高级安全工程师
Senior Security Engineer
我们是谁?
Cohere 是一家以安全为首要任务的企业人工智能公司。我们构建前沿的基础人工智能模型和端到端产品,旨在解决现实世界中的业务问题。
我们正在为正在构建人工智能系统的公司训练和部署前沿模型。我们认为我们的工作对人工智能的广泛应用至关重要,我们正在寻找希望成为其中一员的人才。
我们对所构建的东西精益求精。我们每个人都负责提升模型的能力以及为客户创造的价值。Cohere 是一个由研究人员、工程师、设计师等组成的团队,他们对各自的专业充满热情。
我们是一家总部位于多伦多的全球科技公司,在伦敦、纽约市、旧金山、蒙特利尔、巴黎、柏林和首尔设有主要办公室。加入我们吧!
作为高级安全工程师,您将:
- 通过清晰阐述与安全问题相关的业务风险,为团队领导和合作团队提供可信的建议
- 在 CI/CD 和云原生生产环境中领导安全运营职能——包括漏洞管理、SAST、DAST、检测工程和事件响应
- 在软件开发生命周期中将安全集成到我们的应用程序中
- 与产品和开发团队合作,推动大型项目的成功,确保软件在不牺牲敏捷性和速度的情况下安全地构建和部署
- 推动和支持漏洞赏金计划、应用安全审查和威胁建模,包括代码审查和动态测试
- 评估并集成安全工具,以自动化和扩展安全流程,例如:评估开源方案与供应商解决方案
- 收集和分析安全指标,以解决跨团队依赖的安全问题
- 是一名善于解决问题的人,能够共情开发者的担忧,并采用建设性和灵活的方法来构建创新解决方案
您可能适合这个职位,如果:
- 有 5 年以上应用/产品安全或安全运营经验,重点在于安全工具的引入和优化
- 您了解漏洞管理、网络安全、云安全概念,以及多个安全领域的行业最佳实践
- 您能够适应不确定性,并在数据有限的情况下做出明智的决策
- 您采用灵活且建设性的方法
查看英文原文
Who are we?
Cohere is the leading security-first enterprise AI company. We build cutting-edge foundation AI models and end-to-end products that are designed to solve real-world business problems.
We’re training and deploying frontier models for enterprises who are building AI systems. We believe that our work is instrumental to the widespread adoption of AI and we are looking for folks that want to be part of that.
We obsess over what we build. Each one of us is responsible for contributing to increasing the capabilities of our models and the value they drive for our customers. Cohere is a team of researchers, engineers, designers, and more, who are all passionate about their craft.
We are a global technology company headquartered in Toronto with key offices in London, New York City, San Francisco, Montreal, Paris, Berlin and Seoul. Join us!
As a Senior Security Engineer you will:
- Serve as trusted advisor to team’s leadership and partner teams by clearly articulating business risks associated with security issues
- Lead security operation functions – including vulnerability management, SAST, DAST, detection engineering, and incident response – in CI/CD and cloud-native production environments
- Integrate security into our applications throughout the software development lifecycle
- Collaborate with product and development teams, driving the success of larger projects to ensure that software is built and deployed securely without compromising agility and speed
- Driving and supporting bug bounty program, application security reviews and threat modeling, including code review and dynamic testing
- Assess and integrate security tools to automate and scale security processes, i.e: evaluate open-source vs vendor solutions
- Gather and analyze security metrics to address security issues with cross-team dependencies
- Be a problem solver who is empathetic to developer concerns and will employ constructive and flexible approach to building innovative solutions
You may be a good fit if:
- 5+ years previous experience in Application/Product Security or Security Operations with a strong focus on security tool onboarding and optimization
- You have an understanding of vulnerability management, network security, cloud security concepts, and industry best practices across many fields of security
- You are comfortable with ambiguity and are able to make informed decisions with little data
- You employ a flexible and constructive approach when solving problems
- You are able to make trade-offs between build vs. buy decisions - help build solutions and able to review what tools are available
- You understand secure engineering best practices, can articulate problem statements and propose solutions to both technically savvy and non-technical audiences
- You have a deep technical understanding of common security vulnerabilities and risks, as well as countermeasures and compensating controls
- You’re a hands-on security engineer interested in automating controls
FULL-TIME EMPLOYEES AT COHERE ENJOY THESE PERKS:
- A weekly lunch stipend of $75/£75 or equivalent in your local currency for lunch.
- Full health and dental benefits, including a separate budget for mental health.
- RRSP matching, 401K, Pension Scheme.
- 100% Parental Leave top-up for up to 6 months, for either parent.
- Annual enrichment benefits:
Arts & culture, fitness/wellness, quality time, and a workspace improvement credit.
Education & learning stipend for conferences, courses, and coaching.
- 6 weeks of paid vacation (30 working days!)
- Budget for traveling to other offices if you are remote, plus an annual company offsite.
HOW AND WHERE WE WORK:
- Cohere is remote-friendly, but we also have offices in Toronto, London, New York City, San Francisco, Montreal, Paris, Berlin and Seoul with more opening soon.
- For those in the office: a daily lunch program, plenty of snacks, and regular community and social events.
- For those not near an office: a co-working benefit so you can work alongside others in your city.
- Everyone receives a $500 home office stipend to set up your workspace properly.
If any of the above doesn’t line up exactly with your experience, we still encourage you to apply.
We strive to create an inclusive work environment for all; we welcome applicants from all backgrounds and are committed to providing equal opportunities. Should you require any accommodations during the recruitment process, please submit an Accommodations Request Form https://docs.google.com/forms/d/12a6IrLdF3kI2nonKSr4tiFuz18rLQbaeYV-JM9L4o9Q/edit, and we will work together to meet your needs.
We may use AI-enabled tools to screen and assess applicants against the criteria for this position. This helps our recruiters identify potentially qualified candidates, but it doesn't limit the applications our recruiters may review or consider.
Beware of Scams: Cohere will never ask for payment or third-party services (e.g., CV writing) as part of our hiring process. All legitimate roles are listed on the Cohere careers page and LinkedIn only, with all communications from Cohere employees coming from an @cohere.com or @cw.cohere email alias. If jobs are viewed on other sites then please verify these through our official careers https://cohere.com/careers page.