About Decagon
Decagon is the leading conversational AI platform empowering every brand to deliver concierge customer experience. Our AI agents provide intelligent, human-like responses across chat, email, and voice, resolving millions of customer inquiries across every language and at any time.
Since coming out of stealth, Decagon has experienced rapid growth. We partner with industry leaders like Hertz, Eventbrite, Duolingo, Oura, Bilt, Curology, and Samsara to redefine customer experience at scale. We've raised over $200M from Bain Capital Ventures, Accel, a16z, BOND Capital, A*, Elad Gil, and notable angels such as the founders of Box, Airtable, Rippling, Okta, Lattice, and Klaviyo.
We’re an in-office company, driven by a shared commitment to excellence and velocity. Our values—customers are everything, relentless momentum, winner’s mindset, and stronger together—shape how we work and grow as a team.
About the Team
The Security Engineering team at Decagon protects the platform that powers the most advanced conversational AI agents for enterprise customers across voice, chat, email and SMS. We build the security foundations that enable Decagon's AI agents to handle sensitive customer data with trust while defending against sophisticated, AI-enabled threats at massive scale.
Our mission is to provide magical support experiences — ensuring that AI agents and human agents can collaborate safely to help users resolve their issues while maintaining the highest standards of security and privacy.
About the Role
Lead the application security strategy and implementation for Decagon AI's conversational platform that serves enterprise customers at scale. You'll partner with engineering teams to build security directly into our AI-powered applications, ensuring protection against application-layer threats while maintaining the performance and reliability our customers expect. This role offers the opportunity to apply deep application security expertise to AI systems and shape security practices across our rapidly growing engineering organization.
In this role, you will
Design and implement application security controls across our AI agent platform, including secure coding practices, threat modeling, and vulnerability management.
Collaborate closely with product engineering teams to integrate security throughout the software development lifecycle, from design, coding, PR, and deployment
Establish application security testing programs including static analysis (SAST), dynamic analysis (DAST), and interactive testing (IAST) tailored for AI applications
Lead security code reviews and architecture assessments for new features, with special focus on AI model integration points and customer data handling
Build security tooling and automation to enable developers to identify and remediate vulnerabilities quickly while maintaining development velocity
Respond to security incidents involving application vulnerabilities, coordinating remediation efforts and post-incident improvements
Your background looks something like this
Have 5+ years of hands-on application security engineering experience
Expertise in secure software development practices, including threat modeling, secure code review, and vulnerability assessment
Strong software engineering background with ability to review code across multiple languages and frameworks commonly used in AI/ML applications
Experience implementing application security testing tools and integrating security into CI/CD pipelines
Knowledge of OWASP Top 10, common application vulnerabilities, and modern application security frameworks
Proven track record working with engineering teams to remediate security findings while balancing security and business requirements
Even better
Experience securing AI/ML applications, including prompt injection, model extraction, and adversarial input protections
Background with large-scale, multi-tenant SaaS applications handling sensitive customer data
Familiarity with Google Cloud application security services and container security best practices
Knowledge of enterprise compliance requirements (SOC 2, ISO 27001, GDPR) from an application security perspective
Experience with modern security tools like Semgrep, CodeQL, Cursor Bug Bot, XBOW, or similar
Benefits:
Medical, dental, and vision benefits
Take what you need vacation policy
Daily lunches, dinners and snacks in the office to keep you at your best
Compensation $240K – $330K + Offers Equity
If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.
Lead cross-functional strategic projects and operational programs to accelerate growth and scale for Decagon’s Agent Product team in a fast-paced, in-office San Francisco environment.
As Senior Network Advanced Services Engineer at Arista Networks, you will lead design, deployment, migration, and automation efforts for large-scale Arista solutions while serving as a strategic, customer-facing technical advisor.
AWP seeks a detail-oriented Traffic Planner I in North Canton to design MUTCD-compliant temporary traffic control plans, coordinate permits and agency reviews, and support safe project implementation.
Kimley-Horn is seeking a seasoned Project Manager/Civil Engineer in Orange, CA to lead site development and project delivery for healthcare land-development projects.
Lead and grow the production engineering team for Boeing's F/A-18 SLM program in San Antonio to improve production systems, manage technical authority, and support customer and supplier engagement.
Experienced Electrical Engineer needed in Baltimore to lead lighting control system design and support electrical control and switchgear projects in a hybrid, client-facing role.
Timmons Group is hiring a hands-on Survey Crew Chief in Ashburn, VA to lead field crews and deliver precise boundary, topo, and construction staking surveys.
Join a nimble robotics team as an onsite Field Technician in Rochester, MN, responsible for diagnostics, repairs, and maintenance to keep a fleet of collaborative robots operating at peak performance.
Experienced or early-career civil engineers with FDOT roadway design experience and proficiency in MicroStation OpenRoads Designer are invited to contribute to Dewberry’s Orlando transportation team focused on roadway geometrics, plan production, and construction support.
Experienced Electrical Engineer needed to perform electrical drafting and design reviews for the PPTT training simulator program at Bettis Atomic Power Laboratory in West Mifflin, PA.
Lead AI-informed cloud and SaaS cost optimization, building dashboards, automation, and governance to drive accountable, data-led spend decisions across the organization.
Rolls-Royce Power Systems is hiring a Sr. Applications Engineer in Mankato to specify, size and validate power generation and hybrid systems for customer-specific projects.
Join Kimley-Horn's Oklahoma City Water/Wastewater team as a Civil Engineering Analyst to support municipal water and wastewater design projects and develop professionally through mentorship and hands-on project work.
Experienced electrical engineer needed to design and deliver power, motor control, and lighting systems for water/wastewater projects within Dewberry’s Nashville MEPS Infrastructure team.