Назад
Company hidden
8 дней назад

Staff Security Engineer (AI)

235 000 - 305 000$
Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Staff Security Engineer (AI/AWS): Securing AI-enabled applications, LLM and RAG pipelines, agentic workflows, CI/CD environments, and AWS-native infrastructure with an accent on threat modeling, secure architecture, and AI-specific risk controls. Focus on designing guardrails for prompt handling, tool permissions, data protection, and observability while leading cross-functional security initiatives and critical incident response.

Location: Remote within the United States, excluding U.S. territories. Occasional travel may be requested but is not required. Core collaboration hours are 9AM–2PM Pacific Time. Employees in the San Francisco Bay Area or Providence, Rhode Island may use local offices.

Salary: $235,000–$305,000 per year

Company

hirify.global is an insurance technology innovation company building risk prediction, prevention, acquisition, and digital insurance platform capabilities for State Farm and HiRoad Assurance Company.

What you will do

  • Embed security into AI-enabled products, applications, APIs, services, and platforms throughout their lifecycle.
  • Lead threat modeling, architecture reviews, security design reviews, and risk assessments for LLM applications, RAG pipelines, agentic workflows, MCP servers, model providers, and AI integrations.
  • Define secure AI engineering patterns, guardrails, standards, and reference architectures for identity, data protection, prompt and context handling, permissions, logging, monitoring, and abuse prevention.
  • Strengthen AWS infrastructure and CI/CD environments, including infrastructure-as-code, containers, secrets management, workload identity, deployment pipelines, and software supply chain controls.
  • Improve AI-related detection, observability, telemetry, vulnerability management, incident response, and security operations capabilities.
  • Lead cross-functional security-by-design initiatives, provide practical guidance and training, influence architecture decisions, and own complex security projects.

Requirements

  • Bachelor’s degree in a relevant technical field or equivalent relevant experience.
  • 8+ years of experience in security engineering, product security, application security, cloud security, DevSecOps, infrastructure security, or software engineering with significant security responsibilities.
  • 5+ years of hands-on experience securing, assessing, building, integrating, or operating AI, machine learning, LLM, GenAI, or AI-enabled application environments.
  • Experience with security architecture reviews, threat modeling, secure design reviews, code or configuration reviews, and risk assessments for modern applications, APIs, platforms, and distributed systems.
  • Strong experience securing cloud-native environments, preferably AWS, including IAM, networking, logging, monitoring, secrets management, workload identity, infrastructure-as-code, and secure deployments.
  • Working knowledge of AI security risks including prompt injection, insecure tool use, excessive agency, data leakage, RAG risks, model trust boundaries, MCP risks, agent permissions, model abuse, and AI supply chain concerns.

Nice to have

  • Experience securing agentic AI systems, MCP servers, AI agents, tool-calling workflows, LLM gateways, or AI assistants.
  • Experience with AWS AI/ML services, RAG architectures, vector databases, embedding pipelines, AI security guardrails, or AI usage monitoring.
  • Experience with detection engineering, SIEM/SOAR, cloud security posture management, vulnerability management, Kubernetes, Docker, Terraform, or CI/CD platforms.
  • Familiarity with OWASP Top 10 for LLM Applications, MITRE ATLAS, NIST AI Risk Management Framework, CIS benchmarks, SOC 2, or ISO 27001.
  • Relevant security certifications or experience influencing engineering teams as a senior individual contributor.

Culture & Benefits

  • Remote-first work environment for most positions.
  • Medical, dental, vision, life insurance, supplemental income plans, and a 401(k) plan with company match.
  • $2,000 one-time work-from-home equipment payment and a provisioned MacBook Pro.
  • Four weeks of PTO in the first year and twelve weeks of fully paid parental leave.
  • Up to $5,000 annually for professional development, plus LinkedIn Learning and coaching access.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →