← Back to results

Product Security Engineer (AI & Platform Security) – Taiwan

Join Obsidian Security as a Product Security Engineer to enhance the security of products and cloud infrastructure in a rapidly growing company.

Location
Taipei, Taiwan
Compensation
Not disclosed
Level
mid
Type
full time

Posted by employer 22 hours ago

First seen on Joblaze 17 hours ago

Last verified on the company career page 17 hours ago

Apply at Obsidian Security → Save job Scanned from obsidiansecurity.com

What you'll build

  • Build security features into products and cloud infrastructure
  • Secure customer data across its full lifecycle
  • Design and secure services built on cloud-native platforms
  • Conduct security architecture and design reviews
  • Strengthen CI/CD pipelines with automated security controls

Must have

  • Solid experience in product security or a related discipline
  • Deep knowledge of secure software development
  • Strong software engineering skills in Python, Go, Java, Kotlin, TypeScript
  • Hands-on experience developing and securing applications on cloud-native services
  • Experience securing cloud-native SaaS products

Nice to have

  • Experience securing AI/LLM applications
  • Cybersecurity or identity security product experience
  • Software supply chain security knowledge
  • Familiarity with OWASP, CVSS, and NIST standards
  • Experience with compliance frameworks such as SOC 2 or ISO 27001

AI in the day-to-day

AI security is a core part of what Obsidian sells, and our own platform and products are built with AI and agents.

Not disclosed in this posting: compensation, years of experience, work arrangement, visa sponsorship.

Benefits

401k Match Equity/Stock Options Health Insurance Parental Leave

Joblaze summary

In this hands-on role, the Product Security Engineer at Obsidian Security focuses on integrating security features into the company's backend services and cloud infrastructure, ensuring the protection of customer data throughout its lifecycle. Key skills include proficiency in programming languages like Python and Go, along with experience in securing cloud-native applications on platforms such as AWS and GCP. This position is ideal for someone with a solid background in product security and a track record of implementing security improvements in code. Obsidian's emphasis on AI security makes this role particularly relevant as the company continues to expand its innovative offerings.

Joblaze insights

  • Listed today — first seen on Joblaze October 7, 2026. Last confirmed on Obsidian Security's careers page October 7, 2026.

Quick facts

What's the tech stack?
Joblaze extracted these technologies from the posting: AWS, GCP, Go, Java, Kotlin, Kubernetes.
What seniority level is this role?
Obsidian Security targets mid-level candidates for this position.
Is this full-time or contract?
Full-time for this Product Security Engineer (AI & Platform Security) – Taiwan role at Obsidian Security.

From the original posting

Obsidian Security is a global leader in cyber security protecting the SaaS and non-human identity layer modern enterprises run on — from Salesforce and Snowflake to the AI agents now deployed inside them. The Obsidian Security platform gives unified visibility into every human and machine identity, app, and integration across their SaaS estate, detects identity-based and supply chain attacks in real time, and enforces least-privilege access before it's exploited. Trusted by major Fortune 500 companies T-Mobile, Workday, Snowflake, and S&P Global, Obsidian ranked No. 95 on the 2025 Deloitte Technology Fast 500™, growing nearly 1000% from 2021–2024 — helping CISOs turn an unmonitored attack surface into one they can govern with confidence. Obsidian has also been recognized by Forbes as America's Best Startup Employers in 2026.

Product Security Engineer (AI & Platform Security) – Taiwan

About the Role: Obsidian Security is looking for a Product Security Engineer to strengthen the security of Obsidian's products, software supply chain, development pipelines, and cloud infrastructure. This is a hands-on engineering role: you will design and build security features into our backend services and cloud-native infrastructure, not only review them. AI security is a core part of what Obsidian sells, and our own platform and products are built with AI and agents, so you will help keep those systems secure by design. You will also help protect customer data throughout its lifecycle. The role spans the full product lifecycle, from architecture through production operations.

Key Responsibilities:

  • Build security features into our products, backend services, and cloud infrastructure (authentication and authorization, service-to-service identity, tenant isolation, secrets management, audit logging).
  • Secure customer data across its full lifecycle (collection, processing, storage, and presentation), covering encryption, key management, tenant isolation, access control, and retention.
  • Design and secure services built on cloud-native platforms, primarily AWS and GCP (IAM, networking, storage, Kubernetes, managed services), with secure defaults and infrastructure-as-code.
  • Conduct security architecture and design reviews for new products, services, APIs, data pipelines, and infrastructure components, including those that use AI and agents.
  • Secure the AI and agent workflows in our product development, and turn the findings into concrete guardrails in code (for example, least-privilege tool access, input and output controls, and data-leakage protections).
  • Strengthen CI/CD pipelines with automated security controls, including dependency scanning, static analysis, and container scanning.
  • Lead CVE management, including exposure analysis, risk assessment, prioritization, remediation, testing, deployment, and validation. Automate it where possible.
  • Conduct code reviews and mentor engineers on secure development practices.

Required Qualifications:

  • Solid experience in product security or a related discipline, with a track record of shipping security improvements as code.
  • Deep knowledge of secure software development and common application security risks.
  • Strong software engineering skills in Python, Go, Java, Kotlin, TypeScript, or comparable languages.
  • Hands-on experience developing and securing applications on cloud-native services, such as AWS and/or GCP.
  • Experience securing cloud-native SaaS products, distributed systems, APIs, and microservices, including protecting sensitive data end-to-end.
  • Practical CVE management experience across dependencies and infrastructure.
  • Strong English communication skills and the ability to collaborate across regions and time zones.

Nice-to-Have:

  • Experience securing AI/LLM applications or agent systems (e.g., OWASP Top 10 for LLM Applications, MCP/tool-permission models).
  • Cybersecurity or identity security product experience.
  • Software supply chain security knowledge.
  • Familiarity with OWASP, CVSS, and NIST standards.
  • Experience with compliance frameworks such as SOC 2 or ISO 27001.
  • Penetration testing or vulnerability research background.
  • Mandarin proficiency.

Employee Benefits:

Standard company text repeated across Obsidian Security's postings is omitted here.

Similar positions

Obsidian Security
Senior Product Security Engineer – Taiwan 
Obsidian Security · Taipei, Taiwan
Obsidian Security
AI Security Engineer - Taiwan
Obsidian Security · Taipei, Taiwan
Obsidian Security
Senior Threat Research Engineer – Taiwan
Obsidian Security · Taipei, Taiwan
Obsidian Security
Lead IT Systems Engineer
Obsidian Security · Palo Alto, CA
Opal
Application Security Engineer
Opal · San Francisco