> Markdown version of [/jobs/ext/577001-staff-information-security-engineer-ai-first](https://www.wearedevelopers.com/jobs/ext/577001-staff-information-security-engineer-ai-first). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Staff Information Security Engineer - AI First - **Company:** Rithum Corporation - **Location:** Dallas, TX, United States (Remote available) - **Experience:** Expert - **Salary:** $170,000.0 - $220,000.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Cloud Computing Security, Cloud Engineering, Cyber Security, Python (Programming Language), Machine Learning, Open Web Application Security, Security Information and Event Management, Systems Integration, Policy as Code, Data Processing, Scripting, Large Language Models, Software Security, Data Management, Machine Learning Operations, Terraform, GPT, Security Orchestration, Automation & Response, Static Application Security Testing, Vulnerability Analysis, Dynamic Application Security Testing - **Published:** June 20, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=e5a804d68de55e27 ## About the Role Do you have experience in Vuls?, * 5+ years of security engineering experience with demonstrated AI/ML security depth (prompt injection, model supply chain, adversarial inputs, RAG). * Experience using AI tools (ChatGPT, Copilot, Claude, etc.) and LLM frameworks and APIs (OpenAI, Anthropic, LangChain, or similar) to accelerate and elevate your work. * Hands-on identity and access expertise across modern enterprise and cloud identity stacks, including access models for AI systems and non-human identities. * Infrastructure and policy-as-code (e.g. Terraform, OPA/Rego) and proficiency in a scripting language for automation (Python preferred). * Cloud security expertise: AWS Solutions Architect / Security Specialty or equivalent demonstrated expertise, including multi-account governance, preventive guardrails, and policy-as-code. * Application security (OWASP Top 10 and the OWASP LLM/GenAI Top 10, secure SDLC) and threat-modelling methodologies (STRIDE, PASTA, or equivalent). Practical experience building or operating AI agents, and integrating security tooling (SIEM, CSPM, SAST/DAST/SCA) so it surfaces action rather than raw alerts. * Working knowledge of SOC 2 and/or ISO 27001 control frameworks. Preferred Qualifications * Experience building or operating AI agents in a production environment. * Awareness of privacy regulation (GDPR/CCPA) as it touches AI including privacy-by-design and DPIAs. * Red teaming or adversarial ML research backgrounds. * Experience implementing privileged-access, key-management, posture-management, or data-protection programs. * Experience with EDR, CASB, DLP, Security automation and SAST, DAST, IAST and SCA tools. * Cloud Architecture or Security certifications (CCSK, TAISE, AWS). Travel Required Up to 10% ## Description * Act as the bridge between architectural intent and operational reality; mediate conflicts between security requirements and feasible implementation, propose compensating controls where gaps exist and help register, track and remediate residual risks. * Implement preventive, default-on security controls across cloud and enterprise environments, codified as policy- and infrastructure-as-code so security is enforced by design, including controls that govern how AI tools and models may be used. * Implement and enforce identity and access controls to an agreed standard, including access boundaries for AI systems and non-human/agent identities by partnering with Platform Engineering and IT to align tooling and policy to the architecture. * Assist in maintaining the InfoSec risk register; track emerging threats and translate them into actionable guidance for engineering teams. * Support third-party and vendor risk assessments, with a focus on vendors who process data through AI pipelines. * Automate repetitive security workflows (evidence collection, access reviews, alert enrichment) and build or operate AI-assisted security agents - with human-in-the-loop approval gates, least-privilege credentials, and explicit attention to each agent's own blast radius. * Integrate security tooling (SIEM, CSPM, DAST/SAST, vulnerability scanners) with LLM layers to surface actionable insight and automated responses. * Define and enforce security requirements for AI-powered features: model access controls, prompt-injection mitigations, output validation, and data-handling boundaries. * Conduct threat modelling on agentic and LLM-based systems, accounting for novel attack surfaces such as tool misuse, indirect prompt injection, and supply chain risk. ## Related Videos - [How to govern Vibe Coding for the Enterprise](https://www.wearedevelopers.com/videos/100290-how-to-govern-vibe-coding-for-the-enterprise) - [ Evaluating AI models for code comprehension](https://www.wearedevelopers.com/videos/1462-evaluating-ai-models-for-code-comprehension) - [Infrastructure as Code: The Developer's Secret Weapon](https://www.wearedevelopers.com/videos/1221-infrastructure-as-code-the-developer-s-secret-weapon) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [From Shadow AI to Secure Intelligence: Safe AI Usage in the Enterprise](https://www.wearedevelopers.com/videos/2093-from-shadow-ai-to-secure-intelligence-safe-ai-usage-in-the-enterprise) - [Streaming AI Responses in Real-Time with SSE in Next.js & NestJS](https://www.wearedevelopers.com/videos/1630-streaming-ai-responses-in-real-time-with-sse-in-next-js-nestjs) ## Related Articles - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Got AI ideas but no money? Here are 10 free ways to level up your AI skills with Google Cloud](https://www.wearedevelopers.com/magazine/600-got-ai-ideas-but-no-money-here-are-10-free-ways-to-level-up-your-ai-skills-with-google-cloud) - [How to Become an AI Engineer](https://www.wearedevelopers.com/magazine/331-how-to-become-an-ai-engineer) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 196: AI Killed DevOps, LLM Political Bias & AI Security](https://www.wearedevelopers.com/magazine/659-dev-digest-196-ai-killed-devops-llm-political-bias-ai-security) - [Dev Digest 137 - AI'm not sure about this](https://www.wearedevelopers.com/magazine/485-dev-digest-137-ai-m-not-sure-about-this)