
AI Security Engineer – AI, Agentic Security
Posted 13 hours ago

Posted 13 hours ago
This is a fully remote position, open to applicants in Mexico, +4 more countries.
• Assist in the Enterprise AI Security Program.
• Facilitate the secure and safe integration of AI within internal chatbots, agentic workflows that involve tool access, code assistants, and agentic platforms.
• Evaluate new AI tools and protocols by examining their architecture, trust boundaries, and authentication models.
• Create specific, testable security policies.
• Convert security policies into automated enforcement through policy-as-code, CI/CD gates, gateway-level controls, and DLP rules.
• Assess and mitigate AI/LLM security risks, including prompt injection, unsafe outputs, tool-use abuse, data leakage, identity misuse, and escalation in agentic workflows.
• Provide timely and defensible security assessments on new tools, protocols, and frameworks.
• Transform vendor capability gaps and new tool risk profiles into actionable and testable control requirements.
• Identify and manage shadow-AI/BYOAI usage at scale.
• Support detection engineering, SIEM integration, and telemetry design for AI and agent behaviors.
• Extensive software engineering experience, with a minimum of 5 years.
• Proficiency in Python (or an equivalent programming language).
• At least 3 years of experience in AI/ML or GenAI security, or comparable hands-on information security experience demonstrating a transition into AI security.
• Capability to draft specific, testable security policies and implement automated enforcement, including policy-as-code, CI/CD gates, gateway-level controls, and DLP rules.
• Self-motivated learning on rapidly evolving technical topics; ability to evaluate new tools, protocols, or frameworks, including their architecture, trust boundaries, and authentication models.
• Practical understanding of AI/LLM security risks, including prompt injection, jailbreaking, unsafe outputs, tool-use abuse, identity misuse, and escalation of agentic workflows.
• Hands-on experience with NIST AI RMF, MITRE ATLAS, OWASP LLM Top 10, and OWASP Agentic Top 10.
• Experience with cloud security across at least two platforms: AWS, GCP, and Azure, including their native AI/ML security tools.
• Knowledge of OAuth 2.0/2.1, OIDC, and mTLS.
• Interest in or familiarity with non-human/workload identity, including SPIFFE/SPIRE, and agent identity models.
• Experience in a highly regulated sector, such as healthcare or financial services, with compliance obligations like HIPAA or equivalent.
• Excellent technical writing abilities.
• Preferred: direct experience with MCP or A2A protocol security, or AI gateway products.
• Preferred: exposure to AI-native runtime security platforms or traditional content guardrail products.
• Preferred: familiarity with shadow-AI/BYOAI risk management and discovery/governance tools such as CrowdStrike Falcon, Wiz, and CASB.
• Preferred: experience with AI red-team tooling like PyRIT, Promptfoo, AgentDojo, or custom harnesses.
• Preferred: knowledge of Microsoft Purview DSPM for AI or similar DLP-for-AI tools.
• Preferred: relevant certifications such as CAISP or ISACA AAISM, or equivalent demonstrated expertise.
• Preferred: experience in detection engineering, SIEM integration, and telemetry design for AI and agent behavior.
• Competitive salary and performance-based bonuses.
• Comprehensive health, dental, and vision insurance.
• Opportunities for professional development and continuous learning.
• Flexible working hours and remote work options.
• Supportive and inclusive company culture.
Sony Interactive Entertainment
Squads
Neo4j
PingWind Inc. (SDVOSB)
Get handpicked remote jobs straight to your inbox weekly.