×
Register Here to Apply for Jobs or Post Jobs. X
More jobs:

Senior Security Engineer

Job in Tulsa, Tulsa County, Oklahoma, 74145, USA
Listing for: LiteLLM
Full Time position
Listed on 2026-08-03
Job specializations:
  • IT/Tech
    Cybersecurity
Salary/Wage Range or Industry Benchmark: 120000 - 180000 USD Yearly USD 120000.00 180000.00 YEAR
Job Description & How to Apply Below

Senior Security Engineer

LiteLLM is the world’s most popular AI Gateway, trusted by companies like Adobe, Netflix, and NASA. Our platform gives developers secure, reliable access to LLMs and adjacent services. We’re looking for our first Security Engineer to help secure LiteLLM’s application, infrastructure, and software-delivery pipeline.

About the role

This is a hands‑on security generalist role with a strong emphasis on application security. You’ll spend most of your time reviewing and hardening LiteLLM’s Python codebase, identifying new attack surfaces, working directly with engineers to fix vulnerabilities, and making secure development practices part of how we build.

You’ll also own security work across IT, CI/CD, cloud infrastructure, and the software supply chain. The ideal candidate has built application/product/infrastructure security programs from scratch and genuinely enjoys security outside of work—through CTFs, vulnerability research, open-source projects, or independent experimentation.

Responsibilities Application security
  • Conduct deep security reviews of LiteLLM’s Python proxy, APIs, authentication systems, and enterprise features.

  • Identify and remediate vulnerabilities involving authentication, authorization, secrets, tenant isolation, injection, and data exposure.

  • Partner directly with engineers throughout design, implementation, code review, and release—not only after code is shipped.

  • Build application-security tooling into the development lifecycle, including SAST, DAST, dependency scanning, and secrets detection.

  • Perform internal red teaming and adversarial testing against LiteLLM’s APIs, proxy, and LLM‑specific attack surfaces.

  • Threat‑model new products and architecture changes before they reach production.

  • Create secure coding guidelines and train engineers on common vulnerabilities and defensive practices.

Infrastructure, CI/CD, and supply‑chain security
  • Harden LiteLLM’s Docker images, PyPI packages, Git Hub Actions workflows, and release infrastructure.

  • Detect dependency confusion, poisoned packages, compromised dependencies, exposed secrets, and unsafe build practices.

  • Implement SBOMs, signed builds, provenance checks, and reproducible‑build practices.

  • Design secure‑by‑default configurations for cloud and self‑hosted deployments, including authentication, IAM, secrets management, and key rotation.

  • Review cloud infrastructure, network boundaries, access controls, and production deployment patterns.

IT security and incident response
  • Strengthen employee identity, device, SaaS, and internal access controls.

  • Build monitoring and anomaly detection for suspicious API, model, authentication, and routing activity.

  • Lead security incident response, vulnerability assessment, remediation, post‑mortems, and stakeholder communication.

  • Establish formal vulnerability intake, CVE triage, disclosure, and remediation processes.

  • Maintain threat models as LiteLLM’s product and architecture evolve.

What we’re looking for
  • A strong security generalist who can work across application security, IT, CI/CD, cloud infrastructure, and the software supply chain.

  • Deep application‑security expertise, including manually auditing production Python code and working with engineers to remediate vulnerabilities.

  • Strong understanding of authentication, authorization, tenant isolation, SSRF, injection, deserialization, secrets management, and common web and API vulnerabilities.

  • Experience using and configuring tools such as Semgrep, Bandit, CodeQL, Burp Suite, and other SAST or DAST tooling.

  • Previous experience at an early‑stage security startup during its 0→1 journey.

  • Experience securing containers, Git Hub Actions, build pipelines, packages, and software dependencies.

  • Familiarity with SBOMs, Sigstore, Cosign, Snyk, Grype, Trivy, or equivalent tooling.

  • Strong knowledge of OAuth2, JWT, mTLS, IAM, and high‑throughput API authentication.

  • Familiarity with prompt injection, LLM data exfiltration, tool abuse, and the OWASP Top 10 for LLM Applications.

  • Experience with incident response, CVSS scoring, vulnerability management, CVE triage, and coordinated disclosure.

  • Experience competing in CTFs during college or independently pursuing…

Position Requirements
10+ Years work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary