📋 Job Overview
Obsidian Security is the leading SaaS security platform, trusted by global enterprises like Snowflake, T-Mobile, and Algolia. We protect 200+ organizations across North America, Europe, the Middle East, Southeast Asia, Australia, and New Zealand, including many of the world’s largest Fortune 1000 and Global 2000 companies.
Founded in 2017 and backed by top investors like Greylock, Obsidian was built to close a critical gap: securing SaaS apps where business happens—Microsoft 365, Salesforce, and hundreds more. The company does this by offering a complete SaaS security platform to reduce risk, detect and respond to threats, and prevent breaches at the source. Obsidian was built by leaders who redefined endpoint and identity security at CrowdStrike, Okta, Cylance, and Carbon Black. Now, they’re transforming how SaaS is secured.
With AI driving rapid SaaS growth and complexity, agentic AI tools gain privileged access to sensitive data through integrations, creating new risks most security tools miss. Obsidian uniquely detects anomalous OAuth token activity and manages integration risks. Major announcements are on the horizon. Recognizing that SaaS security needs to evolve, Obsidian enables growing organizations to start with a lightweight, prevention-focused browser extension and expand coverage over time.
With global momentum, a growing partner ecosystem including SentinelOne, Databricks, and Google Cloud, and a major fundraise ahead, Obsidian is scaling rapidly toward long-term growth and IPO readiness.
🏢 About Obsidian Security
Obsidian Security sits directly in the path of this shift.
🎯 The Role
As an AI Security Engineer in Taiwan, you will help define how Obsidian discovers, understands, and mitigates risks across AI and agentic platforms. You will research emerging threats, develop security and data models, and build highly available products that protect enterprise customers.
This is a hands-on role at the intersection of security research, data engineering, and product development. You will work directly with security telemetry and production systems because, in this rapidly evolving space, security judgment, data analysis, and engineering execution are inseparable.
You will collaborate closely with Security Research, Detection Engineering, Product Management, Data Platform, and Site Reliability Engineering teams across Taiwan, the US, the UK, and Australia.
✅ Key Responsibilities
- Research emerging AI security threats, including prompt injection, tool and agent misuse, RAG poisoning, insecure plugins, excessive agency, data leakage, over-permissioned integrations, and compromised non-human identities.
- Design data models that represent AI assets, identities, access relationships, permissions, activities, risks, and attack paths.
- Prototype and deliver production-grade AI security products and capabilities.
- Build backend services and APIs for AI asset discovery, security analysis, risk assessment, detection, investigation, and remediation.
- Build scalable pipelines that ingest, normalize, enrich, correlate, and analyze high-volume security telemetry.
- Write queries and analysis logic that transform raw activity and configuration data into actionable security findings.
- Develop detection rules and behavioral models for suspicious AI and agentic activity.
- Evaluate APIs, audit logs, authentication mechanisms, OAuth permissions, and security controls provided by AI platforms.
- Work with Product Management and customers to understand emerging use cases and turn ambiguous security problems into practical product capabilities.
- Partner with Detection Engineering and Security Research to validate threat hypotheses and improve detection coverage.
- Collaborate with platform and SRE teams to ensure services are secure, observable, highly available, and operationally efficient.
- Improve engineering productivity, pipeline performance, development velocity, and cloud cost efficiency.
- Contribute to technical designs, code reviews, testing strategies, operational readiness, and engineering standards.
- Share research and technical knowledge with engineering teams and help shape Obsidian’s long-term AI security strategy.
📌 Required Qualifications
- Hands-on programming experience in one or more languages such as Python, Go, Java, Kotlin, or a comparable backend language.
- Experience designing and building scalable APIs, distributed systems, or data-processing pipelines.
- Strong data analysis skills and the ability to investigate complex behavior using SQL or other query languages.
- Familiarity with cloud infrastructure, SaaS platforms, identity systems, authentication, authorization, and OAuth.
- Understanding of security fundamentals, including identities, permissions, access controls, vulnerabilities, attack techniques, and risk assessment.
- Ability to translate ambiguous security risks into clear threat models, data requirements, and production capabilities.
- Strong engineering judgment across scalability, reliability, security, performance, maintainability, and cost.
- Curiosity and a willingness to rapidly learn unfamiliar AI platforms, APIs, security models, and attack techniques.
- Ability to work independently while collaborating effectively with security researchers, product managers, and engineers.
- Strong written and verbal communication skills in English.
⭐ Desirable Experience
- Experience building cybersecurity, identity security, SaaS security, threat detection, SIEM, EDR, XDR, or security analytics products.
- Familiarity with AI security risks such as prompt injection, RAG poisoning, insecure tool use, model abuse, excessive agency, and sensitive-data disclosure.
- Experience developing detection rules, behavioral analytics, risk models, or attack-path analysis.
- Experience with large-scale streaming or batch-processing technologies.
- Experience using machine learning or generative AI to analyze security data or automate investigations.
- Contributions to security research, open-source projects, technical publications, or responsible vulnerability disclosures.
- Experience collaborating with globally distributed engineering teams.
- Mandarin proficiency.
🎁 Benefits
Obsidian Security offers a competitive compensation package, including salary, equity, and benefits. The company provides a comprehensive benefits package that may include health insurance, retirement plans, paid time off, and professional development opportunities. Specific details about the compensation and benefits package are not provided in the job posting.
🛂 Visa & Eligibility
No specific information about visa sponsorship or eligibility requirements is provided in the job posting.