bluedoor data·Job Postings API·bluedoor.sh ↗

HomeCompaniesBraintrustApplication Security Engineer

Application Security Engineer

Braintrust · San Francisco · On Site · Active · Ashby

Job facts

FieldValue
CompanyBraintrust
TitleApplication Security Engineer
Normalized title-
Department / teamEngineering / Engineering
LocationSan Francisco, CA, United States
Work modelOn Site
Employment typeFull Time
Salary-
Statusactive
ATS providerAshby
Posted / first seen / 2026-05-29
Changed / last seen2026-05-29 / 2026-06-06

Related slices

PageWhat it containsOpen
Company jobsActive postings from Braintrust.Open
Company breakdownsRole, location, ATS, and work model facets for this company.Open
ATS provider jobsActive postings observed through Ashby.Open
Provider filtered searchThe same provider as a filtered job collection.Open
City jobsActive postings in San Francisco.Open
Department jobsActive postings in Engineering.Open
Work model jobsActive On Site postings.Open
Lifecycle eventsOpen, update, close, and reopen events for this posting.Open
Original postingCanonical source or apply URL captured from the ATS.Open

Linked records

CompanyBraintrust
Source83a2cdae-40c3-4751-9876-eb52400fbe0f
ATS providerAshby

Description

About the company Braintrust is the AI observability platform. By connecting evals and observability in one workflow, Braintrust gives builders the visibility to understand how AI behaves in production and the tools to improve it. Teams at Notion, Stripe, Zapier, Vercel, and Ramp use Braintrust to compare models, test prompts, and catch regressions — turning production data into better AI with every release. About the role We're looking for an Application Security Engineer who lives in the code. Braintrust is a real-time, high-availability data platform that runs in both SaaS and self-hosted environments, with open source libraries embedded inside thousands of customer applications and a model proxy in front of OpenAI, Anthropic, Gemini, and other major model providers. This is a hands-on IC role. You'll review code, build threat models, ship paved-road libraries, and lead AI-specific security work: prompt injection, agent sandbox escapes, tool-use abuse, and the new attack surface that comes with LLM-native applications. If you reach for agentic coding tools as your default workflow and can hold your own in a design review with a backend or systems engineer, we'd love to work with you. What you'll do Drive secure design across the platform: lead threat models for new features, review architecture proposals, and partner with product and backend engineers to ship features that are secure by default Review code across our TypeScript, Python, and Go services, our open source tracing libraries, and our model proxy — and find the bugs others miss Build the paved road: authn/authz primitives, RBAC and tenancy isolation patterns, secret handling, safe data pipelines, and sandboxed code execution for user-supplied JavaScript and Python snippets Own our SAST, DAST, SCA, and secret-scanning tooling end-to-end, keeping signal-to-noise high enough that engineers actually fix what you ship Run our vulnerability management program and triage external bug bounty reports; close the loop with durable fixes, not point patches Lead AI-specific security work: prompt injection defenses, model proxy abuse detection, agent and tool-use sandboxing, data-exfiltration controls in multimodal pipelines, and security for the eval workflows our customers run Partner with our open source maintainers on the security of libraries that get embedded inside customer applications Use agentic coding workflows to scale yourself: automated code review, exploit prototyping, control validation, and IR triage Ideal candidate credentials 5+ years in application security, product security, or backend engineering with a security focus — you've shipped real code and reviewed a lot of it Strong code reading and writing skills in at least two of TypeScript/Node.js, Python, Go, or Rust Deep knowledge of common web and API vulnerability classes and the architectural patterns that prevent them — not just OWASP Top 10 trivia Track record of building secure-by-default libraries, frameworks, or services that other engineers actually adopt Hands-on experience with authn/authz design, multi-tenant data isolation, and secrets/key management at scale Comfortable with the realities of a high-availability data platform: real-time pipelines, ingestion at scale, semi-structured data, Postgres, Redis, AWS A clear point of view on AI/LLM security — prompt injection, agent abuse, tool-use sandboxing, model proxy threats — and ideally hands-on experience defending against them Daily user of agentic coding tools and excited to push the frontier of how AppSec gets done with them Clear communicator who documents decisions, writes tickets engineers want to pick up, and lifts the team's security awareness without becoming a bottleneck Bonus: prior experience with LLM red-teaming, agent sandbox research, or shipping security-focused open source libraries Benefits include Medical, dental, and vision insurance Daily lunch, snacks, and beverages Flexible time off Competitive salary and equity AI Stipend Equal opportunity Braintrust is an equal opportunity employer. All applicants will be considered for employment without attention to race, color, religion, sex, sexual orientation, gender identity, national origin, veteran or disability status.

Full job record

Job IDf09892ab1908a566bdcc29a8b6e2344e5e3ec97f
Org ID29f0bc1c-6b67-47f5-b0d0-4ffd3d02cefc
Source ID83a2cdae-40c3-4751-9876-eb52400fbe0f
Board ID83a2cdae-40c3-4751-9876-eb52400fbe0f
Providerashby
Provider Job Key0e402bde-8881-4001-988e-2e3d7b58b5b6
TitleApplication Security Engineer
Normalized Title
Statusactive
Activeyes
Location TextSan Francisco
DepartmentEngineering
TeamEngineering
Employment Typefull_time
Workplace Typeon_site
Remote Policy
CountryUnited States
RegionCA
CitySan Francisco
Salary Raw
Salary Min
Salary Max
Salary Currency
Salary Period
Source URLhttps://jobs.ashbyhq.com/Braintrust/0e402bde-8881-4001-988e-2e3d7b58b5b6
Apply URLhttps://jobs.ashbyhq.com/Braintrust/0e402bde-8881-4001-988e-2e3d7b58b5b6/application
First Seen At2026-05-29 06:24:09Z
Last Seen At2026-06-06 09:25:21Z
Last Checked At2026-06-06 09:25:21Z
Last Changed At2026-05-29 06:24:09Z
Inactive At
Source Posted At
Source Updated At
Raw Payload Uris3://job-postings-prod-raw-590183727216/raw/provider=ashby/board=Braintrust/date=2026-06-06/2026-06-06T09-25-00-318Z-0c680b0f8853b73849c45393c2606e43e89c62c5605765e516f9cad32e508b8e.json
Event Fields
{
  "content_hash": "8ce50334db393a5bbffd8aa625e8f624758a27832487b242368f6e9c85866482",
  "source_hash": "33255e0396fb0c06003ef68ad5daf4bc952c2c903dfa7c98612d9b738ba81c01",
  "last_changed_at": "2026-05-29T06:24:09.247Z",
  "active_status": "active"
}
Parsed Structured
{
  "language": "en",
  "location": {
    "raw": "San Francisco",
    "city": "San Francisco",
    "region": "CA",
    "country": "United States",
    "is_remote": false,
    "confidence": 0.75
  },
  "salary_max": null,
  "salary_min": null,
  "inferred_at": "2026-06-06T09:25:21.198Z",
  "launch_scope": {
    "reason": "english_us_canada",
    "included": true,
    "language": "en",
    "location": {
      "raw": "San Francisco",
      "city": "San Francisco",
      "region": "CA",
      "country": "United States",
      "is_remote": false,
      "confidence": 0.75
    },
    "countries": [
      "United States"
    ]
  },
  "remote_policy": null,
  "salary_period": null,
  "workplace_type": "on_site",
  "salary_currency": null
}
Extensions
{}
Native Structured
{
  "id": "0e402bde-8881-4001-988e-2e3d7b58b5b6",
  "team": "Engineering",
  "title": "Application Security Engineer",
  "jobUrl": "https://jobs.ashbyhq.com/Braintrust/0e402bde-8881-4001-988e-2e3d7b58b5b6",
  "address": null,
  "applyUrl": "https://jobs.ashbyhq.com/Braintrust/0e402bde-8881-4001-988e-2e3d7b58b5b6/application",
  "isListed": true,
  "isRemote": false,
  "location": "San Francisco",
  "updatedAt": null,
  "apiVersion": "ashby-non-user-graphql-v1",
  "department": "Engineering",
  "publishedAt": null,
  "workplaceType": "OnSite",
  "employmentType": "FullTime",
  "secondaryLocations": [
    {
      "location": "New York City"
    },
    {
      "location": "Seattle"
    }
  ]
}
Get this page with API

Rendered from the bluedoor Job Postings API. Reproduce it:

GET https://api.bluedoor.sh/job-postings/v1/jobs/f09892ab1908a566bdcc29a8b6e2344e5e3ec97f?include=descriptionJSON
GET https://api.bluedoor.sh/job-postings/v1/orgs/29f0bc1c-6b67-47f5-b0d0-4ffd3d02cefcJSON
GET https://api.bluedoor.sh/job-postings/v1/sources/83a2cdae-40c3-4751-9876-eb52400fbe0fJSON
GET https://api.bluedoor.sh/job-postings/v1/jobs/f09892ab1908a566bdcc29a8b6e2344e5e3ec97f/eventsJSON