AI Security Engineer

People Ideas & Culture LLC
United States
25 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
8 years minimum
Compensation
$180,000.0 - $195,000.0
Working hours
Regular working hours

Tech stack

JavaScript (Programming Language) Artificial Intelligence Amazon Web Services Microsoft Azure Cloud Computing Security Code Generation Cyber Security Data Security Cursor (Graphical User Interface Elements) Identity and Access Management Python (Programming Language) Key Management
+20 more
Network Segmentation OAuth OpenID Red Team (Cyber Security) Security Assertion Markup Language (SAML) Secure Coding Security Information and Event Management Software Engineering SQL Databases Tokenization TypeScript Google Cloud Large Language Models Multi-Agent Systems Prompt Engineering Software Security Bicep Hashicorp Machine Learning Operations Terraform

Requirements

  • Secure coding knowledge across languages commonly produced by AI-driven workflows: Python, TypeScript/JavaScript, SQL, and IaC (Terraform/Bicep).\n
  • Strong command of identity protocols: OAuth 2.0, OIDC, SAML, SCIM, and their application to non-human identities.\n
  • Prompt engineering sufficient to construct and evaluate adversarial prompts for testing.\n
  • Experience with SIEM, CSPM, and runtime application security tools; ability to write detection logic and correlation rules.\n
  • Data security controls: encryption, tokenization, DLP, and secrets management (HashiCorp Vault, AWS Secrets Manager, Azure Key Vault).\n
  • Scripting and automation skills for building internal security tooling (Python preferred).\n, * 8+ years of progressive information security experience across architecture, application security, identity, and data domains.\n
  • Hands-on use of Claude for application development, including system prompt design, tool-use configuration, and multi-agent orchestration.\n
  • Experience with the Model Context Protocol (MCP) ecosystem and securing MCP server deployments.\n
  • Red team or adversarial AI testing experience: model evasion, adversarial examples, jailbreak research.\n
  • Background in a regulated industry with data sensitivity requirements, healthcare a plus. \n
  • Contributions to AI security open-source projects, published research, or conference presentations (DEF CON AI Village, Black Hat, NeurIPS).\n
  • Demonstrated success securing AI/ML systems, LLM applications, or agentic AI platforms in a production environment.\n
  • Demonstrated experience building or securing applications developed substantially through LLM-assisted code generation (Claude, Copilot, Cursor, or equivalent).\n
  • Cloud-native security experience on at least one major provider (AWS, Azure, GCP), including IAM policy design, network segmentation, and secrets management.\n
  • Demonstrated success automating adversarial testing infrastructure include jailbreak suites, prompt injection harnesses, and regression pipelines tied to model and prompt changes\n
  • Relevant certifications: CISSP, CCSP, OSCP, AWS/Azure Security Specialty, or emerging AI security credentials.\n

Benefits & conditions

The Senior AI Security Engineer is a full-time, remote, exempt position and reports to the Sr. Director, Security Architecture and Operations.\n \n \nSpecific Responsibilities\n \n This role spans the full security lifecycle for AI systems from architecture and identity design through build, runtime, and incident response.\n \n \n

  • Threat modeling and risk assessment: Lead threat modeling for AI capabilities, agentic features, and integrations. Maintain a living threat model aligned to OWASP Top 10 for LLMs, MITRE ATLAS, and NIST AI RMF, and translate findings into prioritized, actionable controls.\n
  • Secure architecture: Own and maintain the AI security reference architecture covering model hosting, orchestration, tool use, MCP server deployments, and observability. Establish security patterns for new capabilities before they reach production.\n
  • AI model and pipeline security: Evaluate foundation models for data-leakage risk and supply-chain provenance. Harden prompt pipelines against injection, jailbreaking, and context poisoning. Secure fine-tuning pipelines, RAG architectures, and embedding stores with appropriate access controls and poisoning detection.\n
  • Agentic AI security: Define trust boundaries, tool call authorization, privilege scoping, and human-in-the-loop escalation policies for multi-agent systems. Ensure agents operate under least-privilege identities with revocable, short-lived credentials.\n
  • AI-generated code and build security: Establish review, testing, and gating processes for AI-generated code across frontend, backend, IaC, and CI/CD. Embed security requirements and policy-as-code checks directly into Claude system prompts and project instructions used for development. Enforce SCA/SBOM generation, dependency allowlisting, and secrets management for all LLM-driven build outputs.\n
  • Identity and access management: Define and enforce identity patterns for both human and non-human (agent) identities. Apply zero-trust principles to all model API calls, vector store queries, and external tool invocations. Every request must be authenticated, authorized, and logged. Architect OAuth/OIDC delegation patterns for agentic flows with bounded scopes and session limits.\n
  • Data protection and ETL security: Classify and control data flowing into LLM context windows, vector databases, and training pipelines. Secure ETL and ingestion pipelines against poisoning and schema drift. Enforce masking, tokenization, and access controls to prevent regulated data (PII, PHI, PCI) from appearing in model inputs, outputs, or logs. Extend DLP coverage to LLM prompt submissions and completions.\n
  • Detection, monitoring, and response: Instrument AI infrastructure with behavioral telemetry. Write detection rules for prompt injection attempts, anomalous agent behavior, and data exfiltration through LLMs. Serve as SME for AI-related security incidents, including model abuse, pipeline compromise, and agentic runaway actions.\n
  • Compliance and audit: Support SOC 2, HIPAA, ISO 27001, and NIST AI RMF compliance as applied to AI systems. Maintain control mappings, evidence, and audit documentation. Evaluate and deploy AI-specific security tooling (LLM firewalls, guardrail frameworks, agent monitoring) and integrate with SIEM/SOAR.\n, * Custom CI/CD security gate development - policy checks written from scratch, not scanner configuration\n
  • Vector database internals (pgvector, Pinecone, Weaviate) - access controls, audit logging, poisoning detection.\n
  • Red team automation for LLMs - adversarial prompt generation and evasion testing at scale\n
  • Deep familiarity with AI orchestration frameworks (LangChain, LangGraph, AutoGen, Claude Agent SDK, or similar) and their security characteristics.\n
  • Engineer programmatic agent kill-switch and rollback mechanisms triggered by behavioral thresholds\n
  • Track record delivering security architecture artifacts: threat models, reference architectures, security requirements, and control frameworks.\n
  • Build secure memory and context management layers for multi-agent systems - encryption, access scoping, and TTL enforcement\n, DataSpring is the trusted data connector at the core of healthcare. For more than 25 years, we have powered the industry with the largest and most complete healthcare data foundation in the U.S., including more than 4.8 million provider data records sourced directly from providers and member data representing 75% of covered lives supplied by health plans. By improving how essential information flows across the system, DataSpring helps healthcare operate more efficiently, accurately, and with greater confidence.\n \n \nWhat You Get\n \n At DataSpring, you will do meaningful work at the intersection of healthcare, data, and technology, helping solve complex problems that make the healthcare system work better. You will collaborate with experienced professionals who care deeply about accuracy, trust, and meaningful impact in a fully remote environment.\n \n DataSpring offers competitive compensation and a comprehensive benefits package for full-time employees, including medical, dental, and vision coverage, a 401(k) with company contributions and matching, paid parental leave, tuition assistance, and generous paid time off. We are committed to investing in our people and supporting professional growth over time.\n \n \nEqual Opportunity Employer\n \n DataSpring is proud to be an equal opportunity employer and is committed to fostering a workplace where all individuals are valued, respected, and empowered.\n \n

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on jobs.military.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:15 min

Security integration and AI skepticism in developer tooling

Chris Heilmann +2 · LIVE

4:35 min

Setting up passwordless federated identity configuring OpenID Connect patterns

Marcel Lupo · LIVE

2:56 min

Provisioning a secure container infrastructure with Bicep

Matthias Falkenberg +1 · WWC 2022

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · WWC Europe 2026

2:22 min

Adapting OpenID Connect for decentralized data sharing

Adam Larter Adam Larter · WWC 2024

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · WWC Europe 2026

Videos

See all

Related articles

See all