Remote job
AI Security Engineer
Job details
About this role
Role overview An AI security engineer focused on protecting AI-enabled products and agent workflows that rely on third-party models. The role centers on customer data shared with model providers, agent permissions, user data isolation, and prompt injection through uploaded documents and other untrusted content. It also supports regulatory oversight for AI-related technology risks.
Responsibilities - Assess customer data sent to third-party model vendors, covering minimization, vendor controls, retention, logging, and approved use - Design controls limiting AI agent permissions, tools, actions, and system access using least privilege and explicit authorization - Implement and test tenant and user data isolation across prompts, conversation history, retrieval, memory, and AI-connected services - Threat model and test prompt injection and indirect injection through uploaded documents, retrieved content, links, and other untrusted inputs - Partner with Product and Engineering on safe document ingestion, content handling, output validation, and approval flows for sensitive actions - Support SC TRM and BNM RMiT for AI technology risks, including assessments, third-party oversight, control evidence, and remediation - Build security tests, monitoring, and response procedures for AI misuse, data exposure, unauthorized actions, and vendor incidents
Requirements - Degree in Computer Science, Cybersecurity, AI, or a related field, or equivalent experience - 3+ years in application security, product security, security engineering, or AI system security - Experience implementing or owning SC TRM and BNM RMiT controls, technology risk, or regulatory control evidence - Understanding of third-party LLM integrations, model APIs, agent tools, RAG, and AI application architectures - Knowledge of prompt injection, indirect injection, cross-user data leakage, excessive agent permissions, and vendor data disclosure risks - Programming or scripting skills, preferably Python and TypeScript/Node.js, plus APIs and AWS or GCP - Ability to collaborate with Product, Legal, Compliance, Data, and Engineering on practical controls and clear risk communication