Sr. Security Engineer (AI)

Hi Marley
Boston, MA, United States
about 2 months ago
Apply on www.bostonjobsite.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$121,000.0
Working hours
Regular working hours

Tech stack

Application Programming Interfaces (APIs) Artificial Intelligence Amazon Web Services Ubuntu (Operating System) Cyber Security Information Leak Prevention Software Design Patterns Identity and Access Management Cloud Services Data Streaming Systems Integration Large Language Models
+6 more
Multi-Agent Systems Software Security AI Platforms Data Management Machine Learning Operations Data Pipelines

Job description

We’re looking for a Sr. AI Security Engineer to help secure how we use AI across the company, with a primary focus on Hi Marley’s internal AI environment: the tools, agents, and integrations that power how our teams work. Working within the security architecture and frameworks set by our senior security leadership, you’ll do the hands-on engineering that makes them real: threat-modeling new AI capabilities, running adversarial testing, operating the agent and MCP connector review process, and producing the evidence that lets leadership, our teams, and our auditors trust how we use AI. This role is for an experienced security engineer with genuine AI/ML depth who wants to go deep on one of the most important emerging problems in the field.

Teamwork and shared enthusiasm are a core part of our culture, which is why this role involves joining us in the Boston office for 2-3 days each week.

What You’ll Do:

AI Security Engineering & Threat Modeling

  • Apply Hi Marley’s AI security design patterns and reference architectures to LLM integrations, agent frameworks, MCP connectors, and data pipelines across the internal environment.
  • Lead threat modeling for new AI capabilities before they ship, identifying architectural risks and driving mitigations into the design phase.

  • Implement and enforce controls for agent isolation, least-privilege execution, credential scoping, and data-boundary enforcement in agentic environments.
  • Maintain a current inventory of AI tools and integrations in use across the organization, tracking data flows, permission scopes, and access controls.
  • Track emerging AI security research, attack techniques, and defensive tooling, and bring relevant findings into our practices.

AI Security Program Execution

  • Run the risk assessment process for internal AI tools, integrations, and third-party model providers against the established methodology

  • Execute the AI red-teaming cadence e.g. a dversarial testing for prompt injection, data exfiltration, model manipulation, and jailbreaking and drive remediation.

  • Operate the agent and MCP connector lifecycle, from proposal through approval, deployment, monitoring, and retirement.
  • Own the security evaluation of new AI tool requests, including vendor risk assessments, data-handling reviews, and baseline configuration; surface unapproved tools and bring them under governance.
  • Maintain AI security incident response runbooks and help respond when something goes wrong.
  • Track and report AI security metrics that demonstrate program health.

Trust, Compliance & Collaboration

  • Produce compliance evidence and documentation for AI systems supporting SOC 2 Type II examinations and ISO 42001 certification.
  • Translate technical decisions into clear, auditor-ready explanations of what we do, how it works, and why it is safe.
  • Partner with AI Operations and Corporate IT to embed security into the internal AI platform access controls for inference APIs, isolation for cloud-hosted agentic workloads, and endpoint/DLP configuration.

  • Contribute employee-facing guidance on safe AI use, * Max Courage â?? We encourage our team, our customers, and their customers to dream big, try new ideas, and maximize impact by measuring risk.
  • Be Humble â?? We lead with appreciation and promote a culture of humility, compassion, and openness to learn from anyone, anywhere.
  • Ubuntu (“I am because we are”) â?? We believe true success is much bigger than any single individual or company. By aligning our individual aims behind a shared purpose, we can achieve our fullest potential - together.

Life at Hi Marley:

Life at Hi Marley is shaped by collaboration, learning, and genuine connection. We’re proud to foster an environment where people can do their best work, feel supported, and grow alongside a team that celebrates both individuality and shared purpose.

  • A fun, lively startup culture that embraces creativity and innovation
  • Core values-based leadership that guides our decision-making and daily interactions
  • A culture of engagement, diversity, inclusion, and belonging - everyone’s voice matters
  • Flexible, hybrid work environment that values balance and trust
  • Ample opportunities to learn, take on new challenges, and make an impact in a fast-growing organization
  • Meaningful work that directly supports our mission to help people and organizations communicate with empathy and clarity

Requirements

  • 5+ years in security engineering, application security, or infrastructure security, with hands-on exposure to AI/ML systems.
  • Experience securing or building LLM-based systems, agentic frameworks, or ML pipelines in cloud environments.
  • Solid understanding of AI-specific attack surfaces: prompt injection, tool-use exploitation, privilege escalation through inherited access, data poisoning, and model/ training-data leakage.

  • Hands-on familiarity with how AI systems actually, in Python and experience building security tooling, automation, and testing.
  • Strong working knowledge of AWS security: IAM, networking, container isolation, encryption, and monitoring.
  • Familiarity with compliance frameworks (SOC 2, ISO 27001, ISO 42001, NIST AI RMF) and mapping technical controls to audit requirements.
  • Ability to communicate technical risk clearly to engineers, auditors, and stakeholders.

Preferred

  • Experience running or contributing to AI red-teaming or adversarial testing.

  • Experience with MCP s, agent orchestration frameworks, or similar agentic infrastructure.

  • Background in DLP, monitoring, or observability for AI or cloud workloads.
  • Experience at a growth-stage B2B SaaS company.

Benefits & conditions

At Hi Marley, we are committed to fair and transparent pay practices. The annual base salary for this role is expected to fall within the range of [$121,000â??$226,000], depending on experience, skills, qualifications, and location. Offers are determined based on these factors as well as internal peer equity. It’s most common for new hires to start near the midpoint of the range, allowing room for growth as employees develop in their role.

In addition to base pay, we offer a comprehensive total rewards package that supports both your wellbeing and professional growth, including:

  • Equity grants for all employees
  • A 4% matching 401(k) program
  • Medical, dental, vision, disability, and life insurance coverage for employees working 30+ hours per week
  • Monthly wellness stipend
  • Paid parental leave
  • A flexible vacation policy - we all work hard and take time when we need it

About the company

At Hi Marley, our culture is built on three core values that every employee embodies

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.bostonjobsite.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:36 min

Choosing between managed AI platforms and custom governance

Péter Farkas Péter Farkas · Europe 2026 Virtual

6:08 min

Applying software engineering environments and testing to data pipelines

Matthias Niehoff Matthias Niehoff · World Congress 2024

1:50 min

Lowering pipeline latency with data streaming

Nathaniel Okenwa Nathaniel Okenwa · World Congress 2024

1:45 min

Addressing active AI incident remediation and broad ecosystem support

Matthew Brady Matthew Brady · World Congress 2026 Europe

3:03 min

Career evolution in data engineering and AI platforms

Maria Apazoglou · Coffee With Developers

3:52 min

Building a consistent product catalog stream data pipeline

Denis Washington +1 · World Congress 2021

Videos

See all

Related articles

See all