About the job
Join Our Team as a Senior Security Engineer
At LiteLLM, the leading AI Gateway trusted by industry giants such as Adobe, Netflix, and NASA, we empower developers with secure and reliable access to LLMs and associated services. We are seeking a talented Senior Security Engineer to establish robust security measures and observability tools as we scale our platform.
Your Role:
Become a cornerstone of our security team as our inaugural Security Engineer, tackling pivotal security challenges head-on.
Key Responsibilities:
Perform in-depth security assessments of the LiteLLM proxy codebase to uncover potential supply chain vulnerabilities.
Develop and manage automated security scans for our Docker images, PyPI packages, and CI/CD workflows (including dependency scanning and secrets detection).
Create and enforce secure-by-default configurations for both cloud and self-hosted environments (API authentication, IAM least privilege, key rotation).
Implement and oversee intrusion detection systems and alerts tailored to model and API usage patterns.
Lead incident response efforts and post-mortem analyses, including vulnerability assessments and stakeholder communication.
Establish a formal CVE triage and disclosure protocol in collaboration with the engineering team.
Conduct internal red teaming and adversarial testing to simulate real-world attacks and enhance our defenses.
Collaborate with engineering teams to fortify release pipelines (signed builds, provenance checks, reproducible builds).
Develop secure coding standards and conduct regular training sessions for developers focused on supply chain and dependency management.
Maintain and update threat models as LiteLLM’s products and architecture evolve.

