litellm - Senior Security Engineer
Requirements
• A strong security generalist who can work across application security, IT, CI/CD, cloud infrastructure, and the software supply chain. • Deep application-security expertise, including manually auditing production Python code and working with engineers to remediate vulnerabilities. • Strong understanding of authentication, authorization, tenant isolation, SSRF, injection, deserialization, secrets management, and common web and API vulnerabilities. • Experience using and configuring tools such as Semgrep, Bandit, CodeQL, Burp Suite, and other SAST or DAST tooling. • Previous experience at an early-stage security startup during its 0→1 journey. • Experience securing containers, GitHub Actions, build pipelines, packages, and software dependencies. • Familiarity with SBOMs, Sigstore, Cosign, Snyk, Grype, Trivy, or equivalent tooling. • Strong knowledge of OAuth2, JWT, mTLS, IAM, and high-throughput API authentication. • Familiarity with prompt injection, LLM data exfiltration, tool abuse, and the OWASP Top 10 for LLM Applications. • Experience with incident response, CVSS scoring, vulnerability management, CVE triage, and coordinated disclosure. • Experience competing in CTFs during college or independently pursuing vulnerability research, reverse engineering, bug bounties, or security projects. • A genuine interest in security outside your day job—you regularly explore new attack techniques, build security projects, or contribute to the security community. • Bachelor’s or Master’s degree in Computer Science or a related field, or equivalent practical experience.
Responsibilities
• APPLICATION SECURITY • Conduct deep security reviews of LiteLLM’s Python proxy, APIs, authentication systems, and enterprise features. • Identify and remediate vulnerabilities involving authentication, authorization, secrets, tenant isolation, injection, and data exposure. • Partner directly with engineers throughout design, implementation, code review, and release—not only after code is shipped. • Build application-security tooling into the development lifecycle, including SAST, DAST, dependency scanning, and secrets detection. • Perform internal red teaming and adversarial testing against LiteLLM’s APIs, proxy, and LLM-specific attack surfaces. • Threat-model new products and architecture changes before they reach production. • Create secure coding guidelines and train engineers on common vulnerabilities and defensive practices. • INFRASTRUCTURE, CI/CD, AND SUPPLY-CHAIN SECURITY • Harden LiteLLM’s Docker images, PyPI packages, GitHub Actions workflows, and release infrastructure. • Detect dependency confusion, poisoned packages, compromised dependencies, exposed secrets, and unsafe build practices. • Implement SBOMs, signed builds, provenance checks, and reproducible-build practices. • Design secure-by-default configurations for cloud and self-hosted deployments, including authentication, IAM, secrets management, and key rotation. • Review cloud infrastructure, network boundaries, access controls, and production deployment patterns. • IT SECURITY AND INCIDENT RESPONSE • Strengthen employee identity, device, SaaS, and internal access controls. • Build monitoring and anomaly detection for suspicious API, model, authentication, and routing activity. • Lead security incident response, vulnerability assessment, remediation, post-mortems, and stakeholder communication. • Establish formal vulnerability intake, CVE triage, disclosure, and remediation processes. • Maintain threat models as LiteLLM’s product and architecture evolve.
Benefits
• Work on application-security problems at the intersection of AI, APIs, and developer infrastructure. • Secure an open-source product used by enterprises around the world. • Work directly with engineers and influence how security is incorporated into product development. • Take broad technical ownership in a fast-moving environment. • Competitive salary and health, dental, and vision benefits.
Apply in one click
Upload My Resume
Drop here or click to browse · Tap to choose · PDF, DOCX, DOC, RTF, TXT