Remote job
Staff Information Security Engineer - AI First
Job details
About this role
Role overview
A senior security engineering role focused on embedding safe, automated controls across an AI-first organization. The position sits at the intersection of information security and applied AI, designing guardrails for AI-powered products, codifying preventive controls, and building tooling so other teams can move quickly without introducing unseen risk. The work balances deep research with hands-on delivery and partners closely with platform engineering, IT, and external auditors.
Responsibilities
- Translate architectural intent into enforceable, default-on security controls across cloud and enterprise environments, expressed as policy- and infrastructure-as-code, including controls governing how AI tools and models may be used. - Implement identity and access standards, with particular attention to AI systems, agents, and other non-human identities, in partnership with platform engineering and IT. - Maintain the InfoSec risk register, track emerging threats, and convert them into concrete guidance for engineering teams. - Support third-party and vendor risk assessments, especially for vendors that process data through AI pipelines. - Automate repetitive security workflows and build or operate AI-assisted security agents behind human-in-the-loop approvals, least-privilege credentials, and explicit blast-radius limits. - Integrate SIEM, CSPM, SAST/DAST, and vulnerability tooling with LLM layers to surface actionable responses rather than raw alerts. - Define security requirements for AI features (model access controls, prompt-injection mitigations, output validation, data-handling boundaries) and run threat modelling on agentic and LLM-based systems.
Requirements
- 5+ years of security engineering experience, with demonstrated depth in AI/ML security topics such as prompt injection, model supply chain, adversarial inputs, and retrieval-augmented generation. - Hands-on identity and access expertise across modern enterprise and cloud identity stacks, including access models for AI systems and non-human identities. - Infrastructure and policy-as-code experience (for example, Terraform and OPA/Rego) plus scripting proficiency, with Python preferred. - Cloud security expertise equivalent to AWS Solutions Architect or Security Specialty, including multi-account governance and preventive guardrails. - Application security grounding in OWASP Top 10, OWASP LLM/GenAI Top 10, and secure SDLC, plus threat-modelling using STRIDE, PASTA, or comparable methodologies. - Working knowledge of SOC 2 and/or ISO 27001 control frameworks, comfort with privacy regulation touching AI data flows, and practical experience building or operating AI agents in production.
Benefits and work setup
- Remote-first working conditions with a monthly internet stipend. - Base compensation listed in the $170,000–$220,000 USD range, plus a discretionary bonus. - Medical, dental, and vision coverage with HSA contributions from day one, 6% 401(k) match, and life insurance at 2x salary. - Generous paid time off with company holidays, floating holidays, sick days, wellness days, and a paid volunteer day, scaling up with tenure. - 12 weeks primary and 4 weeks secondary caregiver leave, plus accident, critical illness, hospital indemnity, pet, legal, and identity theft insurance. - Access to mental wellness and employee assistance programs, tuition assistance, charitable match, and ongoing career development support.