HimalayasHimalayas logo
Joist AIJA

Security Engineer

Joist AI is a content enablement platform that uses artificial intelligence to help Architecture, Engineering, and Construction (AEC) firms streamline their proposal and marketing content creation.

Joist AI

Employee count: 11-50

India only

Stay safe on Himalayas

Never send money to companies. Jobs on Himalayas will never require payment from applicants.

About the company

Joist AI is a technology company revolutionizing the way professionals in the architecture, engineering, and construction (AEC) industry manage marketing and revenue operations. Our AI-powered software streamlines workflows, making it easier for teams to collaborate, innovate, and succeed.

About the role

We are looking for a Security Engineer to embed robust security practices into the very fabric of our AI-powered platform. Your goal is to eliminate risk without slowing down our engineering teams by championing a "Security by Design" culture. You won't just run scans and mandate fixes; you will partner with our product and platform teams to build automated security guardrails, secure our cloud infrastructure, and protect our cutting-edge LLM workloads, ensuring our customers' most sensitive data remains safe with zero "friction."

What you’ll do

  • Shift-Left Security: Integrate automated security scanning (SAST, DAST, SCA) directly into our CI/CD pipelines to catch vulnerabilities early in the development lifecycle.

  • Cloud Infrastructure Defense: Design and enforce security policies across our primary cloud environment, securing virtual networks, access controls, and cloud-native services using infrastructure-as-code (IaC) principles.

  • AI/ML Security Governance: Pioneer security strategies for our LLM and machine learning workloads, protecting against emerging threats like prompt injection, data poisoning, and model exfiltration.

  • Threat Detection & Incident Response: Build and monitor security observability tools, defining alerting thresholds and leading the response to potential security events or anomalies.

  • Cross-Functional Partnership: Act as an embedded security consultant to our engineering and product teams, conducting threat modeling and architecture reviews while acting as an enabler rather than a blocker.

  • Compliance & Trust: Drive and maintain compliance initiatives relevant to our enterprise AEC clients, ensuring we uphold the highest industry standards of data privacy.

What You’ll Bring

  • 4–6 years of experience in Security Engineering, Application Security, or DevSecOps, with a clear focus on cloud-native SaaS environments.

  • Cloud Security Mastery: Deep expertise in securing large-scale public cloud environments and a strong understanding of cloud networking, threat detection, data encryption, and identity management.

  • Automation Mindset: Proficient in modern scripting languages and experience automating security tasks—you approach security engineering with the same rigor as product software.

  • Modern AppSec: Hands-on experience with modern security tooling (e.g., automated dependency and vulnerability scanners) and a thorough understanding of common web and API vulnerabilities (OWASP Top 10).

  • Strategic Thinker: You can identify systemic security "blind spots" and design automated, paved-road solutions to solve them permanently rather than playing whack-a-mole with vulnerabilities.

Experience we’d be particularly excited about

  • LLM/AI Security Experience: Proven track record of securing Generative AI applications and navigating the unique, evolving threat landscape of large language models.

  • Compliance Leadership: Experience successfully guiding technology startups through major compliance audits and framework adoptions (e.g., SOC 2 Type II, ISO 27001).

  • Platform Collaboration: Experience working closely with Platform/DevOps teams to embed security seamlessly into internal developer tools and portals.

  • Attributes: Exceptional attention to detail, strong analytical and problem-solving skills, and excellent written and verbal communication.

  • Education: Bachelor's degree in Computer Science, Cybersecurity, Engineering, or a related field (or equivalent practical experience).

Experience we’d be particularly excited about

  • You love experimenting with new security methodologies and offensive testing techniques.

  • You have experience or interest in machine learning and AI risk management.

  • You have an understanding of the unique data security and privacy concerns within the AEC (Architecture, Engineering, and Construction) or B2B SaaS industries.

What to expect

We conduct a rigorous interview process based on integrity, talent, and drive. We trust our teammates from day one and move quickly to evaluate whether you are fit for the role. The entire interview process typically takes two weeks. Here's what to expect:

  • A 30 minute Zoom meeting to talk about Joist AI, your background, and answer any questions about the role.

  • A 30 minute Zoom meeting with another one of our team members to hear more about your experience and how you'd approach working in the role.

  • A take home project to assess your functional expertise for the role you're applying for.

  • A 60 minute Zoom call to review your project and answer any outstanding questions.

About the job

Apply before

Posted on

Job type

Full Time

Experience level

Location requirements

Hiring timezones

India +/- 0 hours

About Joist AI

Learn more about Joist AI and their company culture.

View company profile

Joist AI is a technology company dedicated to revolutionizing the Architecture, Engineering, and Construction (AEC) industry through innovative solutions. Powered by artificial intelligence and machine learning, the platform empowers business development and marketing professionals to effectively manage project data, streamline proposals, and enhance team collaboration. The company's mission is to transform the proposal process for the built world, enabling firms to win more work with less effort. Joist AI addresses the longstanding challenge of inefficient proposal creation, where teams often have to manually search through past proposals and rely on institutional knowledge stored in disparate locations. This fragmented approach leads to content silos, burdensome processes for keeping information current, and the proliferation of duplicated or inconsistent content.

The platform provides a centralized 'forever brain' for AEC firms by ingesting existing proposals and boilerplate copy to create a contextual knowledge graph. This allows users to instantly access historical company and project data. Joist AI's features include advanced search capabilities, automated content generation based on past winning proposals, and a built-in analytics tool to identify and rectify language issues, duplications, and inconsistencies. By automating these repetitive and time-consuming tasks, Joist AI frees up proposal teams to concentrate on more strategic activities, such as developing win strategies and creative solutions. The platform is designed to be a collaborative tool, improving communication and efficiency across teams. It helps firms build proposals significantly faster, improve departmental productivity, increase bid win rates, and minimize risk, ultimately boosting profitability through better strategic alignment.

Claim this profileJoist AI logoJA

Joist AI

View company profile

Similar remote jobs

Here are other jobs you might want to apply for.

View all remote jobs

7 remote jobs at Joist AI

Explore the variety of open remote roles at Joist AI, offering flexible work options across multiple disciplines and skill levels.

View all jobs at Joist AI

Remote companies like Joist AI

Find your next opportunity by exploring profiles of companies that are similar to Joist AI. Compare culture, benefits, and job openings on Himalayas.

View all companies

Find your dream job

Sign up now and join over 100,000 remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan