About the company
Cohere is the leading security-first enterprise AI company. We build cutting-edge foundation AI models and end-to-end products that are designed to solve real-world business problems.
We are a global technology company headquartered in Toronto with key offices in London, New York City, San Francisco, Montreal, Paris, Berlin and Seoul.
Responsibilities
- Serve as trusted advisor to team’s leadership and partner teams by clearly articulating business risks associated with security issues.
- Execute the long-term vision for the Security team in alignment with Cohere’s product and business goals.
- Collaborate closely with leadership to prioritize high-impact initiatives and strategic customer engagements.
- Vulnerability Management: Develop and implement enterprise-wide vulnerability management processes and tooling, including identification, prioritization, remediation tracking, and reporting, including customer artifacts.
- Static Application Security Testing (SAST): Establish SAST programs, integrate tools into CI/CD pipelines, and analyze results to identify and remediate security flaws in source code.
- Dynamic Application Security Testing (DAST): Implement DAST methodologies, configure scanning tools, and conduct regular assessments of running applications.
- Penetration Testing: Lead and oversee internal and external penetration testing engagements, including web application, API, network and agentic AI platform including managing our bug bounty program.
- Security Architecture Review: Collaborate with development teams to review and validate security architecture and design patterns.
- Secure SDLC Integration: Embed security practices throughout the software development lifecycle, working closely with engineering and product teams.
- Team Leadership: Lead and grow a high-performing team of Security engineers through hiring, coaching, and mentorship.
- Metrics and Reporting: Establish key security metrics, generate regular reports for leadership, and communicate security posture to stakeholders.
- Compliance and Standards: Ensure application security practices align with industry standards (OWASP Top10 for LLMs, ISO 27001) and regulatory requirements.
Requirements
- 8+ years of previous experience in Application Security / Security Engineering with a strong focus on vulnerability management, SDLC and bug bounty programs.
- Proven experience with SAST, DAST, and penetration testing methodologies and tools.
- Proficiency with programming languages (Python, GoLang, etc.) and web technologies.
- Experience with cloud platforms (AWS, GCP, Azure) and container security.
- Excellent communication and interpersonal skills with ability to influence technical and non-technical stakeholders.
- Experience building and managing high-performing security teams.
- Comfortable with ambiguity and able to make informed decisions with little data.
- Employ a flexible and constructive approach when solving problems.
- Able to make trade-offs between build vs. buy decisions—help build solutions and be able to review what tools are available.
- Understand secure engineering best practices, can articulate problem statements, and propose solutions to both technically savvy and non-technical audiences.
- Deep technical understanding of common security vulnerabilities and risks, as well as countermeasures and compensating controls.
Conditions
- Remote US or Canada.
- A weekly lunch stipend of $75/£75 or equivalent in your local currency for lunch.
- Full health and dental benefits, including a separate budget for mental health.
- RRSP matching, 401K, Pension Scheme.
- 100% Parental Leave top-up for up to 6 months, for either parent.
- Annual enrichment benefits: Arts & culture, fitness/wellness, quality time, and a workspace improvement credit.
- Education & learning stipend for conferences, courses, and coaching.
- 6 weeks of paid vacation (30 working days!)
- Budget for traveling to other offices if you are remote, plus an annual company offsite.
- Cohere is remote-friendly, but we also have offices in Toronto, London, New York City, San Francisco, Montreal, Paris, Berlin and Seoul with more opening soon.
- For those in the office: a daily lunch program, plenty of snacks, and regular community and social events.
- For those not near an office: a co-working benefit so you can work alongside others in your city.
- Everyone receives a $500 home office stipend to set up your workspace properly.