--- title: 'AI Application Security Engineer at Brain Co.' canonical: 'https://feeny.ai/job/ai-application-security-engineer-brain-co-san-francisco-f97wctm0er5y' type: 'job' last_seen: '2026-09-09' --- # AI Application Security Engineer at Brain Co. - **Company:** Brain Co. - **Location:** San Francisco, CA - **Employment:** full-time - **Work type:** hybrid - **Posted:** 2026-05-07 - **Last confirmed live:** 2026-09-09 - **Apply:** https://jobs.ashbyhq.com/brainco/46cacd55-81d9-414c-9fcb-c8be15d94e4a/application **Skills:** Application Security, OWASP Top 10, AuthN/AuthZ, Secure SDLC, Secrets Management, Cryptography, Threat Modeling, CI/CD, API Security, AI/Native Security, Agent Security, LLM Application Security, Authorization Systems, FedRAMP, HIPAA, SOC 2, ISO 27001, Python, Go, TypeScript > Own the security of AI products and application layers by embedding security into the development lifecycle. Write code, ship security tooling, and collaborate with product and ML engineers to build secure-by-default patterns, manage agent security, and protect sensitive data in regulated environments. ## Job description ## OUR MISSION Rebuild how the world works, to make institutions work better for the people they serve. ABOUT BRAIN CO. Brain Co. builds AI-native operating systems for large, regulated institutions. Each system is built for a specific industry, powered by agents that push real workflows forward. Underneath it all is Atlas, our proprietary platform that keeps customers in control, secure by design, and never locked into one model. ## WHY NOW Brain Co. is entering its next phase of production deployments on a national scale with an elite team built from Palantir, Google, Meta, and Nvidia, and a growing footprint across government, insurance, health, and financial services. Joining now means shaping both the company and a new category of applied AI. Every project here ships to production and is expected to create measurable customer value and impact. You'll work alongside exceptional peers on some of the hardest problems in applied AI. It’s the kind of work you'll still be proud of in ten years from now. ## ABOUT THE ROLE As our Security Engineer, Application & AI, you will own the security of our products and application layer — secure development practices, agent security, third-party integration security, and data protection for AI products operating in some of the world's most regulated and sensitive environments. This is a hands-on builder role. You will write code, ship security tooling, and work directly with product and ML engineers to build security in from the start rather than bolt it on after. You are expected to work AI-natively: using AI to write threat models, automate security review, scale code analysis, and build internal tooling. This is not a nice-to-have — it is how the role is designed to operate and how one person can have outsized impact across a fast-moving engineering organization. Brain Co.'s products are built on agentic infrastructure — AI that takes actions, calls tools, and operates inside complex institutional workflows. The degree varies by product, but the underlying security surface is consistent: how agents are authorized, what they can touch, and how that is controlled at the application layer. This role is specifically designed to address that surface, working alongside the Infrastructure Security Engineer who owns the platform layer underneath. ## WHAT YOU'LL WORK ON Application Security - Own secure development practices across our products: AuthN/AuthZ patterns, secrets management, input handling, and secure-by-default standards that engineers can follow without security becoming a bottleneck. - Integrate security into the development lifecycle — code review, CI/CD pipelines, and pre-deployment checks — catching risk before it reaches production. - Conduct threat modeling across product features and release cycles, translating risk into concrete controls that ship alongside each product. - Build and maintain security tooling and automated checks that scale your reach across the codebase — using AI to move faster and cover more ground than manual review alone could. Agent & Integration Security - Own the application-layer security model for Brain Co.'s agentic products — how agents are scoped, what they are authorized to do on behalf of users, and where trust boundaries sit between the agent and the external systems it touches. - Define secure patterns for how agents integrate with third-party systems and APIs: how credentials are stored and scoped, how responses are validated before being acted on, and how each product limits what agents can do with what they get back. - Work directly with product and ML engineers during feature development to define secure agent design patterns: tool scoping, permission boundaries, output validation, and safe handling of user context across multi-step workflows. - Build reusable secure-by-default patterns for agent development — design guidelines, review checklists, and code-level guardrails — so that security standards scale as new agent capabilities are built. - Produce security artifacts for agent features and product deployments: threat models, architecture reviews, and documentation that supports delivery into regulated customer environments. Data Protection - Define and enforce data protection standards at the application layer — ensuring sensitive customer data (PHI, PII, government records) is handled correctly as it flows through AI pipelines and surfaces in agent outputs. - Build safeguards against unauthorized data exposure across our products: access controls, output filtering, and audit logging that make data handling attributable and reviewable. - Design secure data handling patterns for AI features operating on regulated data, working with platform and ML teams to ensure the application layer upholds its share of the data protection contract. YOU MIGHT BE A GREAT FIT IF YOU... - Have 5+ years of experience in application security or product security, with hands-on experience on production systems at scale. - Are a builder first — you write code and ship security tooling, and see embedding security into the engineering workflow as the job, not a side effect of it. - Have deep fluency in application security fundamentals: OWASP Top 10, AuthN/AuthZ, secure SDLC, secrets management, secure integration patterns, and cryptography basics. - Understand the security surface of agentic AI across the product layer — how agents should be designed, scoped, and reviewed for risk — and can work shoulder-to-shoulder with engineers to build those standards in. - Have experience protecting sensitive data at the application layer: access controls, audit logging, and preventing data exposure through third-party integrations and AI-generated outputs. - Work AI-natively — you already use AI to write better code, move faster, and do more with less, and you bring that same instinct to security work. - Think in attack surfaces and trust boundaries and can move cleanly from threat model to concrete shipped control. - Are comfortable working alongside delivery teams shipping into regulated industries, understanding their constraints and translating them into product-level security requirements. - Thrive in high-agency environments and want to own and grow the application security function as the company scales. ## BONUS POINTS FOR - Experience with agent security, LLM application security, or building authorization and guardrail systems for agentic pipelines. - Familiarity with compliance frameworks relevant to government and healthcare: FedRAMP, HIPAA, SOC 2, ISO 27001. - Proficiency in Python, Go, or TypeScript for security tooling and automation. - Experience with SAST/DAST tooling or integrating automated security checks into developer workflows at scale. ## WHY JOIN US - Define what application and AI security looks like at a company building frontier AI for governments, hospitals, and critical industries — from the ground up. - Work directly alongside product and ML teams shipping agentic AI into some of the world's most demanding institutional environments. - Build the security function AI-natively — using the same technology you're helping secure to scale your own work and impact. - Work alongside senior engineers from Tesla, DeepMind, Databricks, and other top engineering organizations. - Ship fast, learn constantly, and see your work protect production systems used by millions of people. - Earn competitive compensation and meaningful equity in a high-growth company. ## BENEFITS - Competitive salary plus equity - Daily lunches - Commuter benefits - 401(k) - Medical, Dental, and Vision - Unlimited PTO ## About Brain Co. ## Company Overview - **One-liner**: Brain Co. builds applied AI platforms and applications that automate complex, manual workflows for the world’s most important institutions, turning permitting, insurance, supply chain, and patient-care processes from months-long bottlenecks into minutes-long transactions. - **Entity Type**: Private (Series A) - **Headquarters**: San Francisco, California, United States (also offices in the United Arab Emirates, United Kingdom, and Spain) - **Founded**: 2024 (founding conversation in February 2024; public launch in 2025) - **Founders**: Jared Kushner, Dan Ashton (CEO), Elad Gil, Dr. Luis Videgaray, Eric Wu, Mircea Pasoi, Revant Kapoor ## Core Business - **Primary industries**: Artificial intelligence, government technology, healthcare, insurance, energy, hospitality, supply chain logistics - **Target customers**: Global 2000 enterprises, federal/state governments, large healthcare systems, insurance carriers (B2B / Enterprise) - **Mission or purpose statement**: “Empower the world’s most important institutions to create an abundant AI future” and “reinvent the broken processes that hold governments and institutions back.” ## Products & Services - **Permitting**: Automates construction and other permitting workflows, cutting the process from months to minutes (claims 99% faster, $375M+ unlocked annually). SaaS / AI workflow platform. - **Specialty Insurance**: Cuts complex underwriting and adjusting workflows from hours to minutes. AI-powered decision engine. - **Supply Chain**: Optimizes end-to-end supply chain operations, delivering 30% lower cost, 99% reliability, and mitigating $100M+ in lost revenue. Integrated AI platform. - **Patient Pathways**: Automates patient care-path management, returning patients to optimal care faster. Healthcare AI application. - **General AI Platform**: An underlying platform that automatically incorporates advances in foundation models, enabling applications to stay current without traditional re-development. ## Market Standing - **Valuation/Market Cap**: Not publicly disclosed (private company; Series A at $30M raised) - **Key Metric**: $30 million total funding (Series A, led by Elad Gil and Affinity Partners, announced October 2025) - **Notable Investors/Partners**: - Lead investors: Elad Gil (Gil Capital), Affinity Partners - Strategic partner: OpenAI - Angel investors include Ali Ghodsi (CEO Databricks), Andrej Karpathy, Aravind Srinivas (CEO Perplexity), Brian Armstrong (CEO Coinbase), Kevin Weil (CPO OpenAI), Reid Hoffman, Patrick Collison (CEO Stripe), Sarah Guo (Conviction), and many more. - **Growth Signals**: - Headcount: 73 employees (LinkedIn, June 2026), monthly growth of +20.2%, quarterly job posting growth +47.4% - 10+ Global 2000 customers and multiple government engagements - $375M+ annual value unlocked in permitting alone; $100M+ supply chain revenue loss mitigated - Strategic partnership with OpenAI for model access and co-innovation - Engineering talent sourced from Stripe, Palantir, Amazon, Adobe, Roblox, and Alchemy ## Competitive Advantages - **Outcome-based pricing**: Revenue model tied to client results, not software licenses – clients pay based on value delivered. - **Production deployment, not pilots**: Every engagement begins with a value case; solutions go straight into production. - **Domain-expertise embedded**: Subject matter experts in each vertical (government, insurance, healthcare) work alongside AI engineers to build around specific rules, regulations, and workflows. - **Future-proof AI**: Applications automatically incorporate new capabilities from foundation models as they are released, avoiding obsolescence. - **Enterprise-grade security**: SOC 2 and HIPAA-ready infrastructure with hallucination controls and guardrails. ## Strategic Focus - Scale the platform across additional government and enterprise verticals (e.g., energy, hospitality) - Deepen the partnership with OpenAI to rapidly leverage newest model capabilities - Expand headcount (28 active job postings, especially in AI engineering, infrastructure, security, and deployment) - Extend presence in the Middle East (Qatar, UAE) and Europe (UK, Spain) - Continue building a new software-development paradigm where applications auto-update with AI advances ## Why Work Here - **Culture**: “World-class talent built to deliver applied AI in production.” The team includes engineers from Tesla, NVIDIA, DeepMind, and top tech companies. Emphasis on solving hard, high-impact problems for the largest institutions. - **Remote/hybrid/office**: Not explicitly stated, but headquarters in San Francisco with distributed teams in UAE, UK, and Spain. Likely a hybrid or office-first model given the nature of client engagements. - **Notable perks or engineering culture**: - Outcome-driven work: every project tied to measurable value cases - Direct partnership with OpenAI and access to cutting-edge models - High-caliber co-founders (Kushner, Gil, Videgaray, Wu) and leadership (Marne Levine, former COO Instagram/Meta) - Rapidly growing (~73 people, +20% monthly headcount growth) – offers early-stage ownership - Roles span AI platform engineering, agentic systems, infrastructure, security, and deployment consulting ## Sources 1. [brain.co](https://brain.co/) – Main site overview 2. [brain.co](https://brain.co/blog/introducing-brain-co-9gk9a) – Introducing Brain Co. blog post (funding, founders, investors, customers) 3. [braincompany.ai](https://braincompany.ai/about) – About page (team, approach, security) 4. [linkedin.com](https://www.linkedin.com/company/brainco-ai/jobs) – LinkedIn company page (headcount, growth, job postings, talent sources) 5. [jobs.ashbyhq.com](https://jobs.ashbyhq.com/brainco/) – Careers page (open positions) ## Other roles at Brain Co. - [Product Manager, Financial Services](https://feeny.ai/job/product-manager-financial-services-brain-co-san-francisco-3fa24156j0vd) — San Francisco, CA - [Private Equity Engagement Lead](https://feeny.ai/job/private-equity-engagement-lead-brain-co-san-francisco-dsr10m5g52v2) — San Francisco, CA - [Specialty Insurance Underwriter/Coverage Attorney/Consultant/Professional (Contract)](https://feeny.ai/job/specialty-insurance-underwriter-coverage-attorney-consultant-professional-qwspr442emtg) - [Commercial/Transactional Lawyer](https://feeny.ai/job/commercial-transactional-lawyer-brain-co-remote-4aeem8qsj0cn) - [Machine Learning Engineer, Platform](https://feeny.ai/job/machine-learning-engineer-platform-brain-co-san-francisco-3b4v2yrmrnjd) — San Francisco, CA - [Full Cycle Technical Recruiter](https://feeny.ai/job/full-cycle-technical-recruiter-brain-co-san-francisco-wwne111bgb3d) — San Francisco, CA - [Machine Learning Engineer, Applied AI - Deployed](https://feeny.ai/job/machine-learning-engineer-applied-ai-deployed-brain-co-london-8n2mv9qr9d3v) — London, United Kingdom - [AI Product Engineer, Deployed](https://feeny.ai/job/ai-product-engineer-deployed-brain-co-london-wknmh7b52szs) — London, United Kingdom - [AI Deployment Lead](https://feeny.ai/job/ai-deployment-lead-brain-co-abu-dhabi-dyvjtkbpcb7h) — Abu Dhabi, United Arab Emirates - [AI Platform & Infrastructure Engineer, Deployed](https://feeny.ai/job/ai-platform-infrastructure-engineer-deployed-brain-co-abu-dhabi-w9efm94wfs0s) — Abu Dhabi, United Arab Emirates