Product Security Engineer (AI & Platform Security) – Taiwan

TaiwanTaiwan·Taipeimid
Product Security EngineerCybersecurity
0 views0 saves0 applied

Quick Summary

Key Responsibilities

Build security features into our products, backend services, and cloud infrastructure (authentication and authorization, service-to-service identity, tenant isolation, secrets management,

Requirements Summary

Solid experience in product security or a related discipline, with a track record of shipping security improvements as code.

Technical Tools
Product Security EngineerCybersecurity

Obsidian Security is a global leader in cyber security protecting the SaaS and non-human identity layer modern enterprises run on — from Salesforce and Snowflake to the AI agents now deployed inside them. The Obsidian Security platform gives unified visibility into every human and machine identity, app, and integration across their SaaS estate, detects identity-based and supply chain attacks in real time, and enforces least-privilege access before it's exploited. Trusted by major Fortune 500 companies T-Mobile, Workday, Snowflake, and S&P Global, Obsidian ranked No. 95 on the 2025 Deloitte Technology Fast 500™, growing nearly 1000% from 2021–2024 — helping CISOs turn an unmonitored attack surface into one they can govern with confidence. Obsidian has also been recognized by Forbes as America's Best Startup Employers in 2026.

In August 2026, Obsidian raised $85 million in Series D financing led by Crescent Cove Advisors, with participation from existing investors including Greylock Partners, Menlo Ventures, Norwest Venture Partners, IVP, Wing Ventures, and GV — pushing Obsidian's valuation to $1.1 billion, crossing into unicorn status. Obsidian is using the funding to deepen its R&D in agentic AI security and extend its platform as the standard for governing what AI agents can access and do inside third-party applications.

With global momentum, a growing partner ecosystem including SentinelOne, Databricks, and Google Cloud, and fresh capital from its Series D behind it, Obsidian is scaling rapidly toward long-term growth and IPO readiness.

About the Role

~1 min read
  • Build security features into our products, backend services, and cloud infrastructure (authentication and authorization, service-to-service identity, tenant isolation, secrets management, audit logging).
  • Secure customer data across its full lifecycle (collection, processing, storage, and presentation), covering encryption, key management, tenant isolation, access control, and retention.
  • Design and secure services built on cloud-native platforms, primarily AWS and GCP (IAM, networking, storage, Kubernetes, managed services), with secure defaults and infrastructure-as-code.
  • Conduct security architecture and design reviews for new products, services, APIs, data pipelines, and infrastructure components, including those that use AI and agents.
  • Secure the AI and agent workflows in our product development, and turn the findings into concrete guardrails in code (for example, least-privilege tool access, input and output controls, and data-leakage protections).
  • Strengthen CI/CD pipelines with automated security controls, including dependency scanning, static analysis, and container scanning.
  • Lead CVE management, including exposure analysis, risk assessment, prioritization, remediation, testing, deployment, and validation. Automate it where possible.
  • Conduct code reviews and mentor engineers on secure development practices.

Requirements

~1 min read
  • Solid experience in product security or a related discipline, with a track record of shipping security improvements as code.
  • Deep knowledge of secure software development and common application security risks.
  • Strong software engineering skills in Python, Go, Java, Kotlin, TypeScript, or comparable languages.
  • Hands-on experience developing and securing applications on cloud-native services, such as AWS and/or GCP.
  • Experience securing cloud-native SaaS products, distributed systems, APIs, and microservices, including protecting sensitive data end-to-end. 
  • Practical CVE management experience across dependencies and infrastructure.
  • Strong English communication skills and the ability to collaborate across regions and time zones.
  • Experience securing AI/LLM applications or agent systems (e.g., OWASP Top 10 for LLM Applications, MCP/tool-permission models).
  • Cybersecurity or identity security product experience.
  • Software supply chain security knowledge.
  • Familiarity with OWASP, CVSS, and NIST standards.
  • Experience with compliance frameworks such as SOC 2 or ISO 27001.
  • Penetration testing or vulnerability research background.
  • Mandarin proficiency.

What We Offer

~1 min read

Our competitive benefits packages are designed to support our employees' well-being, both at work and at home.  Our US based employees enjoy:

✓Competitive compensation with equity and 401k
✓Comprehensive healthcare with dental and vision coverage
✓Flexible paid time off and paid holiday time off
✓12 weeks of new parent or family leave
✓Personal and professional development resources

Location & Eligibility

Where is the job
Taipei, Taiwan
On-site at the office
Who can apply
TW

Listing Details

Posted
October 6, 2026
First seen
October 7, 2026
Last seen
October 7, 2026

Posting Health

Days active
0
Repost count
0
Trust Level
60%
Scored at
October 7, 2026

Signal breakdown

freshnesssource trustcontent trustemployer trust
Newsletter

Stay ahead of the market

Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.

A
B
C
D
Join 12,000+ marketers

No spam. Unsubscribe at any time.

Product Security Engineer (AI & Platform Security) – Taiwan