AI Defense Engineer

Wilmer Cutler Pickering Hale And Dorr LLP
Boston, MA, United States
3 days ago
Apply on www.wayup.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience required
1 year minimum
Working hours
Regular working hours
Job source

Tech stack

Training Data Application Programming Interfaces (APIs) Artificial Intelligence Amazon Web Services Artificial Neural Networks User Authentication Automation of Tests Microsoft Azure Software as a Service Cyber Security Continuous Integration Information Leak Prevention
+32 more
Expert Systems Fuzz Testing Identity and Access Management Key Management Network Security Machine Learning Platform as a Service (PAAS) Microsoft Copilot Security Information and Event Management Data Streaming Software Technical Review Software Vulnerability Management Data Logging Data Processing Cloud Platform System Feature Engineering Prompt Libraries Retrieval-Augmented Generation Large Language Models IT Architecture Software Security Llamaindex AI Platforms Kubernetes Information Technology Enterprise Integration Data Management Machine Learning Operations Api Gateway Semantic Kernel Security Orchestration, Automation & Response Microservices

Job description

The AI Defense Engineer is a technical contributor who helps secure AI capabilities in a global law firm environment. Working under the guidance of the Director of Information Security and in partnership with other Information Services colleagues, this role assists with implementing practical defenses, guardrails, policy enforcement layers, monitoring and detections, adversarial testing, and secure operating practices for AI-enabled systems. The role builds experience translating emerging AI threats into actionable technical controls that help protect firm and client information while supporting responsible AI adoption. The role supports a smart-integration, buy-before-build security strategy by assisting with the evaluation, selection, configuration, and operational use of commercial AI security solutions. This includes supporting assessments of solutions against legal-sector expectations such as matter confidentiality, ethical walls, client audit requirements, data residency constraints, and contractual information technology service obligations. Success in this role includes supporting efficient AI tool reviews and approvals, contributing to assessments of internally developed AI solutions, and helping produce evidence of AI cybersecurity protections for audit and client-facing needs. With guidance, the AI Defense Engineer helps engineering and security teams adopt secure-by-default practices, assists with adversarial evaluations that identify issues before production, strengthens telemetry and detections for early abuse indicators, and develops knowledge of evolving AI technology and threat trends. What You Will Be Doing

  • Threat Modeling & Risk Assessment - Assist with technical threat modeling for AI/ML systems, including neural networks, expert systems, retrieval-augmented generation, classification models, and related AI services. Help identify and document AI-specific risks, including prompt injection, data leakage, jailbreaks, unsafe autonomy, and misuse of vendor-enabled AI capabilities. Support mitigation planning by documenting recommended control configurations, reference patterns, and exception considerations for review by security and technology stakeholders.
  • AI Defense Engineering - Assist with implementing, configuring, and maintaining security controls, guardrails, and enforcement mechanisms for AI services, including input/output filters, policy enforcement layers, content safety checks, rate limiting, and abuse detection. Help monitor and investigate AI-specific attack patterns using logs, telemetry, and model signals. Work with platform and security teams to support the secure integration and operational use of enterprise AI services, including credentials, data flows, storage, and access controls across Copilot and other commercial LLM platforms.
  • Adversarial Testing & Red Teaming - Execute established adversarial test suites for AI applications, including prompt libraries, fuzzing harnesses, and automated testing tools. Simulate common attacker behaviors targeting AI endpoints and agents, document results, and help track identified issues as actionable vulnerabilities. Partner with application, product, and security teams to validate fixes, perform re-testing, and support residual risk tracking.
  • Tooling & Automation - Assist with integrating AI security capabilities into existing and future security stacks, including SIEM, SOAR, EDR, WAF, API gateways, and identity platforms.
  • Incident Response & Forensics for AI Systems - Support security incident response activities involving AI services, abuse, data exfiltration through AI systems, compromised API keys, or poisoned training data. Under guidance, review logs and model behavior to help reconstruct attack paths and identify durable fixes. Contribute to playbook and runbook improvements and post-incident technical reviews.
  • Collaboration - Collaborate with engineering, product, infrastructure, and security colleagues. Communicate technical findings, risks, and recommended remediations clearly to stakeholders. Provide implementation-focused input into AI security standards, guidelines, and procedures, with attention to vendor capability fit, maintainability, and total cost of ownership (TCO).
  • Security Improvements & Operational Readiness - Contribute to prioritized AI security engineering work by translating threat information, risk findings, and operational observations into practical technical recommendations. Participate in technical design reviews, support secure AI architecture patterns, and help ensure AI security controls are tested, documented, supportable, and ready for operational use.
  • Demonstrates a strong commitment to professionalism, delivering high-quality service, and maintaining a positive, solution-oriented (“can-do”) approach. Effectively supports internal departments, external clients, and vendors through clear, courteous communication via electronic correspondence, telephone, and in-person interactions.

Requirements

  • Foundational knowledge of ML/AI pipelines, including data collection, feature engineering, training, evaluation, deployment, and monitoring.
  • Basic understanding of how enterprise AI services (SaaS/PaaS) are deployed and governed, including data handling, routing, and isolation controls.
  • Hands-on exposure to at least one major cloud platform (AWS, Azure, or GCP) and familiarity with modern infrastructure concepts such as containers, Kubernetes, secrets management, and CI/CD.
  • Foundational security knowledge, including authentication and authorization, network security, data protection, logging and telemetry, secure software engineering practices, and vulnerability management.
  • Familiarity with one or more AI application frameworks (e.g., LangChain, Semantic Kernel, or LlamaIndex), agentic/orchestration platforms, APIs, microservices, or data platforms, a plus
  • Ability to analyze identified risks and, with guidance, translate them into practical technical recommendations such as configuration updates, controls, guardrails, and playbooks.
  • Strong written and verbal communication skills and the ability to collaborate effectively with data scientists, software engineers, and security teams. Required Experience

  • 1+ years of experience in security engineering, application security, ML/ML Ops engineering or a related technical area., + Bachelor’s degree in computer science, information security, or related field; or equivalent work experience., + Foundational knowledge of ML/AI pipelines, including data collection, feature engineering, training, evaluation, deployment, and monitoring.
  • Basic understanding of how enterprise AI services (SaaS/PaaS) are deployed and governed, including data handling, routing, and isolation controls.
  • Hands-on exposure to at least one major cloud platform (AWS, Azure, or GCP) and familiarity with modern infrastructure concepts such as containers, Kubernetes, secrets management, and CI/CD.
  • Foundational security knowledge, including authentication and authorization, network security, data protection, logging and telemetry, secure software engineering practices, and vulnerability management.
  • Familiarity with one or more AI application frameworks (e.g., LangChain, Semantic Kernel, or LlamaIndex), agentic/orchestration platforms, APIs, microservices, or data platforms, a plus
  • Ability to analyze identified risks and, with guidance, translate them into practical technical recommendations such as configuration updates, controls, guardrails, and playbooks.
  • Strong written and verbal communication skills and the ability to collaborate effectively with data scientists, software engineers, and security teams.

Benefits & conditions

Why Join Us?

  • A values-driven firm that fosters collaboration and respect
  • This position is eligible for a Hybrid Schedule
  • Medical, dental, and vision insurance
  • 401(k) with company match and profit-sharing options
  • Paid time off and holidays

About the company

WilmerHale is a leading, full-service international law firm with 1,000 lawyers located throughout 12 offices in the United States and Europe. Our lawyers work at the intersection of government, technology and business, and we remain committed to our guiding principles of providing quality, excellent legal and client services; developing diversity among our lawyers and staff and cultivating an environment that promotes an ambitious spirit, collaboration and collegiality by drawing on the extraordinary talents and dynamic experience of our lawyers. Our goal is to reflect the diversity of our clients and the communities in which we practice.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.wayup.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:03 min

Career evolution in data engineering and AI platforms

Maria Apazoglou · Coffee With Developers

1:32 min

Designing a centralized API gateway and identity provider

Axel Barbier · World Congress 2023

1:50 min

Simplifying generative AI deployments using the RagStack opinionated framework

David Leconte David Leconte +1 · World Congress 2024

1:15 min

Deploying local container pods to Kubernetes clusters

Stevan Le Meur Stevan Le Meur · World Congress 2024

3:21 min

Comparing traditional reverse proxies with modern API gateways

Nicolas Fränkel · World Congress 2022

1:08 min

Extending model capabilities through external framework integrations

Tomaz Bratanic · World Congress 2023

Videos

See all

Related articles

See all