Jobs with Startups
JobsStartupsInvestorsMCP
JobsAnyscale

Senior Product Security Engineer

Anyscale logo

Anyscale

Technology

Senior Product Security Engineer

San Francisco
On-site
Full-time
Posted Aug 26, 2026
Apply on company site

Opens the original job posting

Engineering
323 Security
On-site

At Anyscale, we're on a mission to democratize distributed computing and make it accessible to software developers of all skill levels. We’re commercializing Ray, a popular open-source project that's creating an ecosystem of libraries for scalable machine learning. Companies like OpenAI, Uber, Spotify, Instacart, Cruise, and many more, have Ray in their tech stacks to accelerate the progress of AI applications out into the real world.

With Anyscale, we’re building the best place to run Ray, so that any developer or data scientist can scale an ML application from their laptop to the cluster without needing to be a distributed systems expert.

Proud to be backed by Andreessen Horowitz, NEA, and Addition with $250+ million raised to date.

About the Role

Anyscale's product security needs are growing as we ship to larger and more demanding customers. We're looking for a Senior Product Security Engineer to own our secure software development lifecycle and to be engineering's partner on building security into the product. Reporting to the Head of Security, you will work in close partnership with engineering.

This is a senior, high-ownership role. You will own and operate a scalable SSDL, partner with engineering on security features and secure design, review the security of existing systems and new initiatives, and own how we find, track, drive to resolution and report on vulnerabilities in what we ship. This role is based in India.

In your first year, success looks like an SSDL that scales with engineering rather than gating it, security review embedded in how new initiatives ship, and accurate, on-demand vulnerability reporting backed by a working path to resolution.

What You'll Do

  • Own and operate a scalable secure software development lifecycle: threat modeling, security requirements, secure design practices, and scanning that engineering can readily adopt.

  • Partner with engineering on security features and secure-by-design architecture, from early design through implementation.

  • Review the security of existing systems and new initiatives, and turn findings into prioritized, actionable work.

  • Own vulnerability management for what we ship: enumerate components, map known vulnerabilities, and produce accurate posture reporting on demand.

  • Drive vulnerabilities to resolution with engineering against defined SLAs.

  • Own software composition analysis, secret scanning, and SAST across product repositories, and set the bar for secure-development checks.

  • Mentor other engineers and raise the security bar across the organization.

What You'll Bring

  • 8+ years in product or application security, with senior-level depth, ideally at a high-growth startup.

  • Demonstrated ownership of a secure software development lifecycle at scale, including threat modeling and secure design review.

  • A strong hands-on background partnering with engineering on security features and architecture, not just reporting findings.

  • Deep experience with software composition analysis, secret scanning, and SAST or secure-development tooling in real repositories.

  • A solid understanding of software supply chain security and how to enumerate what an organization ships, including SBOM approaches.

  • Experience triaging vulnerabilities using CVSS and business context and driving them to resolution with engineering.

  • The communication and seniority to set direction, review others' work, and raise the bar for those around you.

Nice to Have

  • Experience producing vulnerability or security posture reporting for enterprise or regulated customers.

  • Familiarity with container artifact security, including image scanning, signing, and SBOM generation.

  • Experience building or maturing an SSDL program at scale.

  • Background in AI or ML platforms or distributed systems.

Apply for this role
Anyscale logo

Anyscale

Company profile

What do OpenAI, Uber, and Instacart have in common? They all use Ray, open-source software built by Anyscale that’s used to scale up AI models. The company, which emerged from a research lab at UC Berkeley, enables users to easily scale Python code and create custom apps without becoming experts in distributed computing. It was founded by Cofounder Robert Nishihara, CTO Philipp Moritz, and executive chairman — and Databricks cofounder — Ion Stoica. The company has raised $259 million and has a valuation of $1.1 billion. Recently, the company announced an update to warn users if Ray was configured to be accessible on the open internet after security researchers found that hackers had installed crypto-miners on some users’ AI servers, as Forbes reported.

View Anyscale

Headquarters

San Francisco, California, United States

Team size

500

Keep exploring

More roles at Anyscale

View all roles

Staff Software Engineer, Ray Core

Engineering · San Francisco

Staff Software Engineer, Ray Data

Engineering · San Francisco

Software Engineer (Ray Core)

Engineering · San Francisco

Software Engineer, ML Developer Experience

Engineering · San Francisco

Senior Detection and Response Engineer

Engineering · San Francisco

Jobs with Startups © 2026

Browse startupsBrowse jobsMCP guideAboutPowered by Supabase