About FirstPrinciples
FirstPrinciples is a research company building AI for scientific discovery. It began with Theo, the AI Physicist, and has since grown into a product-focused company with two additional systems including Theo Conjecture, built for automated conjecturing, and Theo Collaborator, an adaptive environment for doing complex research with AI.
We're a fast-growing, remote-first team of builders, researchers, engineers, and thinkers working across Canada, the US, the UK, and expanding globally. What brings us together is a shared curiosity about how the universe works, and a belief that we can build systems that help us explore it more effectively.
We spend our time working on questions that don't have clear answers, like how to design AI that can reason through scientific problems, and how the scientific process as a whole might evolve. This is work that sits somewhere between creativity and rigorous thinking, and often requires comfort with ambiguity and iteration. If you're someone who enjoys tackling big, abstract problems and exploring ideas that don't yet have a defined path forward, you'll likely find the work here interesting.
Why This Role Exists:
We are looking for a Staff Product Security Engineer to define and build the security architecture for Theo and the cloud platform surrounding it.
Theo combines our own AI models, agentic workflows, tool use, code execution, scientific data, model serving, and multi-tenant SaaS infrastructure. These systems create new trust boundaries—and new ways for powerful software to fail, be misused, or be attacked.
This is a hands-on software engineering and architecture role embedded within Engineering. It is not an IT, help-desk, security-operations, or policy-only position. You will review designs and code, build security-critical systems, test our platform adversarially, and help engineers make security a foundational property of the product.
As a senior technical owner, you will have substantial influence over our architecture, engineering practices, and security roadmap. Your goal will not simply be to identify risk or prevent releases. It will be to create secure defaults, reusable controls, and engineering systems that allow us to move quickly without compromising trust.
What You'll Do:
Define the security architecture for Theo. Design security across our SaaS application, APIs, cloud infrastructure, model-serving systems, agent runtimes, data platforms, research environments, and deployment pipelines.
Secure agent identity and authority. Build robust authentication and authorization for users, services, and AI agents, including scoped credentials, delegated permissions, least-privilege tool access, approval boundaries, tenant isolation, and auditable agent actions.
Secure tool and code execution. Help design hardened execution environments for agent-generated and user-provided code, with strong isolation, resource limits, filesystem and network controls, provenance, monitoring, and escape testing.
Lead threat modelling and secure design. Work with Engineering, Research, Product, and Infrastructure from early architecture through production. Identify trust boundaries, abuse cases, attack paths, and practical mitigations before systems ship.
Address AI- and agent-specific threats. Defend against prompt and goal injection, unsafe tool use, confused-deputy behaviour, context or memory poisoning, insecure output handling, model and data exfiltration, model extraction, privilege escalation, resource abuse, and attacks across multi-agent workflows.
Build security-critical software. Implement secure-by-default services, libraries, policies, test harnesses, and platform controls for identity, secrets, encryption, policy enforcement, auditability, abuse prevention, and vulnerability management.
Embed security into development. Integrate static application security testing (SAST) and dynamic application security testing (DAST), alongside dependency, container, infrastructure-as-code, secret, and software supply-chain scanning, into development and release workflows. Establish practical security reviews, release controls, SBOMs, artifact provenance, and automated security regression testing.
Test the platform adversarially. Conduct penetration tests, red-team and purple-team exercises, architecture attacks, and abuse-case testing across our applications, APIs, infrastructure, agents, tools, and model systems.
Own vulnerabilities through resolution. Assess real exploitability and impact, work directly with engineers on remediation, validate fixes, and eliminate recurring classes of weakness rather than producing reports that stop at the finding.
Protect our AI and scientific assets. Secure model weights, training and evaluation data, datasets, embeddings, registries, research artifacts, GPU infrastructure, and software supply chains against leakage, tampering, poisoning, and unauthorized access.
Build detection and response into the platform. Define the telemetry, alerting, containment, and forensic capabilities needed to understand and respond to incidents involving users, services, agents, models, and data.
Engineer compliance into the product. Translate SOC 2 and customer security requirements into real technical controls. Support FedRAMP and NIST SP 800-53 readiness where strategically relevant, and automate evidence collection and control validation wherever possible.
Raise the security capability of Engineering. Mentor engineers, establish reusable patterns, document architectural decisions, and communicate consequential risks clearly to technical teams and company leadership.
Who You Are:
You approach security as a software and systems engineering discipline. You are as comfortable writing production code and reviewing architecture as you are breaking systems.
You likely have:
7+ years of experience in product security, application security, cloud security, offensive security, or security-focused software engineering.
Strong software engineering ability in at least one production language such as Python, Go, Rust, or TypeScript.
Deep experience securing modern cloud and SaaS systems, including web applications, APIs, distributed services, databases, containers, Kubernetes, CI/CD, and infrastructure as code.
Strong knowledge of authentication, authorization, IAM, tenant isolation, secrets management, encryption, network boundaries, logging, and secure software supply chains.
Hands-on experience with threat modelling, architecture review, secure code review, vulnerability analysis, penetration testing, and remediation.
An attacker-informed mindset developed through authorized red teaming, white-hat research, bug bounties, consulting, internal product-security work, or similar experience.
A history of moving beyond findings to durable fixes: changing architectures, contributing code, building shared security systems, or eliminating vulnerability classes.
The judgment to balance security, product velocity, usability, and business risk without reducing security to either compliance or blanket prohibition.
The ability to influence critical decisions across teams without relying on formal authority.
Clear written and verbal communication, intellectual honesty, high agency, and comfort working where the threat model and correct architecture are still emerging.
Bonus if you have:
Security experience with LLM applications, agentic systems, RAG, tool use, MCP integrations, code-generating systems, or multi-agent orchestration.
Experience designing secure sandboxes, delegated authorization systems, machine identities, or fine-grained policy enforcement.
Experience securing model training, evaluation, inference, model registries, datasets, embeddings, or GPU and Kubernetes infrastructure.
Experience implementing technical controls for SOC 2 Type II, FedRAMP, or NIST SP 800-53.
Published vulnerability research, CVEs, meaningful bug-bounty findings, open-source security tools, or participation in respected security communities.
Deep systems and network security expertise across Linux/Unix internals, TCP/IP, DNS, routing, firewalls, proxies, and VPNs, with hands-on offensive-security experience and the ability to design and test isolated cloud environments using technologies such as AWS PrivateLink, VPC endpoints, private subnets, and tightly controlled ingress and egress with no public network exposure.
Experience establishing product security architecture in a high-growth startup, frontier technology company, or research environment.
What Success Looks like:
Within your first year:
Theo has a clear, risk-based product and platform security architecture.
Critical agent, identity, tool-use, data-access, and code-execution paths have explicit boundaries, enforceable controls, and adversarial test coverage.
Engineering teams have secure-by-default components and workflows that prevent recurring vulnerabilities without creating unnecessary friction.
Security testing is integrated into product delivery, with clear ownership and measurable remediation.
SOC 2 controls are reflected in how the platform actually operates, with a credible technical path toward FedRAMP readiness should our strategy require it.
Why FirstPrinciples
You will help define security for a new kind of scientific instrument.
The systems we are building may reason over sensitive research, use powerful tools, execute code, and act on behalf of users. Securing them requires more than applying a conventional SaaS checklist. It requires first-principles thinking across AI, identity, distributed systems, cloud infrastructure, adversarial behaviour, and scientific integrity.
This is an opportunity to shape foundational architecture rather than inherit a finished security program. Your work will directly determine how confidently researchers and organizations can use increasingly capable AI systems to pursue difficult scientific questions.
Please submit a resume and a brief description of a security architecture, product-security system, or authorized offensive-security project that demonstrates how you think.