> Markdown version of [/jobs/ext/2208789-staff-ai-security-engineer](https://www.wearedevelopers.com/jobs/ext/2208789-staff-ai-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Staff AI Security Engineer - **Company:** Veeam Software Corporation - **Location:** San Jose, CA, United States - **Experience:** Expert - **Salary:** $293,100.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Audit Trail, Microsoft Azure, Software as a Service, Cloud Computing Security, Cyber Security, Continuous Integration, Cursor (Graphical User Interface Elements), Github, Python (Programming Language), Log Analysis, Open Source Technology, Windows PowerShell, Role-Based Access Control, Red Team (Cyber Security), TypeScript, Software Vulnerability Management, Cloud Platform System, Data Classification, GitHub Copilot, Large Language Models, Model Validation, Multi-Cloud, Production Code, Microsoft Sentinel, Free and Open-Source Software, Data Management, Machine Learning Operations, Veeam, Static Application Security Testing - **Published:** August 24, 2026 - **Apply:** https://www.dice.com/job-detail/b183452e-9a60-4f40-acb8-3920b93b38d1 ## About the Role * 10+ years across security and engineering, with recent focus on AI/ML systems in production (LLM deployments, model risk, or AI-driven security tooling) * Hands-on experience shipping controls (Code, infra or data gaurdrails) that operate on LLM inputs and outputs (redaction, filtering, output validation, prompt-injection defense) * Build and tune detection systems that catch PII and secrets (API keys, credentials, personal data) across large, messy datasets, knowing when a regex rule is good enough, when you need a trained classifier, and when only an LLM can catch it, and justifying that choice on cost, latency, and accuracy grounds * Track record of taking AI/security work from concept to production, including designing for developer trust and false-positive management * Strong cloud security fundamentals across Azure and AWS: RBAC, secret management, key handling, network egress controls * Turn ad-hoc "is this LLM use case safe?" questions into a reusable mechanism (a scoring rubric in PR templates, a lint rule, an approval gate) that teams run themselves, instead of a doc they read once or a person they ping * Comfort building and hardening security tooling in Python and Go * Familiarity with regulated-industry evidentiary expectations (SOC 2 Type 2, ISO 27001, FedRAMP, HITRUST) and how AI-generated evidence intersects with them * Hands-on experience with agentic AI development environments (Claude Code, Cursor, GitHub Copilot Enterprise) and their operational security implications * A demonstrable track record of shipping production code (a code portfolio, open-source contributions, or internal build history). This is a hands-on building role, not an advisory one Bonus Skills * Familiarity with LLM attack techniques (prompt injection, indirect prompt attacks, tool-boundary abuse, model exfiltration) enough to threat-model and build defenses * Background in traditional AppSec or SAST that translates cleanly to LLM-augmented vulnerability finding * Contributions to open-source LLM safety or evaluation projects (Presidio, PromptFoo, Garak, etc.) * Prior work with Azure OpenAI Service enterprise data-handling controls and LLM governance patterns * Experience integrating security tooling into developer workflows without becoming a merge-blocking bottleneck ## Description Veeam VDC Security Engineering builds and operates the security platform for a multi-cloud (Azure and AWS) SaaS serving regulated industries. This role sits in Platform Security and helps drive AI/LLM security as a discipline. You will help shape how VDC uses large language models safely (defensively, at scale) and how we use them offensively to find and fix real security defects faster than traditional programs allow. What You'll Do * Design and ship the data-handling controls (code, filters, and infrastructure guardrails) for VDC's internal AI tooling and the AI features in our product. Redact sensitive data from prompts, model context, logs, and outputs before any of it reaches a third-party model provider * Build and productionize an AI-enhanced vulnerability reduction capability that plugs into CI/CD, surfaces real defects with a low false-positive rate, and either recommends or applies remediation without eroding developer trust * Publish and evolve a self-serve secure-LLM-use pattern for other VDC engineering teams, including input filtering, output validation, provider-tier data classification, and threat-model shortcuts for teams adding AI features to their products * Threat-model internal AI tools for prompt injection, indirect prompt attack surfaces, model exfiltration, and agent-tool boundary weaknesses. Partner with the red team on findings, then build the fixes and guardrails with tool owners * Partner with Compliance to shape auditor-facing evidence for AI-assisted controls, including which evidence formats hold up when the collector was an LLM and where human review must gate disclosure * Contribute the AI-security lens to adjacent Security Engineering programs where LLMs touch the surface area: vulnerability management maturity, supply chain risk reduction, code owners routing, and compliance evidence collection * Set VDC's direction on emerging LLM security tools and internal AI-forward workflows: what to adopt, what to skip, and what to build in-house Technologies You'll Work With * Azure OpenAI Service and other Azure AI Foundry components * Anthropic Claude, OpenAI, and multi-provider LLM APIs used across VDC internal tools * Microsoft Presidio, custom redaction pipelines, or equivalent PII/secrets detection at the prompt boundary * Cycode (SAST / SCA / Secrets) and Wiz for signal fusion into AI-driven remediation * GitHub Actions and Azure DevOps for CI/CD integration of security-review LLM tooling * Python and Go for the AI security tooling stack; comfort reading PowerShell and TypeScript for integration points * Microsoft Sentinel and Log Analytics for the audit trail on AI-mediated security operations ## Related Videos - [Do TypeScript without TypeScript](https://www.wearedevelopers.com/videos/327-do-typescript-without-typescript) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [Evals vs. Evil - AI and Package Security - Laurie Voss](https://www.wearedevelopers.com/videos/2131-evals-vs-evil-ai-and-package-security-laurie-voss) - [Bringing AI Model Testing and Prompt Management to Your Codebase with GitHub Models](https://www.wearedevelopers.com/videos/1536-bringing-ai-model-testing-and-prompt-management-to-your-codebase-with-github-models) - [Automated Security for the Entire SDLC](https://www.wearedevelopers.com/videos/100323-automated-security-for-the-entire-sdlc) - [Vuejs and TypeScript- Working Together like Peanut Butter and Jelly](https://www.wearedevelopers.com/videos/127-vuejs-and-typescript-working-together-like-peanut-butter-and-jelly) ## Related Articles - [Dev Digest 137 - AI'm not sure about this](https://www.wearedevelopers.com/magazine/485-dev-digest-137-ai-m-not-sure-about-this) - [What Are Large Language Models?](https://www.wearedevelopers.com/magazine/304-what-are-large-language-models) - [MLOps And AI Driven Development](https://www.wearedevelopers.com/magazine/82-mlops-and-ai-driven-development) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Dev Digest 196: AI Killed DevOps, LLM Political Bias & AI Security](https://www.wearedevelopers.com/magazine/659-dev-digest-196-ai-killed-devops-llm-political-bias-ai-security) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers)