About this role.
Reddit is seeking a senior security engineer to secure AI-powered products, LLM integrations, agentic workflows, and the surrounding tool and retrieval ecosystems. The role blends application-security reviews and threat modeling with hands-on development of reusable controls such as guardrails, policy checks, scanners, sandboxes, and enforcement points. The engineer will partner closely with product, platform, infrastructure, privacy, trust and safety, and machine-learning teams to prevent issues including prompt injection, tool misuse, data leakage, and unsafe code generation. Success requires strong product-security judgment, backend engineering capability, and the ability to convert recurring risks into scalable developer-friendly security platforms.
Role DNA
A quick view of the complexity, pace, ownership and collaboration implied by the job description.
Job Complexity
5/5Pace & Pressure
4/5Autonomy Level
5/5Communication Load
5/5Salary analysis
Estimated compensation compared with the broader US market for similar roles.
Core skills
Skills and capabilities most closely associated with this opportunity.
Sample interview questions
I would map assets, actors, trust boundaries, data flows, and tool permissions from user input through retrieval, model context, tool invocation, and output rendering. I would prioritize threats such as prompt injection, retrieval poisoning, excessive permissions, data exfiltration, unsafe actions, and audit gaps, then implement layered mitigations including least-privilege identities, scoped tools, input and output controls, approval gates, sandboxing, and monitoring.
I would first identify the common failure mode and the point in the development or runtime workflow where a control can be applied consistently. I would build a reusable primitive, such as a policy library, CI check, gateway, registry, or sandbox, provide safe defaults and clear remediation guidance, then measure adoption and reductions in recurring findings.
I would block when the risk enables material unauthorized access, sensitive-data exposure, irreversible harmful actions, or lacks sufficient compensating controls and monitoring. I would clearly communicate the exploit path and business impact, propose the minimum viable mitigations, and distinguish launch-blocking issues from risks that can be accepted with explicit ownership and a dated remediation plan.
I would treat all retrieved and third-party content as untrusted data rather than instructions. Controls would include separating instructions from content, limiting tool capabilities, enforcing structured tool calls and authorization checks outside the model, filtering or classifying risky content, requiring confirmation for sensitive actions, and logging attempted policy bypasses for detection and evaluation.
A successful control is reliable, easy to adopt, accurate enough to preserve developer trust, and integrated into existing workflows such as CI/CD, service templates, or runtime platforms. I would pair enforcement with actionable findings, documented paved paths, ownership clarity, feedback loops, and metrics such as adoption, false-positive rate, remediation time, and prevented incidents.
Reddit is a community of communities. It’s built on shared interests, passion, and trust, and is home to the most open and authentic conversations on the internet. Every day, Reddit users submit, vote, and comment on the topics they care most about. With 100,000+ active communities and approximately 130 million daily active unique visitors, Reddit is one of the internet’s largest sources of information. For more information, visit www.redditinc.com.
About The Role
Reddit is a community of communities. It is built on shared interests, passion, and trust and is home to some of the most open and authentic conversations on the internet. Every day, Reddit users submit, vote, and comment on the topics they care most about.
Reddit is hiring a Senior Security Engineer, AI Security to help teams build and ship AI-powered products securely. This role combines product security judgment with hands-on engineering to secure the systems, tools, and workflows behind Reddit’s AI efforts.
You will review AI-powered product designs, threat model LLM and agentic workflows, and build reusable security primitives that make secure AI development easier for teams across Reddit. This is not an MLE role, but you should be comfortable reasoning about how AI systems fail, how agents use tools, and how security controls fit into inference, retrieval, tool-use, and execution paths.
The best candidates combine practical application security judgment with strong builder instincts. They can identify risks before launch, then turn repeated findings into guardrails, scanners, registries, sandboxes, libraries, policy checks, or platform controls that scale beyond one product team.
What You’ll Do
- Review and threat model AI-powered product features, LLM integrations, agentic workflows, MCP servers, tools, plugins, retrieval systems, model outputs, and internal AI tools before launch.
- Build reusable AI security primitives such as guardrails, scanners, policy checks, tool-use controls, registries, sandboxes, libraries, and workflow-native enforcement points.
- Design security tooling that can sit in the inference, retrieval, or execution path to detect and prevent prompt injection, jailbreaks, tool misuse, data leakage, unsafe code generation, and suspicious agent behavior.
- Partner with teams building products and platforms with AI to define practical security controls that fit how they design, build, and ship.
- Proactively find, fix, and prevent AI security issues, while making any required product or engineering changes clear and low-friction for partner teams.
- Turn one-off AI security issues into systemic fixes, paved paths, measurable controls, and reusable guidance.
What We’re Looking For
- 5+ years of experience in product security, application security, software security, security engineering, backend engineering, or security platform engineering.
- Strong application security fundamentals, including secure design review, threat modeling, code review, vulnerability prioritization, and practical remediation.
- Experience in building reliable backend services.
- Hands-on experience building security automation, developer tooling, libraries, infrastructure, or platform controls.
- Familiarity with AI, LLM, or agentic system risks such as prompt injection, jailbreaks, insecure tool use, tool poisoning, data leakage, unsafe model outputs, and abuse of AI-assisted workflows.
- Ability to reason across trust boundaries, including user input, model context, retrieval systems, backend services, tool calls, MCP servers, third-party integrations, sandboxed execution, logs, and frontend rendering.
- Practical understanding of infrastructure security concepts such as identity, authorization, network boundaries, secrets, cloud environments, containers, isolation, runtime policy enforcement, and least privilege.
- Strong engineering judgment about when to block launch, when to accept risk, and how to sequence practical remediations.
- Clear communication skills with the ability to explain technical security risk and business impact to engineers, product managers, and leadership.
Preferred Qualifications
- Experience securing AI/LLM products, AI-assisted development tooling, agent frameworks, MCP-style tool ecosystems, retrieval-augmented generation systems, or model-integrated workflows.
- Experience building guardrails, policy engines, secure frameworks, scanners, linters, CI/CD checks, registries, gateways, or other developer-facing security platforms.
- Familiarity with agent sandboxing, workload identity, network policy, tool permissioning, AI red teaming, or LLM evaluation.
- Experience scanning or governing AI agent components such as skills, prompts, MCP servers, tool manifests, generated code, dependencies, or model-connected workflows.
- Familiarity with machine learning systems, model evaluation, AI data flows, or data governance for AI products.
- Experience with Go, Python, JavaScript, or TypeScript.
- Experience partnering with privacy, trust and safety, infrastructure, platform, or machine learning teams.
- Hands-on experience securing distributed systems or cloud-native applications, including Kubernetes, APIs, and microservices.
- Track record of mentoring engineers or raising the security bar through guidance, tooling, or reusable patterns.
#LI-Remote
Pay Transparency:
This job posting may span more than one career level.
In addition to base salary, this job is eligible to receive equity in the form of restricted stock units, and depending on the position offered, it may also be eligible to receive a commission. Additionally, Reddit offers a wide range of benefits to U.S.-based employees, including medical, dental, and vision insurance, 401(k) program with employer match, generous time off for vacation, and parental leave. To learn more, please visit https://www.redditinc.com/careers/.
To provide greater transparency to candidates, we share base salary ranges for all US-based job postings regardless of state. We set standard base pay ranges for all roles based on function, level, and country location, benchmarked against similar stage growth companies. Final offer amounts are determined by multiple factors including, skills, depth of work experience and relevant licenses/credentials, and may vary from the amounts listed below.
The base salary range for this position is:
$190,800—$267,100 USD
In select roles and locations, the interviews will be recorded, transcribed and summarized by artificial intelligence (AI). You will have the opportunity to opt out of recording, transcription and summarization prior to any scheduled interviews.
During the interview, we will collect the following categories of personal information: Identifiers, Professional and Employment-Related Information, Sensory Information (audio/video recording), and any other categories of personal information you choose to share with us. We will use this information to evaluate your application for employment or an independent contractor role, as applicable. We will not sell your personal information or disclose it to any third party for their marketing purposes. We will delete any recording of your interview promptly after making a hiring decision. For more information about how we will handle your personal information, including our retention of it, please refer to our Candidate Privacy Policy for Potential Employees and Contractors.
Reddit is proud to be an equal opportunity employer, and is committed to building a workforce representative of the diverse communities we serve. Reddit is committed to providing reasonable accommodations for qualified individuals with disabilities and disabled veterans in our job application procedures. If, due to a disability, you need an accommodation during the interview process, please let your recruiter know.
This job listing has been manually reviewed by the Jobicy Trust & Safety Team for compliance with our posting guidelines, including verification of the company's legitimacy, accuracy of job details, clarity of remote work policy, and absence of misleading or fraudulent content.






