
Director, Security Products – Key Management
Posted 3 days ago

Posted 3 days ago
This is a fully remote position, open to applicants in Colorado.
• Report directly to the VP, Deputy CISO.
• Collaborate with Security Data Science and Security leadership teams.
• Spearhead DigitalOcean’s interaction with the external AI security community.
• Act as the internal authority and escalation point for AI-related security risks.
• Outline the integration of AI security controls into products intended for customers.
• Develop, implement, and maintain in-house AI/ML models, guardrails, tools, and automation processes.
• Oversee the monitoring of deployed models for drift and performance, implementing necessary enhancements.
• Direct adversarial testing and AI red teaming, encompassing jailbreaking, prompt injection, evasion, and poisoning assessments.
• Manage security reviews of significant AI product initiatives from conception to launch.
• Provide architectural approval and escalation guidance for decisions deemed high-risk.
• Conduct threat modeling throughout the AI lifecycle, including data ingestion, training, evaluation, model serving, RAG, agent frameworks, and post-deployment monitoring.
• Own and drive DigitalOcean’s AI Security strategy and multi-year roadmap.
• Design and lead the AI Risk & Governance framework across DigitalOcean and Cloudways.
• Establish AI/ML policies, standards, and controls.
• Represent AI security in briefings for executives and board members.
• Convey risk posture, program progress, and strategic decisions to the CISO and senior leadership.
• Define DigitalOcean’s stance on emerging AI security issues.
• Over 10 years of experience in the field of cybersecurity.
• A minimum of 4–5 years dedicated to AI/ML security, adversarial machine learning, or security data science within a production cloud or technology setting.
• Proven track record of defining and advancing AI or security initiatives at an organizational scale.
• In-depth, practitioner-level knowledge of adversarial ML attacks and defenses, including evasion, poisoning, model extraction, membership inference, and prompt injection.
• Capacity to assess academic AI security research and convert it into engineering directives and organizational policies.
• Experience in engaging with executive and senior leadership regarding technical risk.
• Proficient programming skills in Python and Go.
• Experience in creating security tools and automation solutions.
• Expertise in reviewing AI/ML system architecture, covering data ingestion, feature engineering, training pipelines, model serving, and ongoing monitoring.
• Practical experience with AI red-team and defensive tools and model supply-chain frameworks.
• Bachelor’s or Master’s degree in Computer Science, Information Security, Mathematics, or a related discipline, or equivalent practical experience.
• Familiarity with OWASP LLM Top 10, MITRE ATLAS, NIST AI RMF, ISO/IEC 42001, and the EU AI Act.
• Previous experience in a cloud service provider, security product company, or a large-scale internet platform with significant customer-facing AI/ML operations.
• Understanding of production LLM security, including RAG pipelines, agentic frameworks, and model APIs.
• Ability to secure systems against prompt injection, jailbreaking, and data exfiltration.
• Reimbursement for relevant conferences, training, and educational opportunities.
• Access to over 10,000 courses on LinkedIn Learning.
• Employee Assistance Program.
• Local employee meetups.
• Flexible time-off policy.
• Competitive benefits package, varying based on local laws and preferences.
• Potential bonuses based on individual and company performance.
• Equity compensation for eligible employees, including equity grants upon hiring.
• Option to enroll in the Employee Stock Purchase Program.
CrowdStrike
Triumph Enterprises, Inc.
LaunchDarkly
Staffbase
Get handpicked remote jobs straight to your inbox weekly.