Cohere
Product Security Engineer, North Security
Remote role where the employee must remain based in a particular country.
Canada only
Employer listed it 12 days ago · Added 4 days ago
First listed 12 days ago and still open.
Salary
$180,000–$385,000
Location
Canada only
Timezone
US East
Contract
Full-time
Experience
Mid
Category
Software
Published by the employer
Remote flexibility
Work from home
This is a remote role, but the employee must be based in Canada. It is work from home rather than work from anywhere.
What the employer says
- Source listing states candidate location: "Canada, Remote"
What Nomaders makes of it
- Residency required in Canada
- Payroll and tax are likely handled in that country only
The quotes above are the employer's own words; the reading is ours. Always check the original listing and employment terms before working from another country.
About the role
Who are we?
Cohere is the leading security-first enterprise AI company. We build cutting-edge foundation AI models and end-to-end products that are designed to solve real-world business problems.
We’re training and deploying frontier models for enterprises who are building AI systems. We believe that our work is instrumental to the widespread adoption of AI and we are looking for folks that want to be part of that.
We obsess over what we build. Each one of us is responsible for contributing to increasing the capabilities of our models and the value they drive for our customers. Cohere is a team of researchers, engineers, designers, and more, who are all passionate about their craft.
We are a global technology company headquartered in Toronto with key offices in London, New York City, San Francisco, Montreal, Paris, Berlin and Seoul. Join us!
Why this role
Enterprises hand Cohere their most sensitive data and put our models inside workflows they can't afford to get wrong. Securing that means working on problems the industry hasn't settled yet, what authorization means when an agent acts on a user's behalf, how to contain tools that consume untrusted input, and whether tenant boundaries hold when a model can be steered by the data it reads. The established playbooks only take you so far.
We're hiring a Senior Product Security Engineer to work these problems alongside the engineers building the products, reviewing architecture and code, threat modeling before implementation, testing what ships, and turning what you learn into defaults other teams inherit. This is a hands-on engineering role, not an advisory one.
What you’ll do
Lead security reviews. Review architecture, code, and security-sensitive changes. Identify both individual vulnerabilities and the recurring design patterns behind them.
Secure AI-powered products. Evaluate risks such as prompt injection, unsafe tool use, identity and delegation failures, excessive agency, data exposure, tenant isolation, and sandbox escapes.
Threat model new capabilities. Identify trust boundaries, abuse cases, and high-impact failure modes before implementation. Translate findings into practical, prioritized mitigations.
Perform hands-on testing. Investigate suspected vulnerabilities, develop proofs of concept, assess exploitability and impact, and partner with engineers through remediation.
Build scalable guardrails. Develop secure defaults, approved patterns, reusable controls, review requirements, and automated checks that reduce recurring risks.
Strengthen engineering capability. Pair with engineers, document practical guidance, and help product teams develop durable security expertise.
Influence risk decisions. Explain technical findings, business impact, and remediation options clearly to engineers, product leaders, and executives.
You may be a good fit if
You have strong software engineering fundamentals and can independently understand, test, and contribute fixes to production codebases.
You are proficient in at least one of Python, Go, or TypeScript.
You have led security reviews or threat models for complex production systems and can point to meaningful design or risk improvements that resulted.
You understand common vulnerability classes and their underlying design failures, including injection, authorization flaws, IDOR, SSRF, unsafe deserialization, race conditions, cryptographic misuse, and software supply-chain risks.
You understand modern application architecture, including web applications, APIs, OAuth/OIDC, cloud platforms, containers, Kubernetes, and CI/CD systems.
You can reason rigorously about untrusted input, authorization, isolation, identity, delegation, and data boundaries. Direct experience with agentic AI systems is valuable but not required.
You have driven security improvements involving multiple engineering teams, including situations where influence mattered more than authority.
Requirements
The employer hasn't listed requirements separately, they're described in the role summary above and on the original listing.
Benefits
- ·A weekly lunch stipend of $75/£75 or equivalent in your local currency for lunch.
- ·Full health and dental benefits, including a separate budget for mental health.
- ·RRSP matching, 401K, Pension Scheme.
- ·100% Parental Leave top-up for up to 6 months, for either parent.
- ·Annual enrichment benefits:
How to apply
- 1Check the flexibility label above, work from home, matches where you plan to live and work.
- 2Tailor your CV to the role at Cohere, mentioning your remote working experience and working hours (US East).
- 3Apply directly on the employer's careers page using the button below. Nomaders never handles your application.
Found 5d ago. Last checked today. Always confirm the details on the original posting, salary and location can change after publication.
Listing sourced from Company boards.
Similar roles
Other open software roles with comparable remote rules.
Free to apply, no account needed.
$180,000–$385,000 · You'll be taken to the employer's careers page.