
Staff Information Security Engineer – AI First
Posted Jun 18

Posted Jun 18
This is a fully remote position, open to applicants in United States.
• Serve as the intermediary between architectural vision and practical execution; resolve conflicts between security needs and implementable solutions, suggest compensating controls where gaps are identified, and assist in registering, monitoring, and addressing residual risks.
• Enforce preventive, default-on security measures across cloud and enterprise environments, formalized as policy- and infrastructure-as-code to ensure security is integrated by design, including controls governing the use of AI tools and models.
• Establish and uphold identity and access controls to a mutually agreed standard, including access boundaries for AI systems and non-human/agent identities by collaborating with Platform Engineering and IT to align tools and policies with the architecture.
• Aid in the upkeep of the InfoSec risk register; monitor emerging threats and convert them into actionable recommendations for engineering teams.
• Facilitate third-party and vendor risk evaluations, focusing on vendors that process data through AI pipelines.
• Streamline repetitive security tasks (such as evidence collection, access reviews, and alert enrichment) and develop or manage AI-assisted security agents — incorporating human-in-the-loop approval processes, least-privilege credentials, and careful consideration of each agent's operational boundaries.
• Integrate security tools (SIEM, CSPM, DAST/SAST, vulnerability scanners) with LLM layers to generate actionable insights and automated responses.
• Establish and uphold security criteria for AI-driven features: model access controls, prompt-injection countermeasures, output validation, and data-handling limits.
• Perform threat modeling on agentic and LLM-based systems, considering new attack surfaces such as tool misuse, indirect prompt injection, and supply chain vulnerabilities.
• Over 5 years of experience in security engineering with proven expertise in AI/ML security (including prompt injection, model supply chain, adversarial inputs, and RAG).
• Proficient in utilizing AI tools (such as ChatGPT, Copilot, Claude, etc.) and LLM frameworks and APIs (like OpenAI, Anthropic, LangChain, or similar) to enhance and streamline your work processes.
• Hands-on experience with identity and access management within modern enterprise and cloud identity frameworks, including access models for AI systems and non-human identities.
• Knowledge of infrastructure and policy-as-code (e.g., Terraform, OPA/Rego) and proficiency in a scripting language for automation (Python preferred).
• Expertise in cloud security: AWS Solutions Architect / Security Specialty or equivalent demonstrated proficiency, covering multi-account governance, preventive guardrails, and policy-as-code.
• Familiarity with application security (OWASP Top 10 and the OWASP LLM/GenAI Top 10, secure SDLC) and threat modeling methodologies (STRIDE, PASTA, or equivalent). Practical experience in building or managing AI agents, and integrating security tools (SIEM, CSPM, SAST/DAST/SCA) to produce actionable insights rather than raw alerts.
• Working knowledge of SOC 2 and/or ISO 27001 control frameworks.
• Medical, dental, and vision benefits: Affordable healthcare plans and company HSA contributions available from Day 1.
• A 6% 401(k) match.
• Competitive time-off package including 20 days of Paid Time Off, 9 Company-Paid holidays, 2 paid floating holidays, 7 paid sick days, 2 Wellness days, and 1 Paid Volunteer Day; PTO increases to 22 days at 3 years of service and 25 days at 5 years.
• 12 weeks of primary caregiver leave and 4 weeks of secondary caregiver leave.
• Accident, critical illness, and hospital indemnity insurance.
• Pet insurance.
• Legal assistance and identity theft insurance plans.
• Life insurance at 2x salary.
• Access to the Calm app and the Employee Assistance Program.
• $65/month remote work stipend for internet expenses.
• Culture and team-building activities.
• Tuition assistance.
• Opportunities for career development.
• Charitable contribution matching up to $250 per year.
GuidePoint Security
Redpanda Data
CyberSheath
Akamai Technologies
Get handpicked remote jobs straight to your inbox weekly.