Назад
Company hidden
2 дня назад

AI Security Engineer

Формат работы
remote (Global)
Тип работы
fulltime
Грейд
middle
Английский
b2
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
AI Security Engineer (AI/Cybersecurity): Securing AI-enabled financial products and agent workflows with an accent on customer data protection, least-privilege agent controls, tenant isolation, and prompt-injection defense. Focus on threat modeling untrusted content, validating third-party model integrations, implementing security monitoring, and supporting SC TRM and BNM RMiT technology-risk controls.

Location: Global, remote

Company

hirify.global is a Southeast Asian financial technology company building mobile-first insurance and broader financial applications for spending, saving, investing, exchanging, and travel.

What you will do

  • Assess customer data shared with third-party AI model vendors, including minimization, retention, logging, vendor controls, and approved use.
  • Design and implement least-privilege controls for AI agent permissions, tools, actions, and system access.
  • Test tenant and user data isolation across prompts, conversation history, retrieval, memory, and connected AI services.
  • Threat model and test prompt injection and indirect injection through uploaded documents, retrieved content, links, and other untrusted inputs.
  • Partner with Product and Engineering on secure document ingestion, content handling, output validation, and approval of sensitive actions.
  • Build security tests, monitoring, and response procedures for AI misuse, data exposure, unauthorized actions, and vendor incidents.

Requirements

  • Degree in Computer Science, Cybersecurity, AI, or a related field, or equivalent experience.
  • At least 3 years of experience in application security, product security, security engineering, or AI system security.
  • Experience with SC TRM and BNM RMiT controls, technology risk, or regulatory control evidence.
  • Understanding of third-party LLM integrations, model APIs, agent tools, RAG, and AI application architectures.
  • Knowledge of prompt injection, indirect injection, cross-user data leakage, excessive agent permissions, and vendor data disclosure risks.
  • Programming or scripting experience, preferably with Python and TypeScript/Node.js, plus APIs and AWS or GCP.

Culture & Benefits

  • Full-time remote work from a global location.
  • English is the main working language across global teams; strong English communication is required.
  • Collaboration with Product, Legal, Compliance, Data, and Engineering teams.
  • International environment with colleagues from more than 20 nationalities.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →