Senior Security Engineer
thoughtspotPhoenix (AZ)
About the role
ThoughtSpot is a Data & AI platform that helps companies turn data into enterprise advantage. We're Gartner MQ leaders with more than 1,000 customers globally and offices in Mountain View, Chicago, London, Bangalore, Sydney, and Tokyo. In-Office at ThoughtSpot
Spotters are expected in-office 3+ days per week to be part of the energy of their local team. Momentum compounds when we're in the room together with faster decisions, sharper problem-solving, and the kind of peer learning that doesn't happen over a screen. Being in-office is our default way of working, with flexibility available where it's genuinely needed. About ThoughtSpot
The world’s most innovative companies turn to ThoughtSpot’s AI-Powered Analytics to put data in the hands of everyone, from the C-suite to the frontline. With simple, natural language search and AI, anyone can ask questions, discover insights, and act with confidence. Unlike legacy tools that sacrifice performance for complexity, ThoughtSpot is intuitively designed for every business user while being built to handle the most complex, large-scale data, wherever it resides. This unique combination of speed and simplicity is why enterprise leaders trust ThoughtSpot to transform decision-making into a truly data-driven culture. At ThoughtSpot, we’re a curious, data-driven bunch. We believe the world works better when everyone has access to facts. That’s why we build products that make asking and answering data questions as natural as having a conversation. Mandatory and Required Skills for All ThoughtSpot Roles
Spotters are expected to demonstrate AI literacy and workflow integration to include to ability to: Comfortably and confidently integrate artificial intelligence into their daily workflow to increase productivity and quality.
Hands-on experience to leverage AI tools (industry-leading LLMs) to increase productivity, automate routine tasks, and improve work quality.
Speak to the experience of using AI for research, content creation, and document summarization while maintaining ownership of judgment and final decisions.
Write effective prompts to get the most accurate and creative results from AI tools. Spotters are expected to exemplify these key traits and AI Mindset: Curiosity in exploring new AI tools
Adaptability to quickly learn and implement new, emerging AI technologies
Critical thinking to know when to identify when AI should be used versus when human judgement is necessary This combination of curiosity, adaptability, and discernment defines the AI mindset, and it’s required for every role at ThoughtSpot. AI Mindset for All Spotters
At ThoughtSpot, we believe AI is a necessary and essential part of how we work. Every role, across every team, is expected to be fluent and comfortable with using AI to do their best work. All Spotters are expected to experiment with ThoughtSpot’s AI tools (like Spotter and SpotterViz) and leading industry LLMs to streamline workflows, enhance output, and uncover new insights. Whether drafting content, analyzing data, or summarizing documents, AI is a daily partner. We value curiosity, openness to learning, and thoughtful application of AI to create real value. Training and resources are provided so every Spotter can confidently create with AI.ThoughtSpot for All
At ThoughtSpot, diverse teams build better products. Complex data problems need many perspectives, not just one. We welcome different backgrounds, identities, and experiences, and we work to create a place where everyone can be themselves and do their best work. What Makes ThoughtSpot a Great Place to Work?
ThoughtSpot is the Agentic Analytics Platform that empowers every enterprise to transform insights into action, on a mission to make the world more fact driven. We hire people with unique identities, backgrounds, and perspectives - this balance-for-the-better philosophy is key to our success. When paired with our culture of Trust, Customer Obsession, Innovation and Intensity, ThoughtSpot cultivates a respectful culture that pushes norms to create world-class products.
The Role:
We're looking for a Security Engineer to join our AI Platform Security team. It is a high-ownership, low-oversight role for an application/product security generalist who has already done the work and is ready to set direction rather than follow it. You'll own security outcomes for a portfolio of products, define how security reviews and standards operate across the organization, and build the tooling and programs that let a lean team cover a large surface area. We are a lean, high-trust team. You'll make real risk calls, push back on engineering leadership when the data supports it, and be accountable for the areas you own while helping to shape how this team operates as it scales.
What You'll Do:
Own end-to-end security for an assigned portfolio of products: design reviews, threat modeling, risk acceptance, and driving high-severity findings to closure
Set technical direction for your program areas: define the review bar, standards, checklists, and intake processes other engineers follow
Lead vulnerability management and the bug bounty program: complex triage, escalation, researcher relations, SLA ownership, and program evolution
Design and build security automation and internal tooling that removes manual toil and scales coverage beyond headcount
Drive shift-left adoption across the SDLC through pipeline gates, guardrails, paved-path patterns, and developer enablement
Lead the team's AI/LLM security practice: assessment methodology, testing approach, and applied frameworks for agentic and model-backed features
Communicate risk and program health to engineering and executive leadership through metrics, reporting, and clear written narratives Who We're Looking For:
Experience in security engineering, application security, offensive security, or a closely related technical discipline
Deep, demonstrated knowledge of vulnerability classes and exploitation: injection, authentication and session flaws, access control, deserialization, SSRF, and their real-world variants
Track record of owning a security program area independently and driving cross-functional remediation without formal authority
Experience threat modeling non-trivial systems and translating findings into decisions engineering teams will actually act on
Excellent written communication. You will produce standards, risk narratives, executive reporting, and researcher-facing correspondence
Comfort operating with ambiguity and building structure where none exists yet
Preferred:
Experience running or substantially maturing a bug bounty or vulnerability disclosure program
Hands-on depth with security tooling such as Snyk, Burp Suite, DAST, or SAST platforms, including tuning and integration rather than just usage
Demonstrated ability to build security automation or internal tooling used by others
Applied understanding of AI/LLM security risks: prompt injection, insecure tool use, context and data leakage, model supply chain
Prior mentorship, tech lead, or team lead experience
Bug bounty participation as a researcher, published research, or CVE credit
Before you apply
Applying takes about a minute. These four things decide how fast it moves after that.
Your profile is current
It's what we read first. Occupations, seniority and locations matter more than a long history.
Two examples you can talk through
Not a portfolio — just two pieces of work where you can explain the decisions and what you'd change.
A number in mind
What you're on now and what would make you move. We negotiate better when we know both.
Your notice period
Employers plan around it, and it's the question that stalls offers most often.
Once you apply, someone reads it and calls you before anything reaches the employer — usually within two working days.
More like this
