обновлено 3 дня назад
AI Security Engineer (Offensive & Defensive)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
AI Security Engineer (Offensive & Defensive) (AI Security/Crypto): Reviewing and penetration-testing AI agents while developing automated security detection, alert triage, and attack attribution tools with an accent on prompt injection, context poisoning, agent misuse, and cloud-native attack surfaces. Focus on building agent behavior auditing and anomaly detection systems, designing defense-in-depth for Kubernetes and Docker environments, and validating offensive and defensive techniques with Python, Go, or C++.
Location: Any; hybrid workplace
Company
is a regulated Philippine crypto platform serving more than 18 million users with cryptocurrency trading and financial services through a mobile app.
What you will do
- Review and penetration-test AI agents, including defenses against tool misuse, context poisoning, data and prompt poisoning, and prompt injection.
- Design and develop AI-based security detection tools for automated alert triage, attack attribution, and security operations.
- Build agent behavior auditing and anomaly detection systems for runtime monitoring.
- Design AI-driven security operations and countermeasure solutions based on real business scenarios.
- Assess agent runtime attack surfaces across Kubernetes, Docker, cloud services, IAM, and network isolation, and implement defense-in-depth controls.
Requirements
- At least 3 years of security offense and defense experience, including penetration testing or red team practice.
- At least 1 year of experience in LLM security offense and defense; extensive hands-on red team experience is preferred.
- Experience with network architecture, Kubernetes, Docker container security, cloud security, IAM, network isolation, and cloud-native threat models.
- Ability to independently build or modify AI agents, including with frameworks such as LangChain, and validate attacks such as tool misuse, prompt injection, and context poisoning.
- Knowledge of OWASP Top 10 for LLM, MITRE ATT&CK, AI attack techniques, adversarial logic, and defensive solutions.
- Proficiency in at least one programming language such as Python, Go, or C++ for developing security tools or extending open-source security platforms.
Nice to have
- Experience with PyTorch, TensorFlow, LangChain, local large-language-model deployment, or model optimization.
- Hands-on AWS cloud security experience or relevant certifications.
Culture & Benefits
- Full-time employee role in a hybrid workplace.
- Cross-functional collaboration focused on improving customer experience.
- Fast-growing organization expanding beyond APAC with career advancement opportunities.
- Culture that encourages data-backed ideas and meaningful product improvements.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →