Remote job
Staff Information Security Engineer - AI First
Job details
About this role
Role overview This Staff-level role sits at the intersection of AI adoption and information security, designing guardrails for AI-powered products, building automated security tooling, and shaping controls for an AI-first workforce. It is a highly autonomous, hands-on engineering position that splits time between building/automating and reviewing, partnering with platform engineering, IT, security champions, and external auditors.
Responsibilities - Mediate conflicts between security requirements and feasible implementation, propose compensating controls, and track residual risk in the InfoSec risk register. - Implement preventive, default-on security controls across cloud and enterprise environments as policy- and infrastructure-as-code, including controls governing AI tool and model use. - Implement and enforce identity and access controls, including boundaries for AI systems and non-human/agent identities, partnering with platform engineering and IT. - Automate repetitive security workflows (evidence collection, access reviews, alert enrichment) and build or operate AI-assisted security agents with human-in-the-loop approval gates and least-privilege credentials. - Integrate security tooling (SIEM, CSPM, DAST/SAST, vulnerability scanners) with LLM layers to surface actionable insight and automated responses. - Define security requirements for AI-powered features, including model access controls, prompt-injection mitigations, output validation, and data-handling boundaries, and conduct threat modelling on agentic and LLM-based systems. - Support third-party and vendor risk assessments with a focus on vendors processing data through AI pipelines.
Requirements - 5+ years of security engineering experience with demonstrated AI/ML security depth across prompt injection, model supply chain, adversarial inputs, and RAG. - Experience using AI tools and LLM frameworks/APIs (e.g., OpenAI, Anthropic, LangChain) to accelerate work. - Hands-on identity and access expertise across modern enterprise and cloud identity stacks, including non-human identities. - Proficiency with infrastructure and policy-as-code (e.g., Terraform, OPA/Rego) and a scripting language for automation (Python preferred). - Cloud security expertise equivalent to AWS Solutions Architect or Security Specialty, including multi-account governance and preventive guardrails. - Application security knowledge (OWASP Top 10 and OWASP LLM/GenAI Top 10, secure SDLC) and threat-modelling methodology (STRIDE, PASTA, or equivalent). - Working knowledge of SOC 2 and/or ISO 27001; practical experience building or operating AI agents in production; awareness of GDPR/CCPA.
Benefits and work setup - Remote-first working conditions, with generous time off and wellness days. - Base pay range of $170,000–$220,000 annually plus a discretionary bonus equal to 12% of base salary. - Medical, dental, and vision coverage with HSA contributions from day one; 6% 401(k) match. - 20 days PTO (rising to 22 at 3 years and 25 at 5 years), 9 company holidays, 2 floating holidays, 7 sick days, 2 wellness days, and 1 paid volunteer day. - 12 weeks primary and 4 weeks secondary caregiver leave, life insurance at 2x salary, accident and hospital indemnity insurance, pet insurance, legal and identity theft plans, Calm app and EAP access, $65/month remote work stipend, tuition assistance, and a charitable match up to $250/year.