Staff AI Application Security Engineer
Relevanceai
| Company | Relevanceai |
| Category | Engineering |
| Location | Sydney |
| Remote | Hybrid |
| Employment | Not stated |
| Level | Not stated |
| Salary | Not stated by the employer |
| Posted | 7 Aug 2026 |
| Last verified | 8 Aug 2026 |
| Source | Employer ATS (ashby) |
Description
Location 📍 Sydney, AU, Hybrid (3 days in office required)
ABOUT US 🚀
At Relevance AI, we're building the home of the AI workforce. Our mission is simple: empower every team to delegate meaningful work to AI agents that think, act, and collaborate like experts.
With Relevance AI, anyone can create and manage intelligent agents that handle workflows, decisions, and collaboration - all within one unified platform. Our technology already powers industry leaders such as Canva, Databricks, Confluent, Autodesk, Lightspeed and Rakuten, helping them scale excellence across operations, marketing, and sales.
We're backed by Bessemer Venture Partners and raised our Series B in April 2025 to accelerate growth and push the boundaries of agentic automation. Headquartered in San Francisco and Sydney, we operate on a hybrid model and thrive on curiosity, collaboration, and execution - we move fast, think big, and win together.
If you want to define how the world works with AI, join us.
THE ROLE 🥳
Our engineering team works at the frontier of AI-native software development - where curiosity, product thinking, rapid experimentation, taste and judgment are embedded in our ways of working.
As our Staff Application Security Engineer, you'll be the specialist behind application and product security for a platform of autonomous agents that plan, decide and act on behalf of enterprise customers.
This is a new threat surface. The established AppSec playbook still applies to our product, our APIs and our production environment - but stops well short of the harder questions. How do you let an agent act on real work without it going off the rails? How do you contain prompt injection when a model can't reliably tell instructions from data?
Enterprises won't hand real work to agents they can't trust. That makes security a reason customers choose our product, and we invest in it accordingly.
This is a specialist IC seat reporting to our Head of Engineering. No direct reports, and no handing a list of vulnerabilities to other engineers to fix.
We'll sponsor relocation to Sydney, and would like to hear from you if you're in the UK or Europe and looking to move.
HOW WE BUILD ⚒️
- AI engineering (coding agents, loops, eval) is core to every engineer's workflow.
- Engineers own product areas and customer problems end-to-end.
- We prototype quickly, validate with customers, and ship continuously.
- We care about product impact as much as technical quality.
YOUR IMPACT 💥
- Migrate access control to the new model, and close any gaps.
- Secure the product surface: authn/authz, API security, input and output handling, supply-chain risk.
- Build the guardrails that let agents act safely: permissions, attribution, sandboxing, tool-use limits, prompt-injection defence.
- Establish least-privilege access across production, and make the secure path the fast path.
- Longer term, take us towards an autonomous security team: agents that continuously scan the platform and the code we ship, and help remediate what they find.
WHO WE'RE LOOKING FOR 🧠
While depth of experience is important, how you think matters more. In priority order:
- A view on agentic security. You've thought about what security means when agents do the work, not humans.
- AppSec depth on a production platform: authn/authz, API security, secure design and review, supply-chain risk. This is your core skill set we are hiring you for.
- Hands-on ownership. You'd rather fix it, than assign it.
- Systems thinking. You can talk through how an end-to-end autonomous system should be designed, and where it breaks.
- The basics for our stack: TypeScript, AWS, MCP, and AI engineering fundamentals - tool use, context, evals.
- Comfortable building with agents. It's how the whole team works. If you're not there yet you'll learn it here, but you need to want to.
This is a hands-on building role, and a deliberately specialist one. If you want