Security Engineer
erpmarkSeattle (WA)
About the role
Security Engineer
Location: Seattle, WA – Preferred / Sunnyvale, CA – Local Candidates Preferred
Client: Indium Technologies
Employment Type: W2 Only no c 2cRole
Overview:
We are looking for experienced Security Engineers to support Engineering Security initiatives focused on security and privacy reviews, threat modeling, and third-party AI Agent security testing. The selected candidate will work closely with Engineering, Security, Privacy, and third-party teams to identify security risks, perform hands-on assessments, and provide actionable remediation guidance.
Key Responsibilities:
Conduct security and privacy design reviews of services, applications, APIs, engineering proposals, and AI integrations. Evaluate architecture, data flows, access controls, trust boundaries, and security safeguards. Perform threat modeling for critical services and AI agents, identifying attack surfaces, threat scenarios, attack paths, mitigations, and residual risks. Conduct hands-on security testing of third-party AI agents, including: Prompt injection Tool misuse Data access and permissions Excessive agency External integrations Sensitive-data exposure Document security findings, risk assessments, supporting evidence, and practical remediation recommendations. Partner with Engineering and Security teams through remediation and validation. Develop repeatable security assessment processes, including review checklists, threat models, test cases, reporting templates, and automation workflows.
Minimum Qualifications:
3+ years of professional experience in Security Engineering, Application Security, Product Security, Offensive Security, Systems Architecture, or a related technical security field. Experience reviewing complex technical designs and identifying security risks across applications, APIs, cloud services, microservices, or distributed systems. Strong knowledge of: Threat Modeling Vulnerability Classification Risk Modeling Authentication & Authorization Least Privilege Data Protection Hands-on experience with security testing, vulnerability investigation, penetration testing, adversarial testing, or security-control validation. Strong communication skills with the ability to explain technical security findings to Engineering, Security, Privacy, and third-party stakeholders. Preferred / Good to Have Experience assessing AI/LLM agents and AI security risks. Hands-on knowledge of prompt injection, unsafe tool use, excessive agency, and AI security testing. Experience with privacy and security design reviews. Cloud security experience across AWS, Azure, or GCP.Experience with security automation using Python, Go, Bash, or similar languages. Hands-on penetration testing and vulnerability assessment across applications, APIs, cloud infrastructure, and networks. Experience identifying and validating real-world attack paths and providing actionable remediation guidance.
Note:
Candidates must be able to work on W2.Local candidates in Seattle, WA or Sunnyvale, CA are strongly preferred.
Before you apply
Applying takes about a minute. These four things decide how fast it moves after that.
Your profile is current
It's what we read first. Occupations, seniority and locations matter more than a long history.
Two examples you can talk through
Not a portfolio — just two pieces of work where you can explain the decisions and what you'd change.
A number in mind
What you're on now and what would make you move. We negotiate better when we know both.
Your notice period
Employers plan around it, and it's the question that stalls offers most often.
Once you apply, someone reads it and calls you before anything reaches the employer — usually within two working days.
More like this
