Duo Security Engineer
OpenKyber LLC
United States
3 months ago
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours
Job source
Tech stack
Application Programming Interfaces (APIs)
Artificial Intelligence
Amazon Web Services
Architectural Patterns
Microsoft Azure
Cloud Computing
Cloud Computing Security
Cyber Security
Continuous Integration
Database Security
Information Systems Security Architecture Professional
Key Management
+13 more
Open Web Application Security
Azure Active Directory
Zero Trust Network Access
Azure Machine Learning
Data Logging
Retrieval-Augmented Generation
Large Language Models
AI Platforms
Deployment Automation
Bicep
Virtual Agents
Terraform
Vulnerability Analysis
Job description
Reporting to the Director of Security in Global Security organization, you will research security controls, validate emerging architectural patterns, and define the governance standards for M365 Copilot Agents and autonomous agents built on Azure AI Foundry. Primary Responsibilities:
- Technology Evaluation & Security Architecture Emerging Tech Research: Proactively evaluate new AI tools, frameworks, and LLM providers to assess their security posture and suitability for a highly regulated investment environment.
- Architectural Design: Design and validate secure architectural patterns for AI agent integration within the organization’s ecosystem, ensuring data privacy and IP protection.
- Threat Modeling: Conduct deep-dive analysis of AI-specific threats (prompt injection, model inversion, data poisoning) and architect systemic mitigations.
- Platform Assessment: Evaluate the security capabilities of Azure AI Foundry, M365 Copilot Studio, and the Microsoft Graph API against the organization’s compliance standards.
- MCP Specialization: Assess Model Context Protocol (MCP) security best practices, designing isolation strategies for context management.
- As a security architect, assist with evaluations of other technologies being evaluated with via our Enterprise Architecture Review Board Technical Implementation & Validation Hardening & Standards: Create hardening checklists and configuration standards for AI platforms that bridge the gap between innovation and rigorous risk management.
- Identity & Integration: Test and document sophisticated integration approaches with Azure Key Vault, Entra ID, and Managed Identities.
- Security Telemetry: Implement advanced logging, auditing, and monitoring for AI agent telemetry to ensure visibility into autonomous actions.
Governance & Standards Development
- Design Principles : Lead the creation of the organization’s AI Agent Security Design Principles document.
- Policy Authoring: Working with various teams assist in developing technical sections of governance policies that address the risks of emerging AI technologies and autonomous workflows.
- CI/CD Integration: Identify and bridge control gaps in existing CI/CD pipelines to support secure, automated AI deployments.
- Stakeholder Collaboration: Translate complex security architectures into actionable implementation guides for developers and investment tech teams.
Requirements
- Architectural & Technical Skills 5+ years in Cloud Security/Architecture with deep hands-on Azure platform experience.
- AI Specialization: Hands-on experience with Azure AI Services, Azure OpenAI, and Azure AI Foundry (or similar platforms like AWS SageMaker).
- Modern Identity: Expert-level understanding of Microsoft Entra ID, Service Principals, and Managed Identity in a complex enterprise environment.
- Emerging Protocols: Deep familiarity with Model Context Protocol (MCP) and its implications for data isolation and session security.
- GenAI/LLM Expertise: Strong grasp of RAG (Retrieval-Augmented Generation) patterns and vector database security.
Security Implementation & Strategy
- Zero Trust: Proven track record of implementing Zero Trust controls in financial services or cloud-native environments.
- Automation: Experience with Infrastructure as Code (Terraform, Bicep) to codify security guardrails.
- Threat Assessment: Familiarity with the OWASP Top 10 for LLMs and AI-specific vulnerability scanning.
Preferred Qualifications:
- Certifications: Azure Security Engineer Associate, Azure AI Engineer Associate, or CISSP/CCSP.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on indeed.comGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
AJ
Austin Joy
over 4 years ago
CH
Chris Heilmann
Dev Digest 138 - Are you secure about this?
almost 2 years ago
LM
Luis Minvielle
Why Upskilling And Reskilling is Important For Developers
over 2 years ago
CH
Chris Heilmann
Dev Digest 134 - Where pixels sing?
almost 2 years ago
ER
Erin Rifkin
Got AI ideas but no money? Here are 10 free ways to level up your AI skills with Google Cloud
about 1 year ago
CH
Chris Heilmann
Dev Digest 120 - Apple and peers
about 2 years ago