
Director, Security Products – Key Management
Posted 3 days ago

Posted 3 days ago
This is a fully remote position, open to applicants in Massachusetts, +1 more state.
• Report directly to the VP, Deputy CISO.
• Collaborate with the Security Data Science team and Security leadership.
• Spearhead DigitalOcean's involvement with the external AI security community.
• Act as the internal authority and escalation point for AI-related security risks.
• Establish the integration of AI security controls within customer-facing products.
• Develop, implement, and maintain in-house AI/ML models, guardrails, tools, and automations.
• Oversee the monitoring of deployed models for drift and performance, implementing necessary enhancements.
• Direct adversarial testing and AI red teaming, encompassing jailbreaking, prompt injection, evasion, and poisoning tests.
• Conduct security reviews of significant AI product initiatives, providing architectural approvals and escalation recommendations.
• Threat model the AI lifecycle, covering data ingestion, training, fine-tuning, evaluation, model serving, RAG, agent frameworks, and post-deployment monitoring.
• Own and develop DigitalOcean's AI Security strategy and multi-year roadmap.
• Design and lead the AI Risk & Governance framework across DigitalOcean and Cloudways.
• Represent AI security during executive and board-level briefings.
• Define DigitalOcean's stance on emerging AI security issues.
• Over 10 years of experience in cybersecurity, with at least 4–5 years dedicated to AI/ML security, adversarial machine learning, or security data science in a production cloud or technology setting.
• Proven history of establishing and leading AI or security programs at an organizational level.
• Practitioner-level understanding of adversarial ML attacks and defenses, such as evasion, poisoning, model extraction, membership inference, and prompt injection.
• Capability to assess academic AI security research and convert it into engineering guidance and organizational policies.
• Experience in engaging with executive and senior leadership on technical risks.
• Strong programming abilities in Python and Go.
• Proficient in reviewing and evaluating AI/ML system architecture.
• Practical experience with AI red-team, defensive, and model supply-chain tools.
• Bachelor's or Master's degree in Computer Science, Information Security, Mathematics, or a related field, or equivalent practical experience.
• Familiarity with OWASP LLM Top 10, MITRE ATLAS, NIST AI RMF, ISO/IEC 42001, and the EU AI Act.
• Prior experience within a cloud provider, security product firm, or large-scale internet platform.
• Knowledge of production LLM security, including RAG pipelines, agentic frameworks, and model APIs.
• Ability to work remotely.
• Reimbursement for relevant conferences, training, and educational opportunities.
• Access to LinkedIn Learning's extensive library of over 10,000 courses.
• Employee Assistance Program.
• Opportunities for local employee meetups.
• Flexible time-off policy.
• Competitive benefits package, varying based on local regulations and individual preferences.
• Bonus eligibility based on both company and individual performance.
• Equity compensation available for eligible employees, including equity grants upon hire.
• Option to enroll in the Employee Stock Purchase Program.
CrowdStrike
Triumph Enterprises, Inc.
LaunchDarkly
Staffbase
Get handpicked remote jobs straight to your inbox weekly.