QuantumScape Corporation

Security AI Engineer, Principal Member of Technical Staff

QuantumScape Corporation · San Jose, California, United States · $155K–$236K/yr

Renewable Energy Equipment Manufacturing · 501-1,000 employees

Jul 30
Principal (10+ yrs) Full-time United States
Log in to apply, save this posting, or score it against your profile with AI.

About the role

You will design, build, and operate a multi-agent AI platform to automate security operations, including incident triage and asset reconnaissance. Additionally, you will harden cloud and network infrastructure while serving as a technical advisor for security automation across the organization.

What they look for

Python Kubernetes GCP Terraform Cybersecurity Artificial intelligence Large language models Network security Cloud infrastructure Automation Detection engineering Identity and access management Prompt engineering Model context protocol Incident response System architecture

Requirements

The role requires a bachelor's degree in a technical field and over 10 years of experience in cybersecurity, cloud infrastructure, or platform engineering. Candidates must possess deep expertise in GCP, Kubernetes, Python, and building production-grade systems using large language models.

Benefits

Health insurance Employee stock purchase plan Annual bonus Rsu/equity package

Full description

QuantumScape is on a mission to transform energy storage with solid-state lithium-metal battery technology. The company’s next-generation batteries are designed to enable greater energy density, faster charging and enhanced safety to support the transition away from legacy energy sources toward a lower carbon future.

About the Team

Our Cybersecurity Team sits at the intersection of innovation and protection. We are a small, high-leverage group that operates like a product engineering team: we build the platforms, agents, and automation that allow a lean team to defend a company with world-changing intellectual property.

We are actively building an internal agentic AI platform for security and IT operations — multi-agent workflows that triage incidents, perform asset reconnaissance, run access reviews, and generate audit evidence, with humans in the loop wherever judgment matters. If you are excited about applying AI to hard security problems in a fast-moving, deeply technical environment, you'll feel right at home here.

What We Need

We need an engineer who builds. Someone who can stand up cloud infrastructure, reason about a network end to end, and then automate the security work that runs on top of it using AI agents. This role is about replacing manual, repetitive security operations with engineered systems that are auditable, testable, and safe by design.

Here's what that looks like in this role:

  • Design, build, and operate AI agents that perform real security work — incident triage, asset reconnaissance, access reviews, evidence collection, and reporting
  • Engineer the infrastructure those agents run on: Kubernetes, service networking, workload identity, secrets, and observability
  • Build and maintain Model Context Protocol (MCP) servers that connect agents to our security, cloud, and IT platforms with least-privilege, scoped tooling
  • Replace runbooks and manual toil with automated pipelines that close the loop into ticketing, SIEM, and GRC systems
  • Treat the agent platform as production security infrastructure — no public exposure of internal tooling, least privilege everywhere, full audit trail
  • Hold a high bar for correctness: an agent that is confidently wrong is worse than no agent at all
  • Harden cloud and network environments by identifying gaps, enforcing segmentation, and ensuring monitoring coverage
  • Communicate with clarity across all levels of the organization, adapting your message to your audience
  • Take problems all the way to resolution — not just to identification — closing loops and holding yourself and others accountable

What You'll Do

As a Principal AI Security Engineer, you will be the technical owner of our security AI and automation platform, and a trusted advisor across cloud security, network security, and detection engineering. You will partner with platform engineering, IT, and infrastructure teams to reduce risk and dramatically increase what a small security team can cover.

Security AI Agent Engineering

  • Build and operate a multi-agent security platform (Python, Google Agent Development Kit, Anthropic Claude) deployed on GKE — including agent routing, session management, streaming interfaces, and multi-agent handoff
  • Design human-in-the-loop gating so any agent action with real-world consequence requires explicit approval, with full decision provenance retained
  • Develop and maintain MCP servers exposing scoped tools over Microsoft Defender XDR, Google SecOps (Chronicle), Entra ID, GCP, Jira/Confluence, and Microsoft 365
  • Build evaluation harnesses and regression suites that measure agent accuracy, tool-call correctness, and hallucination rate before anything reaches production
  • Own agent observability: prompt and response logging, tool-call auditing, cost and latency telemetry, and behavioral drift detection
  • Ship analyst-facing surfaces — a web frontend with SSO and role-based access control, plus agentic CLI workflows for hands-on investigation

Security Automation Modernization

  • Identify the highest-toil security workflows and rebuild them as automated pipelines: alert enrichment, phishing triage, vulnerability ticket routing, access certification, and audit evidence collection
  • Codify detection content and response actions as version-controlled, peer-reviewed, testable artifacts (detection-as-code)
  • Integrate automation into SIEM, ITSM, and GRC platforms so findings become tracked, closed-loop work rather than another dashboard
  • Define what stays human: escalation criteria, blast-radius limits, approval gates, and rollback paths for every automated action
  • Measure and report the outcome — analyst hours reclaimed, mean time to triage, coverage gained, and false-positive reduction

Cloud & Infrastructure Security Engineering (GCP-focused)

  • Design and harden GCP foundations: organization policy, IAM and service account hygiene, Workload Identity Federation, VPC Service Controls, Secret Manager, CMEK, and Cloud Audit Logs
  • Harden GKE end to end — control plane configuration, node hardening, workload identity, admission control, network policy, and supply chain integrity (image signing, Binary Authorization, SBOM)
  • Build infrastructure as code (Terraform) with policy-as-code guardrails so security posture is enforced at deploy time rather than discovered during an audit
  • Eliminate privilege escalation and lateral movement paths across projects, service accounts, and peered networks
  • Instrument cloud telemetry into Google SecOps and validate detection coverage across GCP, Azure, and SaaS log sources

Network & Platform Security

  • Assess and harden network architecture across on-premises, cloud, and OT-adjacent environments, ensuring alignment with security best practices
  • Design and enforce segmentation and zero-trust access patterns, including perimeter and egress controls
  • Partner with IT and infrastructure teams on firewall policy management, private connectivity and cloud interconnects, VPN architecture, and secure remote access
  • Ensure agent and automation workloads follow strict networking principles: private in-cluster service discovery, controlled egress, and no public exposure of internal tooling
  • Evaluate and improve network visibility tooling (NDR, IDS/IPS, flow logging) and feed that telemetry into automated detection and hunting
  • Provide security guidance on network and platform architecture decisions, including IT/OT boundary controls

Securing AI Itself

  • Own the security model for our own AI usage: prompt injection resistance, tool authorization boundaries, token scoping and lifetime, and data classification controls governing what agents are permitted to read
  • Define and operationalize GenAI governance — approved tooling, handling rules for classified intellectual property, and monitoring of AI application usage across the company
  • Review third-party AI integrations, connectors, and MCP servers, and build the controls that let the business adopt them safely rather than blocking them outright
  • Track the evolving AI threat landscape and translate it into concrete detections, guardrails, and architecture requirements

Advisory & Cross-Functional Enablement

  • Act as a security advisor to engineering, platform, and IT teams, translating complex security requirements into practical, actionable guidance
  • Influence technology decisions, architecture reviews, and vendor assessments from a security lens
  • Communicate risk and program progress clearly to both technical and non-technical stakeholders, including senior leadership
  • Foster a culture of security ownership and automation-first thinking across the organization

Skills You'll Need

Experience

  • Bachelor's degree in Computer Science, Computer Engineering, or a related technical field and 10+ years of hands-on experience across cybersecurity, cloud infrastructure, or platform engineering, with demonstrated depth in cloud security, networking, and automation
  • Proven track record shipping production software or infrastructure — not just scripts. You have built systems that other people depend on daily
  • Hands-on experience building with large language models: agent frameworks, tool and function calling, retrieval, prompt engineering, and systematic evaluation
  • Track record of building or maturing security capabilities from initial gap identification through operationalization in complex, fast-paced environments
  • Experience working alongside engineering, IT, and infrastructure teams in an embedded or advisory capacity

Technical Skills

  • AI & Agent Engineering: Practical experience with agent frameworks (Google ADK, LangGraph, or equivalent), LLM APIs (Anthropic Claude, Vertex AI, or comparable), Model Context Protocol (MCP), tool-use design, and agent evaluation. Ability to reason clearly about non-determinism, guardrails, and failure modes.
  • Programming: Strong production-quality Python (typing, testing, packaging, async). Working knowledge of a second language such as Go, TypeScript, or PowerShell.
  • Cloud Platforms: Deep GCP expertise — IAM, VPC and networking, GKE, Cloud Run, Secret Manager, Workload Identity Federation, Cloud Logging and Audit Logs, and Security Command Center. Working knowledge of Microsoft Azure and Entra ID.
  • Infrastructure & DevOps: Kubernetes, containers, Terraform, CI/CD pipelines, GitOps, secrets management, and observability tooling.
  • Networking: Strong grasp of TCP/IP, DNS, TLS, routing, firewall management, segmentation, private connectivity and interconnects, IDS/IPS and NDR tooling, and IT/OT boundary controls.
  • Detection & Response: Hands-on experience with SIEM and XDR platforms including Google SecOps (Chronicle), Microsoft Defender XDR, and Microsoft Sentinel; detection engineering, correlation logic, and response automation.
  • Security Engineering Breadth: Vulnerability management (Tenable or equivalent), endpoint control and application allowlisting (ThreatLocker or equivalent), identity and privileged access (SSO, FIDO2, PAM), and software supply chain security (SBOM, image scanning, signing).
  • Frameworks: MITRE ATT&CK, NIST CSF and NIST SP 800-207, CIS Benchmarks; familiarity with emerging AI security guidance such as the OWASP Top 10 for LLM Applications and the NIST AI Risk Management Framework.
  • Operating Systems: Solid experience across Linux and Windows environments.

Nice to Have

  • Experience securing or operating manufacturing and OT environments
  • Experience with automotive supplier security assessments (TISAX / VDA ISA) or comparable regulated audit regimes
  • Contributions to open-source agent, MCP, or security tooling

Certifications

  • CISSP (Certified Information Systems Security Professional) preferred
  • Google Professional Cloud Security Engineer, CKA/CKS, or equivalent cloud and Kubernetes certifications strongly considered
  • Relevant certifications such as GCIH, GCFA, GCIA, GCTI, or equivalent advanced certifications are strongly considered

ONSITE: This position is required to work onsite 5 days per week to meet the minimum essential duties and requirements of this position.

Compensation & Benefits: The expected salary range for this role is from $155,000 to $236,000 and a final salary will be determined by the candidate's experience and educational background. QuantumScape also offers an annual bonus and a generous RSU/Equity package as part of its compensation plan. In addition, we do offer a tremendous benefits plan including employee paid health care, Employee Stock Purchase Plan (ESPP), and other benefits.

We are an equal opportunity employer and value diversity at our company. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status.

We will ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, to perform essential job functions, and to receive benefits and privileges of employment. Please contact us to request an accommodation.

We are an equal opportunity employer and value diversity at our company. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status.

We will ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, to perform essential job functions, and to receive benefits and privileges of employment. Please contact us to request an accommodation.