> Markdown version of [/jobs/ext/267501-principal-staff-security-engineer-ai-platform-devsecops](https://www.wearedevelopers.com/jobs/ext/267501-principal-staff-security-engineer-ai-platform-devsecops). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Principal / Staff Security Engineer - AI Platform & DevSecOps - **Company:** AIdash Inc - **Location:** Palo Alto, CA, United States - **Experience:** Experienced - **Salary:** $210,000.0 - $270,000.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Microsoft Azure, Software as a Service, Cloud Computing, Cloud Computing Security, EXEC (Scripting Language), Cyber Security, Databases, Continuous Integration, Data Discovery, DevOps, Programming Tools, Identity and Access Management, IT Management, Intrusion Detection and Prevention, Machine Learning, Network Segmentation, Open Web Application Security, Performance Tuning, Systems Development Life Cycle, Zero Trust Network Access, Security Information and Event Management, Software Requirements Analysis, Tripwire, Software Vulnerability Management, Cyberark, Large Language Models, Software Security, Veracode, Amazon Virtual Private Cloud (VPC), Containerization, AI Platforms, Kubernetes, Hashicorp, Terraform, SentinelOne Expertise, Devsecops, Static Application Security Testing, Dynamic Application Security Testing - **Published:** May 20, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=64c1336e23bb0ed4 ## About the Role Do you have experience in Vulnerability management?, * 10+ years in security engineering, with 3+ years owning a DevSecOps or platform-security program in a cloud-native environment (AWS strongly preferred) * AppSec depth: shipped and operated SAST/DAST/SCA (e.g., Codacy, Semgrep, CodeQL, Snyk, Veracode, or equivalents) at production scale * AI security: hands-on hardening of a production LLM deployment (AWS Bedrock, Azure OpenAI, Vertex AI, or equivalent) - IAM, VPC routing, guardrails, eval gating. RAG-demo experience alone does not meet the bar * EDR/XDR + cloud security platform operator: production experience administering CrowdStrike Falcon (Insight/XDR, Cloud Security CNAPP/CSPM, Identity Protection, or Next-Gen SIEM), SentinelOne, Microsoft Defender XDR, or equivalent, including custom detection authoring * Zero-trust access: experience standing up or operating a privileged-access broker (e.g., Teleport, StrongDM, BeyondTrust, CyberArk, HashiCorp Boundary) * SBOM/AIBOM tooling: operated Interlynk, Anchore, Dependency-Track, or equivalent at production scale * Vulnerability management: production experience with Trivy, Aqua, Wiz, Orca, Lacework, or equivalent across containers, IaC, and SCA * IaC & policy-as-code: Terraform plus production policy-as-code (OPA/Rego, Checkov, Kyverno, tfsec, or equivalent) in a live pipeline * Container & Kubernetes security: production experience with admission controllers (Kyverno, Gatekeeper), runtime visibility (Falco or equivalent), and pragmatic Kubernetes hardening (gVisor, Kata where it earns its keep) * DLP experience: real-world sensitive-data discovery across SaaS or developer tooling, including AI-assisted environments * Compliance fluency: has personally driven SOC 2 Type II or ISO 27001 controls to audit, and can read a control map without flinching. * Bay Area based; able to work hybrid (3 days/week in office) Preferred qualifications * Hands-on MCP work - design, hardening, or auth - even early-stage * ISO 42001 implementation experience; ISO/IEC 42001 Lead Implementer or Lead Auditor certification, or comparable AI-governance leadership * Familiarity with NIST AI RMF and the EU AI Act's high-risk system requirements * Prompt-layer DLP and AI runtime guardrails (e.g., Nightfall, Lakera Guard, Cyberhaven, Harmonic Security, Protect AI, NVIDIA NeMo Guardrails) * LLM eval-as-gate in CI (e.g., Promptfoo, Garak, DeepEval, Giskard) and AI red-teaming experience * Modern PAM / zero-trust rollouts (Teleport, StrongDM) and SaaS posture management (e.g., AppOmni, Obsidian) * Experience securing SaaS products sold into regulated sectors (utilities, energy, financial services, healthcare) * Public signals: conference talks (fwd:cloudsec, DEF CON AI Village, BSides) or open-source contributions in CI/CD, MCP, or LLM-deployment security * Leadership of incident response for a material security event * Comfort working with remote, distributed engineering teams across US/India time zones ## Description AiDASH protects the critical infrastructure that delivers power to tens of millions of people. We are SOC 2 Type II certified today, and we're working toward ISO 27001 and ISO 42001 certifications in 2027. As we embed GenAI more deeply into our SaaS products (RAG pipelines, agentic / MCP services) and roll out AI-assisted development internally, the threat landscape is shifting fast. Autonomous adversaries, Mythos-class threat actors, prompt injection, model exfiltration, and vibe-coded internal apps spun up by non-engineers are now part of the daily attack surface., We're hiring a Principal or Staff Security Engineer to be our deepest technical voice on security - covering DevSecOps, AI/LLM security, cloud and endpoint defense, IT-Security, and the governance work that will land us ISO 27001 and 42001 certifications in 2027. You'll architect the strategy, pick the right tools where gaps exist, run the audits, and grow the function. You will report to senior leadership and partner with platform, ML, DevOps, and IT leadership across the company. If you've been waiting for a chance to lead the security program at a Series C AI company that ships production AI to critical infrastructure operators, this is that role. The Team You'll partner with our existing security and compliance team based in India - a security engineer plus two compliance specialists, currently within the DevOps organization - and serve as the most senior security IC at AiDASH and the company's authority on AI/LLM security. This role represents the next phase of our security investment: bringing senior-IC depth, AI-native security leadership, and modern detection engineering to a program that has so far been operated alongside DevOps. How you'll make an impact: * DevSecOps & AppSec + Operate and mature our AppSec toolchain across CI/CD - SAST, DAST, SCA, secrets scanning, and IaC policy-as-code. Deepen coverage and evaluate additional tooling where gaps are real + Run threat modeling and secure-design reviews; champion shift-left so security is part of every PR, not a gate at the end + Operate the AIBOM / SBOM toolchain; enforce risk-tiered dependency controls and extend SLSA practices to model artifacts * AI & LLM Security + Harden production GenAI deployments on AWS (managed model APIs, agentic / MCP services) - IAM, VPC routing, prompt-layer guardrails, output filtering, rate/cost controls + Codify OWASP LLM Top 10 and MITRE ATLAS controls into the SDLC; introduce LLM eval-as-gate in CI + Govern internal AI-assisted developer tooling - DLP for what egresses to external model providers, sensitive-data discovery in prompts, and acceptable-use telemetry + Stand up controls for vibe-coded apps and shadow AI: discover, classify, gate with sane defaults, and bring under the SDLC * ISO 27001 / 42001 & Security Governance + Lead the company's path to ISO 27001 and ISO 42001 (AI Management System) certifications in 2027 - scope the management systems, run gap assessments, build the control sets, and steer the audit cycles + Maintain our SOC 2 Type II posture; manage the evidence pipeline, control mappings, and external auditor relationships + Maintain alignment with the NIST AI RMF and translate emerging AI regulation (EU AI Act, US state AI laws, utility-sector mandates) into concrete engineering requirements * Cloud, Endpoint & IT-Security + Operate our endpoint, cloud, identity, and SIEM platforms end-to-end. Own detection engineering, tuning, and integration with the rest of the stack + Harden AWS posture across accounts (Organizations, SCPs, Control Tower); mature Kubernetes security (admission controllers, runtime visibility, pragmatic hardening) + Stand up zero-trust privileged access - short-lived, audited sessions for production infra, databases, and Kubernetes + Lead IT-Security: device posture, identity (SSO, MFA, SCIM), network segmentation, SaaS posture, and offboarding hygiene * Detection, Response & Resilience + Build and tune detections in our SIEM; own the on-call rotation, runbooks, and IR retainer relationships + Run tabletop exercises across Eng, Legal, and Exec; lead post-incident reviews with blameless write-ups + Translate AI threat research - prompt injection, data poisoning, model inversion, agent hijacking - into detections and controls that ship with every release ## Related Videos - [Hacking Kubernetes: Live Demo Marathon](https://www.wearedevelopers.com/videos/488-hacking-kubernetes-live-demo-marathon) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [The New AI Security Stack: Observe, Detect, Protect](https://www.wearedevelopers.com/videos/100302-the-new-ai-security-stack-observe-detect-protect) - [DevOps Maturity Check – a way to balance autonomy and alignment](https://www.wearedevelopers.com/videos/58-devops-maturity-check-a-way-to-balance-autonomy-and-alignment) - [Surviving the Vulnpocalypse: Open Source and Supply Chain Security in a Post Mythos World](https://www.wearedevelopers.com/videos/100279-surviving-the-vulnpocalypse-open-source-and-supply-chain-security-in-a-post-mythos-world) - [#90DaysOfDevOps - The DevOps Learning Journey](https://www.wearedevelopers.com/videos/548-90daysofdevops-the-devops-learning-journey) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 132 - Binging WADFlix?](https://www.wearedevelopers.com/magazine/473-dev-digest-132-binging-wadflix) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence)