teams.
  • Demonstrated ability to work independently, self-organize, prioritize competing risks, and lead complex cross-functional security initiatives from concept through execution.

Bonus Points

  • Experience securing agentic AI systems, MCP servers, AI agents, tool-calling or autonomous workflows, internal copilots, LLM gateways, AI assistants, or AI-enabled developer productivity tools.
  • Experience with AWS AI/ML and GenAI services such as Amazon Bedrock, SageMaker, Comprehend, Transcribe, Textract, or related AWS-native capabilities.
  • Experience securing RAG architectures, vector databases, embedding pipelines, knowledge retrieval systems, data classification workflows, and sensitive data within AI applications.
  • Experience implementing AI security guardrails such as model access controls, approved-provider patterns, prompt and context protections, DLP integrations, logging requirements, policy enforcement, and AI usage monitoring.
  • Experience with detection engineering, SIEM/SOAR platforms, cloud security posture management, vulnerability management, endpoint security, or related security operations tooling.
  • Experience developing secure software in Python, TypeScript, JavaScript, Go, Java, or similar languages.
  • Experience with Kubernetes, Docker, Terraform, GitHub Actions, GitLab CI/CD, Jenkins, or similar cloud-native and DevOps technologies.
  • Familiarity with frameworks and guidance such as the OWASP Top 10 for LLM Applications, MITRE ATLAS, NIST AI Risk Management Framework, CIS benchmarks, SOC 2, ISO 27001, or cloud security reference architectures.
  • Relevant certifications such as AWS Certified Security – Specialty, CISSP, CSSLP, CCSP, GIAC, OSCP, or other cloud, application security, AI security, or security engineering certifications.
  • Experience as a senior individual contributor influencing engineering teams, establishing security standards, and delivering security outcomes without direct management authority.

Salary: $290,000 to $400,000

*Please note that the final salary offered will be determined based on the selected candidate's skills, and experience, as well as the internal salary structure at Quanata. Our aim is to offer a competitive and equitable compensation package that reflects the candidate's expertise and contributions to our organization.

Additional Details:

  • Benefits: We provide a wide variety of health, wellness and other benefits.These include medical, dental, vision, life insurance and supplemental income plans for you and your dependents, a Headspace app subscription, monthly wellness allowance and a 401(k) Plan with a company match.
  • Work from Home Equipment: Given our virtual environment— in order to set you up for success at home, a one-time payment of $2K will be provided to cover the purchase of in-home office equipment and furniture at your discretion. Also, our teams work with MacBook Pros, which we will deliver to you fully provisioned prior to your first day.
  • Paid Time Off: All employees accrue four weeks of PTO in their first year of employment. New parents receive twelve weeks of fully paid parental leave which may be taken within one year after the birth and/or adoption of a child. The twelve weeks is applicable to both birthing and non-birthing parent.
  • Personal and Professional Development: We’re committed to investing in and helping our people grow personally and professionally. All employees receive up to $5000 each year for professional learning, continuing education and career development. All team members also receive LinkedIn Learning subscriptions and access to multiple different coaching opportunities through BetterUp.
  • Location: We are a remote-first company for most positions so you may work from anywhere you like in the U.S, excluding U.S. territories. For most positions, occasional travel may be requested or encouraged but is not required. Some positions might require travel per the job description provided to the employee. Employees based in the San Francisco Bay Area or in Providence, Rhode Island may commute to one of our local offices as desired.
  • Hours: We maintain core meeting hours from 9AM - 2PM Pacific time for collaborating with team members across all time zones.

Quanata, LLC is an equal opportunity workplace. We are committed to equal employment opportunities regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity or Veteran status. Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.

If you are a San Francisco resident, please read the City and County of San Francisco's Fair Chance Ordinance notice. https://www.sf.gov/sites/https://www.sf.gov/sites/default/files/2022-12/FCO%20poster2020_0.pdf

This role is employed by Quanata, LLC which is a separate company in the State Farm family of companies.

If you require a reasonable accommodation, please reach out to your Talent Acquisition Partner for assistance.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Quanata's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Quanata's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Quanata's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.