> Markdown version of [/jobs/ext/2283784-security-engineer](https://www.wearedevelopers.com/jobs/ext/2283784-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer - **Company:** Jasper Llc - **Location:** United States (Remote available) - **Experience:** Expert - **Salary:** $174,000.0 - $205,000.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Cloud Computing Security, Code Review, Continuous Integration, Data Governance, Information Leak Prevention, Github, Identity and Access Management, Intrusion Detection and Prevention, Key Management, Network Segmentation, AI Infrastructure, Data Logging, Scripting, Large Language Models, Software Security, AI Platforms, RSA Archer Platform, Machine Learning Operations, Virtual Agents - **Published:** August 28, 2026 - **Apply:** https://jobs.ashbyhq.com/Jasper%20AI/f5a4a890-e544-4a85-bd45-f75ad40b0d35?utm_source=2jjrqoekOE ## About the Role * AI fluency-a working understanding of core AI concepts (LLMs, agents, copilots, tokens, credits, context windows, RAG, data governance, etc.), applied in the context of security engineering, with demonstrated enthusiasm for using AI tools to work faster and more effectively day to day * 8+ years in security engineering, with hands-on experience across at least two of: AI/ML security, cloud infrastructure security, and/or GRC compliance engineering * Practical experience securing AI systems-LLM applications, agents, or ML pipelines-including familiarity with common AI-specific threats (prompt injection, data leakage, model abuse, insecure tool use) * Deep understanding of security principles, best practices, and common vulnerabilities, including strong security judgment under ambiguity * A proactive mindset, with the ability to identify, prioritize, and address security gaps or inefficiencies through automation and tooling * Expertise and curiosity about using frontier models and agents to effectively solve security challenges * Demonstrated ability to build security programs, processes, or standards from scratch rather than inheriting a mature playbook * Strong working knowledge of GCP and AWS security services and IAM models * Experience with GitHub security controls (branch protection, secret scanning, Actions/CI security) and secure software supply chain practices * Hands-on experience with Wiz or a comparable CSPM/CNAPP platform * Comfort building automation and tooling (scripting, APIs, infrastructure-as-code) rather than relying solely on point-and-click console work * Strong cross-functional collaborator who can communicate security and compliance tradeoffs clearly to both engineers and non-technical stakeholders * Direct experience building or securing AI agent frameworks, agent tool-calling systems, or internal AI platforms * Experience supporting SOC 2 / ISO 27001 or similar compliance frameworks and working with GRC platforms (e.g., Vanta, Drata) * Background in detection engineering or building internal security tooling * Experience being an early or first specialized hire on a small security team, comfortable with ambiguity and shifting priorities * Experience working in AI infrastructure platforms (e.g., Modal, CoreWeave, etc.) ## Description As a Senior Security Engineer at Jasper, you'll be the first true generalist on our Security Engineering team-someone equally comfortable securing and building AI agents and platforms as they are automating GRC controls or hardening cloud infrastructure. This role sits at the center of a fast-moving security function, partnering closely with Engineering, GRC, Product, and IT to protect the systems and AI products Jasper builds. You'll set technical direction on AI security while still being hands-on across infrastructure, product security, and compliance engineering-a true jack-of-all-trades role that flexes across the full security spectrum as priorities shift. This is a force-multiplier position on a small team where your work will have outsized impact on how Jasper builds securely at scale. This fully remote role reports to the Director, Security and is open to candidates located anywhere in the US. What you will do at Jasper * Lead the security design, implementation, and controls for Jasper's AI infrastructure and AI-powered internal workflows-building the guardrails that govern how AI systems access, process, and handle sensitive data at every layer * Own threat modeling for AI-specific risks, including the attack surfaces that don't map cleanly onto traditional application security, and design controls for validating, logging, and auditing AI outputs where accuracy and data protection are non-negotiable * Build security tooling and automated checks that let internal teams adopt AI capabilities without slowing down * Collaborate, design, and influence the direction of the Security program at Jasper * Work with the GRC team to build and maintain GRC-related engineering-automating evidence collection, control monitoring, and compliance workflows (ie. via Vanta or similar) so the team spends less time on manual audit prep * Strengthen infrastructure security across GCP and AWS: identity and access management, network segmentation, secrets management, and secure-by-default infrastructure patterns * Own and improve GitHub security controls-branch protection, required reviews, secret scanning, dependency/SCA policies, and CI/CD pipeline security * Operate and tune Wiz (or equivalent CSPM/CNAPP tooling) to continuously identify and drive remediation of cloud misconfigurations and vulnerabilities * Use AI tools heavily in your own workflow (code review, triage, detection engineering, documentation) and help the broader security and engineering org do the same safely, while partnering cross-functionally with Engineering, Legal, Product, IT, and GRC to translate security and compliance requirements into practical, low-friction engineering solutions ## Related Videos - [Are Code Reviews Worth It? Insights from 16 Years of Review Data](https://www.wearedevelopers.com/videos/1135-are-code-reviews-worth-it-insights-from-16-years-of-review-data) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [The New AI Security Stack: Observe, Detect, Protect](https://www.wearedevelopers.com/videos/100302-the-new-ai-security-stack-observe-detect-protect) - [Bringing AI Model Testing and Prompt Management to Your Codebase with GitHub Models](https://www.wearedevelopers.com/videos/1536-bringing-ai-model-testing-and-prompt-management-to-your-codebase-with-github-models) - [Automated Security for the Entire SDLC](https://www.wearedevelopers.com/videos/100323-automated-security-for-the-entire-sdlc) ## Related Articles - [How to Become an AI Engineer](https://www.wearedevelopers.com/magazine/331-how-to-become-an-ai-engineer) - [What is Software Engineering in the Age of AI?](https://www.wearedevelopers.com/magazine/640-what-is-software-engineering-in-the-age-of-ai) - [Trustworthy AI Starts at Deployment: 5 Checks Before You Ship](https://www.wearedevelopers.com/magazine/753-trustworthy-ai-starts-at-deployment-5-checks-before-you-ship) - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Got AI ideas but no money? Here are 10 free ways to level up your AI skills with Google Cloud](https://www.wearedevelopers.com/magazine/600-got-ai-ideas-but-no-money-here-are-10-free-ways-to-level-up-your-ai-skills-with-google-cloud)