Overview
Join the Advanced Threat Protection team within Auth0 Customer Identity as a research-focused Security Engineer. Research how attackers will use AI against identity systems, build AI-assisted defenses, and translate forward-looking threat research into protections for products, infrastructure, and customer tenants.
What you'll do
- Research and lead how to use AI to protect customer tenants proactively and during active incidents by accelerating detection, triage, and response.
- Research and build protections against novel AI attacks affecting Auth0 and its customers, including adversarial ML, prompt injection, abuse of agentic protocols, and model and data poisoning.
- Partner with identity security teams to help customers strengthen their tenant security posture through AI-assisted defenses.
- Research the emerging AI threat landscape and translate it into a forward-looking 12–24 month view of threats to protect against.
- Architect, recommend, and build tooling based on that threat research.
- Review and harden Auth0's AI security offering, identifying gaps and recommending mitigations before exploitation.
- Partner across a globally distributed product-aligned team of security engineers to turn research into shipped protections for customer tenants.
- Establish and execute a long-term engineering and threat research roadmap for Advanced Threat Protection aligned with company-wide business and security goals.
- Own high-impact security architecture designs and decisions across Auth0 and Okta Customer Identity infrastructure to support long-term threat resilience.
- Drive cross-functional security strategies and partner across engineering, product, and enterprise security leadership to influence platform-wide standards and policies.
- Coach, mentor, and level up Senior (P3) engineers and team members, fostering technical excellence, research discipline, and leadership growth.
What you'll need
- Hands-on experience with AI/ML security, attacking, defending, or both, including adversarial ML, LLM/prompt-injection attacks, agentic-system or model abuse, and an interest in using AI to build defenses.
- 8+ years of experience in security engineering.
- A proven track record of setting technical vision, driving cross-organizational initiatives, and leading architectural choices in cloud/product security.
- Demonstrated experience mentoring senior-level engineers, defining multi-quarter technical strategy, driving architectural consensus, and influencing cross-organizational security initiatives.
- Hands-on development experience sufficient to prototype tooling, build AI-powered defenses, and operationalize research.
- Working knowledge and hands-on experience with one or more of AWS and/or Azure security or Kubernetes.
- Strong knowledge of OWASP, including the OWASP Top 10 for LLM Applications, and secure coding best practices.
- A strong foundation in secure software development lifecycle best practices.
- Strong written and verbal communication skills, with the ability to turn research into clear guidance for engineering and product teams.
- Experience working with a globally distributed and remote team.
Nice to have
- Go development experience.
- Published threat research, CVEs, or conference talks in AI/ML security or identity security.
- Experience building AI/ML-powered security tooling or defensive automation in a production environment.
- Working knowledge and experience with one or more of adversarial ML, model red-teaming, or AI safety research.
- Working knowledge and experience with the AI agent / MCP ecosystem and its security implications.
- Working knowledge and experience with identity and access management.
- Working knowledge and experience with full-stack engineering.
- Working knowledge and experience with site reliability engineering.
- Working knowledge and experience with vulnerability and threat management.
- Working knowledge and experience with governance, risk and compliance.
Details
- Location: Bengaluru, India.
- The team is globally distributed, and the role works with a globally distributed and remote team.
- This role is level-agnostic, with scope, autonomy, and leadership expectations scaling with level from Senior through Staff.
- The role is not dedicated application security, code review, or compliance-focused work.
- Reactive patch and vulnerability management is not the primary function; the role focuses on getting ahead of threats.
Read the full description and apply on the company’s own careers page.