Cohere is the leading security-first enterprise AI company. We build cutting-edge foundation AI models and end-to-end products that are designed to solve real-world business problems.
We’re training and deploying frontier models for enterprises who are building AI systems. We believe that our work is instrumental to the widespread adoption of AI and we are looking for folks that want to be part of that.
We obsess over what we build. Each one of us is responsible for contributing to increasing the capabilities of our models and the value they drive for our customers. Cohere is a team of researchers, engineers, designers, and more, who are all passionate about their craft.
We are a global technology company headquartered in Toronto with key offices in London, New York City, San Francisco, Montreal, Paris, Berlin and Seoul. Join us!
Задачи
Serve as trusted advisor to team’s leadership and partner teams by clearly articulating business risks associated with security issues
Execute the long-term vision for the Security team in alignment with Cohere’s product and business goals
Collaborate closely with leadership to prioritize high-impact initiatives and strategic customer engagements
Vulnerability Management: Develop and implement enterprise-wide vulnerability management processes and tooling, including identification, prioritization, remediation tracking, and reporting, including customer artifacts
Static Application Security Testing (SAST): Establish SAST programs, integrate tools into CI/CD pipelines, and analyze results to identify and remediate security flaws in source code
Dynamic Application Security Testing (DAST): Implement DAST methodologies, configure scanning tools, and conduct regular assessments of running applications
Penetration Testing: Lead and oversee internal and external penetration testing engagements, including web application, API, network and agentic AI platform including managing our bug bounty program
Security Architecture Review: Collaborate with development teams to review and validate security architecture and design patterns
Secure SDLC Integration: Embed security practices throughout the software development lifecycle, working closely with engineering and product teams
Team Leadership: Lead and grow a high-performing team of Security engineers through hiring, coaching, and mentorship
Metrics and Reporting: Establish key security metrics, generate regular reports for leadership, and communicate security posture to stakeholders
Compliance and Standards: Ensure application security practices align with industry standards (OWASP Top10 for LLMs, ISO 27001) and regulatory requirements
YOU MAY BE A GOOD FIT IF
Proficiency with programming languages (Python, GoLang, etc.) and web technologies
Experience with cloud platforms (AWS, GCP, Azure) and container security
Experience building and managing high-performing security teams
You employ a flexible and constructive approach when solving problems
You understand secure engineering best practices, can articulate problem statements, and propose solutions to both technically savvy and non-technical audiences
WORKING LOCATION
Требования
You have 8+ years of previous experience in Application Security / Security Engineering with a strong focus on vulnerability management, SDLC and bug bounty programs
Proven experience with SAST, DAST, and penetration testing methodologies and tools
Excellent communication and interpersonal skills with ability to influence technical and non-technical stakeholders
You are comfortable with ambiguity and are able to make informed decisions with little data
You are able to make trade-offs between build vs. buy decisions—help build solutions and be able to review what tools are available
You have a deep technical understanding of common security vulnerabilities and risks, as well as countermeasures and compensating controls
Паспорт вакансии
История публикации
Появилась в Вакандии26 дней
Перепубликациинетпубликовалась один раз
Проверяли на источникеВидели сегодня
Среди похожихНет данных22 из 30 · похожих вакансий слишком мало для сравнения
Откуда что взялось
Отмечено то, что вывели мы. Без пометки — значение назвал работодатель.
ГрейдSeniorвыведено из другого признака
Формат работыОфис
ГеографияТоронто, СШАвычитано из текста вакансии
Зарплата225 000 USD — 325 000 USD в годвычитано из текста вакансии
Почему на этом месте в выдаче
Порядок выдачи объявлен контрактом: свежесть решает между днями, полнота и зарплата — внутри дня.
Полнота карточки1004 из 4 полей: грейд, формат, география, зарплата
Зарплата названа100вилку назвал источник
Проверка Вакандии
Источники и свежесть
Тип источника
Карьерный сайт работодателя
Найдено публикаций
1
Посмотреть публикации и даты
ashbyОсновная публикация · 2026-05-27
C
Работодатель
Cohere
50 активных вакансий · вилка работодателя указана в 25%