# Product Security Engineer, North Security

[Cohere](https://gurify.com/jobs?q=Cohere) · Canada · Posted yesterday

[Security](https://gurify.com/jobs/security)

[Apply on the original posting → (opens in a new tab)](https://jobs.ashbyhq.com/cohere/9b596ab8-0df4-41aa-85da-e07578c082b2)

## Job description

Who are we?

Cohere is the leading security-first enterprise AI company. We build cutting-edge foundation AI models and end-to-end products that are designed to solve real-world business problems.

We’re training and deploying frontier models for enterprises who are building AI systems. We believe that our work is instrumental to the widespread adoption of AI and we are looking for folks that want to be part of that.

We obsess over what we build. Each one of us is responsible for contributing to increasing the capabilities of our models and the value they drive for our customers. Cohere is a team of researchers, engineers, designers, and more, who are all passionate about their craft.

We are a global technology company headquartered in Toronto with key offices in London, New York City, San Francisco, Montreal, Paris, Berlin and Seoul. Join us!

### WHY THIS ROLE

Enterprises hand Cohere their most sensitive data and put our models inside workflows they can't afford to get wrong. Securing that means working on problems the industry hasn't settled yet, what authorization means when an agent acts on a user's behalf, how to contain tools that consume untrusted input, and whether tenant boundaries hold when a model can be steered by the data it reads. The established playbooks only take you so far.

We're hiring a Senior Product Security Engineer to work these problems alongside the engineers building the products, reviewing architecture and code, threat modeling before implementation, testing what ships, and turning what you learn into defaults other teams inherit. This is a hands-on engineering role, not an advisory one.

### WHAT YOU’LL DO

- Lead security reviews. Review architecture, code, and security-sensitive changes. Identify both individual vulnerabilities and the recurring design patterns behind them.

- Secure AI-powered products. Evaluate risks such as prompt injection, unsafe tool use, identity and delegation failures, excessive agency, data exposure, tenant isolation, and sandbox escapes.

- Threat model new capabilities. Identify trust boundaries, abuse cases, and high-impact failure modes before implementation. Translate findings into practical, prioritized mitigations.

- Perform hands-on testing. Investigate suspected vulnerabilities, develop proofs of concept, assess exploitability and impact, and partner with engineers through remediation.

- Build scalable guardrails. Develop secure defaults, approved patterns, reusable controls, review requirements, and automated checks that reduce recurring risks.

- Strengthen engineering capability. Pair with engineers, document practical guidance, and help product teams develop durable security expertise.

- Influence risk decisions. Explain technical findings, business impact, and remediation options clearly to engineers, product leaders, and executives.

### YOU MAY BE A GOOD FIT IF

- You have strong software engineering fundamentals and can independently understand, test, and contribute fixes to production codebases.

- You are proficient in at least one of Python, Go, or TypeScript.

- You have led security reviews or threat models for complex production systems and can point to meaningful design or risk improvements that resulted.

- You understand common vulnerability classes and their underlying design failures, including injection, authorization flaws, IDOR, SSRF, unsafe deserialization, race conditions, cryptographic misuse, and software supply-chain risks.

- You understand modern application architecture, including web applications, APIs, OAuth/OIDC, cloud platforms, containers, Kubernetes, and CI/CD systems.

- You can reason rigorously about untrusted input, authorization, isolation, identity, delegation, and data boundaries. Direct experience with agentic AI systems is valuable but not required.

- You have driven security improvements involving multiple engineering teams, including situations where influence mattered more than authority.

- You communicate clearly with both technical and non-technical audiences.

### NICE TO HAVE

- Experience building or operating security tooling such as SAST, DAST, SCA, custom linters, or policy-as-code.

- Experience securing multi-tenant SaaS, enterprise software, or systems that process sensitive customer data.

- Offensive security experience through penetration testing, red teaming or security research.

- Experience operating or participating in a vulnerability disclosure or bug bounty program.

- Contributions to open-source security projects, published research, conference talks, or credited vulnerability discoveries.

### FULL-TIME EMPLOYEES AT COHERE ENJOY THESE PERKS:

- A weekly lunch stipend of $75/£75 or equivalent in your local currency for lunch.

- Full health and dental benefits, including a separate budget for mental health.

- RRSP matching, 401K, Pension Scheme.

- 100% Parental Leave top-up for up to 6 months, for either parent.

- Annual enrichment benefits:

 Arts & culture, fitness/wellness, quality time, and a workspace improvement credit.

 Education & learning stipend for conferences, courses, and coaching.

- 6 weeks of paid vacation (30 working days!)

- Budget for traveling to other offices if you are remote, plus an annual company offsite.

### HOW AND WHERE WE WORK:

- Cohere is remote-friendly, but we also have offices in Toronto, London, New York City, San Francisco, Montreal, Paris, Berlin and Seoul with more opening soon.

- For those in the office: a daily lunch program, plenty of snacks, and regular community and social events.

- For those not near an office: a co-working benefit so you can work alongside others in your city.

- Everyone receives a $500 home office stipend to set up your workspace properly.

If any of the above doesn’t line up exactly with your experience, we still encourage you to apply.

We strive to create an inclusive work environment for all; we welcome applicants from all backgrounds and are committed to providing equal opportunities. Should you require any accommodations during the recruitment process, please submit an Accommodations Request Form https://docs.google.com/forms/d/12a6IrLdF3kI2nonKSr4tiFuz18rLQbaeYV-JM9L4o9Q/edit, and we will work together to meet your needs.

We may use AI-enabled tools to screen and assess applicants against the criteria for this position. This helps our recruiters identify potentially qualified candidates, but it doesn't limit the applications our recruiters may review or consider.

Beware of Scams: Cohere will never ask for payment or third-party services (e.g., CV writing) as part of our hiring process. All legitimate roles are listed on the Cohere careers page and LinkedIn only, with all communications from Cohere employees coming from an @cohere.com or @cw.cohere email alias. If jobs are viewed on other sites then please verify these through our official careers https://cohere.com/careers page.

**Live in Cohere’s hiring system.** Read from the company's own applicant tracking system, not reposted from a job board — so it's a real, open requisition rather than an ad that outlived the role.

We remove it as soon as it disappears at source.

## More jobs like this

- AP [Product Security Engineer](https://gurify.com/job/product-security-engineer-at-apolloresearch-7e39c1fe2016) Apolloresearch · London & San Francisco · last week
- ST [Senior Product Security Engineer](https://gurify.com/job/senior-product-security-engineer-at-staffbase-9c270cb1bef2) Staffbase · Germany Remote · 2 days ago
- LI [Product & AI Security Engineer](https://gurify.com/job/product-ai-security-engineer-at-linkedin-dde4a2718339) Linkedin · Berlin · 3 weeks ago
- ST [Senior Product Security Engineer](https://gurify.com/job/senior-product-security-engineer-at-staffbase-46bf92e491d9) Staffbase · Berlin, Germany · 3 weeks ago
- AI [Senior Security Engineer, Detection & Response](https://gurify.com/job/senior-security-engineer-detection-response-at-aircallioinc-88e23520e0c1) Aircallioinc · San Francisco Office; Seattle Office · 3 days ago
- GO [Senior Security Engineer, Product Security](https://gurify.com/job/senior-security-engineer-product-security-at-goodleap-788ee656f8bd) Goodleap · Remote, United States · 2 weeks ago

```json
{"@context":"https://schema.org/","@type":"JobPosting","title":"Product Security Engineer, North Security","description":"\u003Cp\u003EWho are we?\u003C/p\u003E\u003Cp\u003ECohere is the leading security-first enterprise AI company.  We build cutting-edge foundation AI models and end-to-end products that are designed to solve real-world business problems.\u003C/p\u003E\u003Cp\u003EWe\u2019re training and deploying frontier models for enterprises who are building AI systems. We believe that our work is instrumental to the widespread adoption of AI and we are looking for folks that want to be part of that.\u003C/p\u003E\u003Cp\u003EWe obsess over what we build. Each one of us is responsible for contributing to increasing the capabilities of our models and the value they drive for our customers. Cohere is a team of researchers, engineers, designers, and more, who are all passionate about their craft.\u003C/p\u003E\u003Cp\u003EWe are a global technology company headquartered in Toronto with key offices in London, New York City, San Francisco, Montreal, Paris, Berlin and Seoul. Join us!\u003C/p\u003E\u003Ch3\u003EWHY THIS ROLE\u003C/h3\u003E\u003Cp\u003EEnterprises hand Cohere their most sensitive data and put our models inside workflows they can\u0026#39;t afford to get wrong. Securing that means working on problems the industry hasn\u0026#39;t settled yet, what authorization means when an agent acts on a user\u0026#39;s behalf, how to contain tools that consume untrusted input, and whether tenant boundaries hold when a model can be steered by the data it reads. The established playbooks only take you so far.\u003C/p\u003E\u003Cp\u003EWe\u0026#39;re hiring a Senior Product Security Engineer to work these problems alongside the engineers building the products, reviewing architecture and code, threat modeling before implementation, testing what ships, and turning what you learn into defaults other teams inherit. This is a hands-on engineering role, not an advisory one.\u003C/p\u003E\u003Ch3\u003EWHAT YOU\u2019LL DO\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003ELead security reviews. Review architecture, code, and security-sensitive changes. Identify both individual vulnerabilities and the recurring design patterns behind them.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ESecure AI-powered products. Evaluate risks such as prompt injection, unsafe tool use, identity and delegation failures, excessive agency, data exposure, tenant isolation, and sandbox escapes.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EThreat model new capabilities. Identify trust boundaries, abuse cases, and high-impact failure modes before implementation. Translate findings into practical, prioritized mitigations.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EPerform hands-on testing. Investigate suspected vulnerabilities, develop proofs of concept, assess exploitability and impact, and partner with engineers through remediation.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EBuild scalable guardrails. Develop secure defaults, approved patterns, reusable controls, review requirements, and automated checks that reduce recurring risks.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EStrengthen engineering capability. Pair with engineers, document practical guidance, and help product teams develop durable security expertise.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EInfluence risk decisions. Explain technical findings, business impact, and remediation options clearly to engineers, product leaders, and executives.\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003EYOU MAY BE A GOOD FIT IF\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EYou have strong software engineering fundamentals and can independently understand, test, and contribute fixes to production codebases.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EYou are proficient in at least one of Python, Go, or TypeScript.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EYou have led security reviews or threat models for complex production systems and can point to meaningful design or risk improvements that resulted.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EYou understand common vulnerability classes and their underlying design failures, including injection, authorization flaws, IDOR, SSRF, unsafe deserialization, race conditions, cryptographic misuse, and software supply-chain risks.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EYou understand modern application architecture, including web applications, APIs, OAuth/OIDC, cloud platforms, containers, Kubernetes, and CI/CD systems.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EYou can reason rigorously about untrusted input, authorization, isolation, identity, delegation, and data boundaries. Direct experience with agentic AI systems is valuable but not required.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EYou have driven security improvements involving multiple engineering teams, including situations where influence mattered more than authority.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EYou communicate clearly with both technical and non-technical audiences.\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003ENICE TO HAVE\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EExperience building or operating security tooling such as SAST, DAST, SCA, custom linters, or policy-as-code.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExperience securing multi-tenant SaaS, enterprise software, or systems that process sensitive customer data.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EOffensive security experience through penetration testing, red teaming or security research.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExperience operating or participating in a vulnerability disclosure or bug bounty program.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EContributions to open-source security projects, published research, conference talks, or credited vulnerability discoveries.\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003EFULL-TIME EMPLOYEES AT COHERE ENJOY THESE PERKS:\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EA weekly lunch stipend of $75/\u0026#163;75 or equivalent in your local currency for lunch.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EFull health and dental benefits, including a separate budget for mental health.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ERRSP matching, 401K, Pension Scheme.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003E100% Parental Leave top-up for up to 6 months, for either parent.\u003C/li\u003E\u003C/ul\u003E\u003Cp\u003E- Annual enrichment benefits:\u003Cbr /\u003E   \u003Cbr /\u003E   Arts \u0026amp; culture, fitness/wellness, quality time, and a workspace improvement credit.\u003Cbr /\u003E   \u003Cbr /\u003E   Education \u0026amp; learning stipend for conferences, courses, and coaching.\u003C/p\u003E\u003Cul\u003E\u003Cli\u003E6 weeks of paid vacation (30 working days!)\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EBudget for traveling to other offices if you are remote, plus an annual company offsite.\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003EHOW AND WHERE WE WORK:\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003ECohere is remote-friendly, but we also have offices in Toronto, London, New York City, San Francisco, Montreal, Paris, Berlin and Seoul with more opening soon.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EFor those in the office: a daily lunch program, plenty of snacks, and regular community and social events.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EFor those not near an office: a co-working benefit so you can work alongside others in your city.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EEveryone receives a $500 home office stipend to set up your workspace properly.\u003C/li\u003E\u003C/ul\u003E\u003Cp\u003EIf any of the above doesn\u2019t line up exactly with your experience, we still encourage you to apply.\u003C/p\u003E\u003Cp\u003EWe strive to create an inclusive work environment for all; we welcome applicants from all backgrounds and are committed to providing equal opportunities. Should you require any accommodations during the recruitment process, please submit an Accommodations Request Form https://docs.google.com/forms/d/12a6IrLdF3kI2nonKSr4tiFuz18rLQbaeYV-JM9L4o9Q/edit, and we will work together to meet your needs.\u003C/p\u003E\u003Cp\u003EWe may use AI-enabled tools to screen and assess applicants against the criteria for this position. This helps our recruiters identify potentially qualified candidates, but it doesn\u0026#39;t limit the applications our recruiters may review or consider.\u003C/p\u003E\u003Cp\u003EBeware of Scams: Cohere will never ask for payment or third-party services (e.g., CV writing) as part of our hiring process. All legitimate roles are listed on the Cohere careers page and LinkedIn only, with all communications from Cohere employees coming from an @cohere.com or @cw.cohere email alias. If jobs are viewed on other sites then please verify these through our official careers https://cohere.com/careers page.\u003C/p\u003E","identifier":{"@type":"PropertyValue","name":"Gurify","value":"product-security-engineer-north-security-at-cohere-8f5b2fe1e9a5"},"url":"https://gurify.com/job/product-security-engineer-north-security-at-cohere-8f5b2fe1e9a5","datePosted":"2026-09-11","validThrough":"2026-10-26T23:59:59Z","hiringOrganization":{"@type":"Organization","name":"Cohere","sameAs":"https://jobs.ashbyhq.com/cohere"},"directApply":false,"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressCountry":"CA"}}}
```

```json
{"@context":"https://schema.org/","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Jobs","item":"https://gurify.com/jobs"},{"@type":"ListItem","position":2,"name":"Canada","item":"https://gurify.com/jobs/canada"},{"@type":"ListItem","position":3,"name":"Product Security Engineer, North Security","item":"https://gurify.com/job/product-security-engineer-north-security-at-cohere-8f5b2fe1e9a5"}]}
```
