Remote job
Sr. AI Security Engineer
Job details
About this role
Role overview A senior, hands-on security engineering role focused on safeguarding internal AI usage, especially agentic and tool-using systems, within a large-scale cloud environment. The position designs and builds runtime enforcement, identity controls, and detection capabilities rather than only defining policy, and protects developers using AI-assisted coding tools. It suits a practitioner who has shipped security controls in production and is comfortable working across AI, identity, and observability domains.
Responsibilities - Architect and implement guardrails for tool-using AI systems, including tool allowlists, context and memory isolation, and step-level validation of agent actions aligned to OWASP Agentic AI guidance. - Build runtime enforcement mechanisms such as interceptors, proxies, middleware, policy decision layers, rate limits, execution bounds, and kill-switches that govern AI behavior at execution time. - Design identity and access systems for agents and automation, including short-lived credentials, scoped permissions, clear separation between human and non-human identities, and full audit attribution. - Implement logging and tracing for prompts, tool usage, and decision flows, and build detection capabilities using behavioral baselining and anomaly detection. - Perform agentic system threat modeling using the MAESTRO framework, mapping capabilities, trust boundaries, and attack paths, and translate findings into safeguards and detection logic. - Protect developers using AI tools by preventing sensitive data exposure, validating AI-generated code and actions, and enabling safe usage of AI-assisted development tooling.
Requirements - 7+ years of experience in security engineering or backend systems, with proven experience designing and deploying security controls in production. - Strong programming skills in Python; Go, Java, or TypeScript a plus. - Practical familiarity with agentic AI systems or tool-integrated LLM workflows, and OWASP guidance for AI and agent risks. - Experience with non-human identity, zero trust, secrets management, credential scoping, and observability tooling such as OpenTelemetry or ELK. - Hands-on experience applying OWASP Agentic AI or LLM risk guidance, NIST AI RMF concepts, and CSA guidance on workload and machine identity in real systems. - Experience using AI-assisted development tools such as Claude Code, Codex, or Cursor in real workflows, including their associated risks and safeguards.
Nice to have - Background securing internal AI platforms or developer-facing AI tools. - Experience in detection engineering, threat hunting, or adversarial testing. - Familiarity with agent frameworks such as LangChain or LlamaIndex. - Experience mentoring engineers and guiding secure design.
Benefits and work setup - Remote role based in the LATAM region, focused on internal AI security work for a large-scale cloud platform. - Family healthcare including dental and vision, 401(k), RSU grants, ESPP, flexible vacation, parental leave, childcare and fertility support, commuter benefits, and a learning and development program. - Company laptop plus a workstation personalization stipend and a culture that supports work-life balance.