About this role
Overview
Teradyne Information Security is building an in-house capability to design, build and operate its own security applications using AI-assisted development. The Security Software Engineer owns those applications end to end: architecture, delivery, bug resolution, new features and the full application security lifecycle. The first major platform in scope is the Cyber Incident Response Platform, with further security applications to follow.
Applications built with AI coding tools can be delivered quickly, but speed is only valuable if the result is secure, tested, maintainable and trusted by the teams who depend on it. This role is accountable for that outcome. The engineer is expected to treat AI-generated code as untrusted input, applying engineering discipline and application security rigor to everything that ships, and to set the standard for how Information Security builds software with AI.
The platforms in this role will hold some of the most sensitive data in the company, including incident details, investigation evidence and security telemetry. They must therefore meet a higher security bar than a typical internal tool.
This role reports into the Information Security team led by the Deputy CISO and works closely with Security Operations and Incident Response, Product Security, Enterprise Architecture and IT. It suits a hands-on engineer who combines software development skills with genuine application security depth, and who has a background or strong interest in cyber security or product security.
Responsibilities
Building and Owning Security Applications
- Application Delivery — Design, build and deliver security applications using AI-assisted development, beginning with the Cyber Incident Response Platform. Translate requirements from Incident Response, Security Operations and Product Security into working, maintainable software.
- End-to-End Ownership — Own each application across its lifecycle, including architecture, roadmap, backlog, releases, documentation and eventual retirement. Act as the accountable owner and technical point of contact for the platforms you build.
- Maintenance and Support — Triage and resolve bugs, respond to production issues, and design and deliver new features and enhancements. Keep the applications reliable, performant and aligned to agreed service levels.
- Integration — Build and maintain secure integrations with SIEM, SOAR, EDR, ticketing, identity and data platforms using least-privilege service identities and well-governed APIs.
- Quality Engineering — Establish automated testing, code review, CI/CD and observability so that AI-generated code is verified rather than trusted, and so that changes can be released with confidence.
Owning the Application Security Lifecycle
- Secure SDLC — Define and operate the secure development lifecycle for the applications you own, including secure design, threat modeling, secure coding standards and pipeline security gates.
- Security Testing and Vulnerability Management — Run SAST, DAST, software composition analysis, secrets scanning and infrastructure-as-code scanning in the pipeline. Triage and remediate findings within defined timelines and track remediation to closure.
- Dependency and Supply Chain Security — Manage third-party dependencies, SBOMs, version pinning and package provenance. Defend against hallucinated, typosquatted or malicious packages introduced by AI tooling.
- Application Hardening — Implement strong authentication and authorization (including role-based access), secrets management, encryption, audit logging, data retention, and evidence integrity appropriate to incident response data.
- Independent Assurance — Support independent review of the applications you build through Product Security, peer review and third-party penetration testing. Remediate findings and maintain evidence to support internal and external audits.
Secure AI-Assisted Development
- Engineering Standards — Define, apply and continuously improve standards for AI-assisted development, including spec-driven workflows, mandatory human review of AI-generated code, test coverage expectations, approved tools and models, and prompt and context hygiene (no secrets or sensitive data in prompts).
- Securing the Tooling — Secure the coding agents and development environment, including scoped permissions, sandboxing, controls on MCP and tool access, and defenses against prompt injection through repositories, dependencies and external content.
- AI Features in Applications — Where applications embed LLM or agent capabilities, threat model them and apply OWASP guidance for LLM applications, including controls on data exposure and agent autonomy.
- Knowledge Sharing — Share patterns, templates and lessons learned with the wider security team and with other Teradyne teams looking to build with AI safely.
Cross-Cutting
- Cross-Functional Collaboration — Partner with Incident Response, Security Operations, Product Security, Enterprise Architecture, IT, Legal and Compliance to ensure the applications meet operational, regulatory and data governance requirements.
- Enterprise AI Governance Input — Provide technical input to Teradyne’s AI governance processes where application engineering expertise is needed, such as review criteria for AI tooling. This is a secondary responsibility.
- Documentation — Maintain architecture documentation, threat models, runbooks and decision records so that each application can be supported, audited and handed over without reliance on any one individual.
- Perform other duties as assigned.
Qualifications
Required
- Bachelor’s degree in Computer Science, Information Security, Engineering or a related field, or an equivalent combination of education and demonstrated experience.
- 5-7+ years of combined software engineering and application security experience, with a track record of building, shipping and supporting production applications, not only scripts or one-off tooling.
- Hands-on application security experience, including threat modeling, secure code review, and use of SAST, DAST and software composition analysis tools. Strong working knowledge of the OWASP Top 10 and API security risks.
- Strong proficiency in Python and at least one other modern language (for example TypeScript/JavaScript, C# or Go), with experience building backend services, APIs and user interfaces, and working with relational or document databases.
- Practical experience delivering software with AI coding assistants or agents (for example Claude Code, GitHub Copilot or Cursor), and a clear, demonstrable approach to validating AI-generated code for correctness, security and maintainability.
- Understanding of the security risks specific to AI-generated code and AI agents, such as insecure defaults, hallucinated dependencies, secrets leakage, prompt injection and excessive agency.
- Experience with Git, CI/CD pipelines, containers and infrastructure as code, and with securing them.
- Experience implementing secure authentication and authorization (for example OAuth 2.0 / OpenID Connect and role-based access control), secrets management, and secure API design.
- Experience building automated test suites (unit, integration and security tests) and applying them as release gates.
- Strong analytical and problem-solving skills, with the ability to work through ambiguity and make sound design decisions independently.
- Clear communicator, able to explain technical and security trade-offs to engineers, security analysts and leadership.
- Self-directed, with an ownership mindset and comfort being accountable for a platform from design through production support.
Preferred
- Background in, or strong interest in, cyber security or product security, such as secure product development, vulnerability handling (PSIRT / coordinated vulnerability disclosure), SBOM practices, or regulatory compliance such as the EU Cyber Resilience Act.
- Experience building or supporting incident response, case management, SOAR or SIEM-integrated tooling, and familiarity with incident response processes and evidence handling.
- Experience building LLM-based applications or agents, including agent frameworks and MCP-based tooling, and familiarity with OWASP guidance for LLM applications, MITRE ATLAS and the NIST AI Risk Management Framework.
- Familiarity with Microsoft Azure and Entra ID, and with deploying and securing cloud-hosted applications.
- Experience with DLP, EDR/XDR or SIEM platforms.
- Familiarity with security and compliance frameworks such as ISO 27001, NIST CSF or NIST SP 800-53, and experience producing audit evidence for applications.
- Relevant certifications such as CSSLP, GIAC (for example GWEB or GCSA), OSWE, CISSP, or cloud security certifications.
- Experience working within a distributed or offshore team model, collaborating across time zones with a US-based security leadership team.
We are only considering candidates local to position location and are unable to provide relocation for this position
This position is not eligible for visa sponsorship