
AI Security, DevOps Engineer
Posted Sep 10

Posted Sep 10
This is a fully remote position, open to applicants in United States, +1 more country.
• Oversee Casper's development-to-production security standards.
• Establish and manage security checkpoints, such as threat models, design evaluations, and release decisions.
• Strengthen identity and authentication protocols, manage secrets, ensure data protection, enforce egress controls, and enhance agent security.
• Handle security-dependent platform tasks including CI/CD, automated repository scanning and reviews, infrastructure-as-code, environment and access management, as well as logging and telemetry.
• Conduct audits of internal repositories and systems and address any identified issues.
• Lead client security initiatives, collect requirements, map authorized and unauthorized vendors, and generate threat models and evidence packs.
• Identify preferred vendors for authentication, secrets management, telemetry, and scanning services.
• Integrate security validation timelines into project planning and production schedules.
• Elevate engineering security standards through reviews, collaborative efforts, and documented guidance.
• Collaborate on client projects, primarily with regulated enterprises utilizing Microsoft technologies.
• Extensive hands-on experience in application and product security, including threat modeling, vulnerability identification, and writing remediation fixes.
• Proficiency in DevOps and platform environments with CI/CD, infrastructure-as-code, and cloud technologies (especially Azure, along with AWS/GCP), secrets management, and observability.
• Expertise in identity and authentication frameworks: OAuth/OIDC, SSO/SCIM, RBAC, conditional access, and Microsoft Entra.
• Knowledge in LLM and agent security, including prompt injection, excessive agency, tool and connector permissions, insecure output handling, retrieval abuse, and AI supply chain risks.
• Experience with secure SDLC processes including SAST/DAST/SCA, dependency and supply chain controls, as well as automated reviews.
• Ability to appropriately scale controls according to the project stage and associated risks.
• Strong client-facing credibility with enterprise security teams and the capacity to communicate risk to executives effectively.
• Familiarity with modern AI tools and the ability to customize workflows.
• Excellent writing skills and a high level of initiative.
• Experience in regulated industries or consulting environments, familiarity with OWASP Top 10 for LLM Applications, MITRE ATLAS, NIST AI RMF, ISO 42001, SOC 2 or ISO 27001, AI red teaming, adversarial testing, or abuse-case analysis is a plus.
• Must reside in the US or Canada.
• A GitHub profile with private contributions enabled is required.
• Medical, Dental, and Vision Coverage.
• Flexible Paid Time Off (PTO).
• Health Flexible Spending Account (FSA) / Health Savings Account (HSA).
• Life Insurance.
• Fully remote work options.
• Occasional travel to client sites.
FourEnergy GmbH
ICF
Mastercam
C&S Informática
Get handpicked remote jobs straight to your inbox weekly.