Role Description
At Dropbox, we believe in simplifying the way people work together. We provide a range of innovative cloud-based solutions to empower individuals and businesses to share, access, and collaborate on their files seamlessly. Security plays a pivotal role in shaping our mission of building a more enlightened way of working where everyone can unleash their creative potential without constraints.
As a Security Engineer, you'll safeguard our digital ecosystem alongside a diverse team of professionals dedicated to protecting our products and users. Trusted by millions, our mission is to integrate security seamlessly into Dropbox, empowering confident collaboration. Join us in owning a range of security projects, fostering innovation and growth in a collaborative environment.
Responsibilities
- Design, deploy and operate infrastructure-level security controls for Dropbox's AI and agentic infrastructure, including cloud infrastructure, Kubernetes and data stores.
- Design and implement secure authentication, authorization and networking patterns for AI agents and other non-human actors
- Lead security implementation for secure usage of AI tools and governance.
- Maintain a high and continuously improving bar for the security of Dropbox infrastructure in order to protect customer data.
- Review the current and upcoming infrastructure stack from a security perspective and provide hardening mechanisms and recommendations.
- Deploy, build, and/or operate security infrastructure solutions to help scale and raise the security bar for Dropbox’s on-prem and cloud infrastructure.
- Collaborate with cross functional teams and lead security initiatives to influence product decisions and enhance security posture.
Requirements
- 9+ years of Security experience or related industry experience, demonstrating impactful contributions to security strategies.
- Bachelor's degree in Computer Science, Information Security, or related field, or equivalent experience, with coding proficiency.
- Experience in securing agentic AI systems with hands-on implementation of security controls targeting AI-specific vulnerabilities like prompt injection, data or model poisoning, and AI supply-chain risk.
- Experience in designing and implementing identity and authorization for non-human workloads and agents using modern frameworks such as SPIFFE/SPIRE, OAuth 2.1, OIDC, or cloud provider equivalents.
- Experience implementing policy-as-code, infrastructure-as-code, and security automation for cloud and AI platforms.
- Experience with cloud security technologies for providers like Amazon Web Services (AWS), Google Cloud Platform (GCP) or Microsoft Azure.
- Profici