Назад
Company hidden
15 часов назад

Staff AI Security Engineer

293 100 - 544 200$
Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Staff AI Security Engineer (AI/LLM Security): Building production security controls and AI-enhanced vulnerability reduction tooling for a multi-cloud SaaS platform with an accent on prompt and data protection, secure LLM patterns, and regulated-industry evidence. Focus on threat-modeling prompt injection and agent boundaries, integrating remediation into CI/CD, and designing scalable guardrails across Azure, AWS, and multi-provider LLM APIs.

Location: San Jose, CA; hybrid work location

Compensation: $293,100–$544,200 USD annual total target compensation

Company

hirify.global provides data resilience and data security posture management solutions, with a focus on securing data and AI for organizations worldwide.

What you will do

  • Design and ship data-handling controls for internal AI tooling and AI product features, including redaction, filtering, and infrastructure guardrails.
  • Build and productionize AI-enhanced vulnerability reduction capabilities integrated with CI/CD, including low-false-positive detection and remediation.
  • Develop reusable secure-LLM patterns covering input filtering, output validation, data classification, and threat-modeling guidance.
  • Threat-model AI tools for prompt injection, indirect prompt attacks, model exfiltration, and agent-tool boundary weaknesses, then implement fixes with tool owners and the red team.
  • Partner with Compliance on auditor-facing evidence for AI-assisted controls and contribute AI security expertise to vulnerability management, supply chain, code ownership, and compliance programs.
  • Set direction for LLM security tools and AI-enabled security workflows, deciding what to adopt, build, or exclude.

Requirements

  • 10+ years of experience across security and engineering, with recent experience in production AI/ML systems, LLM deployments, model risk, or AI-driven security tooling.
  • Hands-on experience building LLM input and output controls, including redaction, filtering, output validation, and prompt-injection defenses.
  • Experience detecting PII and secrets across large datasets and selecting detection approaches based on cost, latency, and accuracy.
  • Strong Azure and AWS cloud security fundamentals, including RBAC, secrets management, key handling, and network egress controls.
  • Production development experience with Python and Go, plus familiarity with PowerShell and TypeScript integration points.
  • Knowledge of regulated-industry evidence requirements such as SOC 2 Type 2, ISO 27001, FedRAMP, and HITRUST, along with hands-on experience securing agentic AI development environments.

Nice to have

  • Experience with prompt injection, indirect prompt attacks, tool-boundary abuse, and model exfiltration.
  • Traditional AppSec or SAST experience applied to LLM-augmented vulnerability detection.
  • Open-source contributions to LLM safety or evaluation projects such as Presidio, PromptFoo, or Garak.
  • Experience with Azure OpenAI enterprise data-handling controls and LLM governance.

Culture & Benefits

  • Unlimited paid time off, 12 paid holidays, and paid volunteer time.
  • Paid parental leave, medical, dental, and vision coverage from the first day.
  • Mental health support, therapy sessions, and digital wellness tools.
  • 401(k) retirement plan with company matching, plus tax-advantaged spending accounts.
  • Learning libraries, mentoring, workshops, and annual learning events.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →