--- title: 'Staff Security Engineer at LiveKit' canonical: 'https://feeny.ai/job/staff-security-engineer-livekit-north-xe9qpkekq0ea' type: 'job' last_seen: '2026-09-06' --- # Staff Security Engineer at LiveKit - **Company:** LiveKit - **Location:** North, United States - **Compensation:** $150k–$250k - **Employment:** full-time - **Work type:** remote - **Posted:** 2026-09-04 - **Last confirmed live:** 2026-09-06 - **Apply:** https://jobs.ashbyhq.com/livekit/efc06ff8-37c4-473e-8de8-bbba56cf0479/application **Skills:** Secure Coding, Threat Modeling, Vulnerability Management, CI/CD, Cloud Platforms, AWS, GCP, Container Security, API Security, WebRTC Security, Media Pipelines, Real-time Systems, Static Analysis Tools, Dynamic Analysis Tools, Fuzzing, Sandboxing, Open Source Security Tooling > The Staff Security Engineer owns security across the stack, including applications, services, and infrastructure. This role involves proactively identifying and mitigating risks, leading secure code reviews, and hardening the platform from top to bottom through proactive measures rather than just compliance checks. ## Job description ## ABOUT LIVEKIT LiveKit is building the infrastructure layer for the agentic era of computing. Our platform gives developers everything they need to build, test, deploy, scale, and observe AI agents in production. Founded in 2021, LiveKit powers voice and agentic AI applications for OpenAI, Salesforce, Spotify, Meta, and tens of thousands of other developers, collectively facilitating billions of calls each year. ## ABOUT THIS ROLE This isn't one of those roles where "security" means running scans or writing policies that gather dust. We're looking for a real engineer — someone who thinks like a builder and a breaker. Someone who gets deep into the stack, whether it's an API endpoint, a container image, or a browser sandbox. You know how things are supposed to work — and what happens when they don't. While some security professionals lean toward policy, compliance, or audits (and we value that too), we're after someone who wants to write code, secure systems, dig into strange bugs, and harden the platform from top to bottom. This is not a role for pointing out what needs to be done. It's for someone who's ready to do it. ## YOU'LL THRIVE HERE IF YOU: - think like both a builder and a breaker, and understand security from first principles - can analyze systems for weaknesses — whether they're in business logic, configuration, or code - translate security concerns into engineering action without being the "no" person - are an excellent communicator who can document and evangelize best practices across the org - stay current with security research, tooling, and threats — and put that knowledge into action ## WHAT YOU'LL DO - Own security across the stack — applications, services, infrastructure, and developer workflows - Proactively identify, assess, and mitigate risks in both infrastructure and application codebases - Lead secure code reviews, architecture discussions, and threat modeling sessions - Build tooling and automations that help prevent security issues before they reach production - Harden authentication and access control across internal and external surfaces - Partner closely with engineers across teams to design secure-by-default APIs, workflows, and deployments - Investigate vulnerabilities, respond to security incidents, and manage disclosure processes when needed ## WHO YOU ARE - 6+ years of experience as a software engineer with a strong interest in security engineering - You've led or heavily contributed to security engineering efforts across applications, infrastructure, or both - Experienced with threat modeling, secure coding practices, and vulnerability management - Worked with CI/CD systems, cloud platforms (AWS, GCP, etc.), and containerized environments - You've responded to real-world security incidents, led postmortems, or driven remediation efforts ## NICE TO HAVE - Experience with security reviews of WebRTC, media pipelines, or real-time systems - Contributions to open-source security tooling or research - Hands-on experience with static and dynamic analysis tools, fuzzing, or sandboxing - You've built (or tried to build) something with LiveKit ## OUR COMMITMENT TO YOU - An opportunity to build something truly impactful to the world - Contribute to open source alongside world-class engineers - Competitive salary and equity package - Health, dental, and vision benefits - Flexible vacation policy LiveKit is an equal opportunity employer and does not discriminate on the basis of any characteristic protected by applicable law. If you require a reasonable accommodation during the application or interview process, please contact recruiting@livekit.io. ## About LiveKit ## Company Overview - **One-liner**: LiveKit provides an open-source framework and cloud platform for building, deploying, and scaling voice, video, and physical AI agents. - **Entity Type**: Private (Series C) - **Headquarters**: San Jose, California, United States - **Founded**: 2021 - **Founders**: David Zhao (Co-Founder and CTO) ## Core Business - **Primary industry/industries**: Developer Infrastructure, Real-Time Communications (RTC), Voice AI, Video AI, Robotics - **Target customers**: B2B; Developers, AI labs, robotics teams, and enterprises (including Fortune 500 companies) building real-time multimodal AI applications. - **Mission or purpose statement**: To build the infrastructure for the voice-driven era of computing, making it possible for every developer to build AI that can interact with the world in real time. ## Products & Services - **LiveKit Cloud**: A hosted, managed platform for deploying and scaling AI agents globally. It provides a global real-time media server network with sub-1000ms latency and 99.99% uptime, handling millions of concurrent calls. Includes telephony integration (phone numbers, SIP), full-stack observability, and an inference gateway for TTS, LLM, and STT models. - **LiveKit Agents Framework**: An open-source, high-level framework (Python/Node.js) for building AI agents. It includes tools for automatic turn detection, interruption handling, voice activity detection (VAD), and a plugin system for connecting to various AI providers. - **LiveKit Server (Open Source)**: The core open-source WebRTC Selective Forwarding Unit (SFU) that orchestrates real-time communication. Can be self-hosted or used with LiveKit Cloud. - **Integration Services**: Telephony (PSTN/SIP connectivity), Egress (recording and streaming), and Ingress (external media streams). - **Client SDKs**: Real-time SDKs for Web, Swift, Android, Flutter, React Native, Unity, Python, Node.js, Rust, C++, and ESP32. ## Market Standing - **Valuation/Market Cap**: Not publicly disclosed. Total funding is $181M. - **Key Metric**: Total Funding of $181M. Over 2.5 billion calls powered annually. Over 300,000 developers use the platform. - **Notable Investors/Partners**: Index Ventures (led Series C), Altimeter Capital (led Series A), Redpoint (led Seed). Angel investors include Elad Gil, Jeff Dean (Chief Scientist, Google), Aravind Srinivas (CEO, Perplexity), Guillermo Rauch (CEO, Vercel), Amjad Masad (CEO, Replit), Mati Staniszewski (CEO, ElevenLabs), Erik Bernhardsson (CEO, Modal), Logan Kilpatrick (Product Lead, Google DeepMind), Rohan Anil (Researcher, Anthropic), Garrett Camp (Founder, Uber), Ev Williams (Founder, Twitter), and Justin Kan (Founder, Twitch). Key customer: OpenAI (built ChatGPT’s Advanced Voice on LiveKit Cloud). - **Growth Signals**: Rapid headcount growth (+7.1% monthly). Raised a $100M Series C in January 2026. Expanded from a WebRTC livestreaming project to the default infrastructure layer for voice AI. Operates in 12 countries. SOC 2 Type 2 and HIPAA compliant. ## Competitive Advantages - **Open-Source Foundation**: A large and active open-source community (over 300,000 developers) creates a strong ecosystem and lowers the barrier to entry. - **Full-Stack Platform**: Provides everything from the media server and client SDKs to the agent framework, inference gateway, and telephony integration, offering a unified, end-to-end solution. - **Proven at Scale**: Powers billions of calls annually for the world’s leading AI companies, including OpenAI’s Advanced Voice Mode, demonstrating extreme reliability and performance. - **Global Infrastructure**: A global network of media servers ensures low latency (<1000ms) and high uptime (99.99%) for real-time voice and video applications. - **Enterprise-Grade Compliance**: SOC 2 Type 2, HIPAA, and GDPR compliant, making it suitable for regulated industries. ## Strategic Focus - **Voice-First AI Infrastructure**: Doubling down on being the default platform for the emerging voice-driven computing paradigm. - **Expanding the Agent Ecosystem**: Continuously improving the Agents framework, adding new plugins, and supporting more AI models and hardware (including robotics). - **Scaling the Cloud Platform**: Investing in global infrastructure to handle increasing demand and maintain performance as usage grows. - **Enterprise Adoption**: Targeting Fortune 500 companies and regulated industries by emphasizing compliance, security, and reliability. ## Why Work Here - **High-Impact Work**: Build the core infrastructure powering the next generation of AI applications used by millions. Employees work on challenging problems in distributed systems, real-time media, and AI. - **Strong Engineering Culture**: A technical team with a high density of senior engineers. The tech stack is modern and includes Go, Rust, Python, TypeScript, WebRTC, Kubernetes, and various AI/ML tools. - **Remote-First with Hubs**: The company is remote-first but has a hybrid hub in San Francisco. Employees are distributed across 12 countries including the US, Canada, Germany, UK, and India. - **Top-Tier Investors & Advisors**: Backed by the best investors and advised by leaders from Google, OpenAI, and other top AI companies, providing a strong network and strategic direction. - **Growth Trajectory**: The company is in a high-growth phase (recent $100M Series C, rapid hiring), offering significant career growth opportunities. - **Culture**: Described as having a 5.0/5.0 employer rating on LinkedIn, with high marks for work-life balance, compensation, and career development. The company values "crazy ones" who want to build the future. ## Sources 1. [livekit.com](https://livekit.com/) 2. [livekit.com/about](https://livekit.com/about) 3. [livekit.com/careers](https://livekit.com/careers) 4. [linkedin.com/company/livekitco](https://www.linkedin.com/company/livekitco) 5. [docs.livekit.io](https://docs.livekit.io/intro/about/) ## Other roles at LiveKit - [GTM Strategic Finance Manager](https://feeny.ai/job/gtm-strategic-finance-manager-livekit-united-states-rb0ccpmpan16) — United States - [Senior Developer Advocate, Social](https://feeny.ai/job/senior-developer-advocate-social-livekit-united-states-r3sdwt54j53e) — United States - [Startup Program Lead](https://feeny.ai/job/startup-program-lead-livekit-san-francisco-jn2kpw565v3p) — San Francisco, CA - [Forward Deployed Engineer, Spanish/English](https://feeny.ai/job/forward-deployed-engineer-spanish-english-livekit-miami-cz5s5tj4xe6b) — Miami, FL - [Partnerships Manager, Alliances](https://feeny.ai/job/partnerships-manager-alliances-livekit-united-states-p4erkt0fy92x) — United States - [Demand Generation Manager](https://feeny.ai/job/demand-generation-manager-livekit-united-states-5dtd0fvha72r) — United States - [IT Engineer](https://feeny.ai/job/it-engineer-livekit-north-4zf3s3bvdxn9) — North, United States - [Research Engineer (Reinforcement Learning)](https://feeny.ai/job/research-engineer-reinforcement-learning-livekit-north-synx9vbxczqz) — North, United States - [Staff Product Manager, Growth](https://feeny.ai/job/staff-product-manager-growth-livekit-north-pw7e6z612sc2) — North, United States - [Staff Product Manager, Telephony](https://feeny.ai/job/staff-product-manager-telephony-livekit-north-j4hxe419ndwr) — North, United States