About Us:
Zenity is the leader in AI Agent Security and the first company to bring an agent-centric security platform to market. As enterprises accelerate AI agent adoption, we are establishing the security framework for how AI agents are secured and governed at enterprise scale.
We deliver full-lifecycle visibility, governance, detection, prevention, and response for AI agents from build time to runtime, across SaaS, home-grown platforms, and end-user devices. Backed by $180M+ in total funding, including a $125M Series C led by Norwest, with participation from SoftBank Vision Fund 2 and Microsoft's M12, Zenity is trusted by Fortune 500 and Global 2000 enterprises worldwide.
Join us in shaping how AI agents are secured at enterprise scale.
About the Role:
Zenity is looking for a Senior Product Security Engineer to own and evolve our Application and Cloud Security programs end-to-end. You'll embed security early in the development lifecycle, drive automation-first security practices across engineering, and partner closely with DevOps and product teams to keep our platform secure by design - from code to cloud.
What You’ll DoResponsibilities:
- Own, maintain, and continuously improve the Secure Design Review process, ensuring security considerations are integrated early in the development lifecycle.
- Develop, implement, and maintain Zenity's Application Security Program, including controls, standards, developer enablement, and automation - managing SAST and DAST tooling, integrations, alerting, and program-wide reporting.
- Develop and maintain Zenity's Cloud Security Program, defining guardrails, policies, and automated controls for secure-by-default cloud deployments, including CSPM tooling, findings triage, and alignment with internal risk and compliance processes.
- Monitor and enforce SDLC security controls, ensuring consistent application of secure development practices across all engineering teams.
- Partner with DevOps to design, implement, and maintain a fully secured CI/CD pipeline, embedding security checks, guardrails, and automated gates throughout build, test, and deployment stages.
- Collaborate closely with engineering teams to deliver actionable guidance, model threats, advise on architecture, and support secure implementations.
- Identify gaps in product, application, and cloud security posture, and drive end-to-end remediation and vulnerability management campaigns.
- Define and track KPIs, metrics, and reporting for application and cloud security health.
- Drive automation-first approaches to product and cloud security, reducing friction and enabling fast, safe development, while promoting a culture of security and developer empowerment.
Requirements:
- 5+ years of experience in Engineering / Security Engineering, including 3+ years in an Application Security or Product Security focused role.
- 2+ years of experience managing enterprise-wide security projects, with strong project planning and organizational skills.
- Proven experience leading AppSec-focused Security Review programs and CloudSec-focused Secure Design reviews.
- Hands-on experience owning the migration or deployment of AppSec tooling (SAST, DAST, ASPM, or similar).
- Strong proficiency with Kubernetes, Helm, and Terraform.
- Strong proficiency with Python and TypeScript.
- A builder's mindset - comfortable developing in-house solutions when faced with a capability gap.
Skills Required
- Five (5) + years of experience in Engineering / Security Engineering
- Three (3) + years of experience in an Application Security/Product Security focused role
- Two (2) + years of experience managing enterprise wide security projects
- Very comfortable with Kubernetes, Helm, and Terraform
- Very comfortable with Python and Typescript
- Led AppSec focused Security Review programs
- Led CloudSec focused Secure Design reviews
- Led multiple vulnerability management campaigns to mitigate Cloud and Application security risks
- Owned and delivered the migration or deployment of an AppSec focused security tool (SAST, DAST, ASPM, etc.)
- Strong opinion on what a project plan document should look like
Zenity Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Zenity and has not been reviewed or approved by Zenity.
-
Fair & Transparent Compensation — Pay is considered competitive and generally favorable, with indications that totals can be strong for key roles. While volume of signals is limited, sentiment toward compensation trends positive.
-
Strong & Reliable Incentives — Go-to-market roles appear to feature robust variable compensation and high on-target earnings. Role and location differences are evident, which can shape incentive outcomes.
-
Equity Value & Accessibility — Equity is routinely referenced as part of offers, indicating broad eligibility consistent with growth-stage startups. This points to accessible upside potential alongside cash compensation.
Zenity Insights
What We Do
Zenity is the first security and governance platform purpose-built for AI agents - spanning SaaS, home grown platforms (Cloud), and end-user devices (Endpoint). Trusted by Fortune 500 enterprises, Zenity helps security teams confidently adopt AI by delivering defense in depth with full-lifecycle coverage: from agent discovery and posture management to real-time detection, prevention, and response. As enterprises adopt Microsoft Copilot, Salesforce Agentforce, AWS Bedrock, and developer tools like GitHub Copilot, Zenity eliminates blind spots and enforces consistent policy across environments so organizations can innovate with AI, without compromising security. Learn more at www.zenity.io.







