Senior AI Platform Security Engineer
This role defines, builds, and secures the internal platform supporting Front’s engineering, GTM, data, and AI tooling. It owns AWS and Snowflake infrastructure, paved-road delivery, observability, access controls, vulnerability management, incident response, compliance support, and AI-client security.
About the job
Responsibilities
- Define standards, reference architecture, security requirements, and review processes for internal software and AI systems.
- Partner with product engineering, GTM Systems, Data, Enterprise Security, Legal, and IAM teams to establish and adopt platform conventions.
- Own AWS and Snowflake infrastructure, including compute, networking, data stores, DNS, certificates, environments, infrastructure as code, observability, and cost management.
- Build and maintain CI/CD pipelines, testing and security gates, deployment and rollback workflows, golden paths, templates, base images, shared modules, and self-service automation.
- Design secrets architecture with centralized storage, scoped short-lived credentials, and automated rotation.
- Secure infrastructure and the SDLC through IaC, container, dependency, supply-chain, secret, and pipeline security controls.
- Harden cloud configurations against CIS or equivalent baselines, manage drift, and operate vulnerability-management processes.
- Review infrastructure, integrations, and AI tooling before governed-data access; maintain connectivity inventories and least-privilege network and access boundaries.
- Monitor platform, integration, and AI-client security signals; develop detections for anomalous queries, data egress, off-hours access, privilege escalation, and other threats.
- Define data-loss-prevention controls for governed-data paths, including AI responses and downstream exports.
- Respond to incidents, preserve evidence, coordinate with Enterprise Security, and maintain and rehearse incident runbooks and tabletop exercises.
- Support SOC 2, ISO, and related compliance evidence collection; conduct access reviews for MCP, Workato, and AI-client integrations.
- Implement RBAC, ABAC, or hybrid access controls, JML automations, just-in-time access, and periodic access reviews.
- Troubleshoot MCP and AI-client integrations, maintain semantic-layer configuration, and investigate data-quality issues.
Requirements and qualifications
- Experience building and operating platform and security practices for internal software and AI systems.
- Ability to define standards, architecture, review bars, and secure paved roads while implementing them directly.
- Experience with AWS, Snowflake, infrastructure as code, CI/CD, observability, secrets management, vulnerability management, cloud security, and access control.
- Experience securing AI clients, MCP, Workato, data integrations, governed data, and semantic layers is relevant.
- Strong cross-functional communication and consensus-building skills across engineering, systems, data, security, legal, IAM, and GRC teams.
Compensation
- Annual base salary: $187,000–$250,000
Skills
AWS, Snowflake, Infrastructure As Code, CI/CD, Kubernetes, Observability, Secrets Management, Vulnerability Management, Cloud Security, RBAC, Abac, Mcp, Workato, Terraform, IAM
Similar jobs
Security Engineering jobsBuild and operate foundational security services covering identity, authorization, secrets, and privileged access for an AI-powered enterprise platform. The role requires 5+ years of production software engineering experience and hands-on security infrastructure expertise.
Build data pipelines, integrations, policy-as-code, and agentic AI workflows that automate security governance and continuous compliance. The role requires 7+ years of production software engineering experience plus expertise in LLMs, APIs, distributed data, and cloud infrastructure.
Own end-to-end security detection engineering, incident response, automation, and threat hunting across endpoint, identity, SaaS, and cloud environments. The role requires substantial hands-on experience with production detection logic, incident response, programming, and modern SIEM or detection pipelines.
The Senior GRC Analyst will manage security governance, risk, and compliance programs, including SOC 2 controls, risk assessments, vendor reviews, audits, and data governance. The role requires 8+ years of GRC experience, a bachelor’s degree, and familiarity with compliance platforms and SaaS environments.
Develops and operates detection engineering systems across endpoint, cloud, container, and SaaS environments. The role requires at least six years in detection, incident response, or offensive security, strong attacker TTP knowledge, macOS expertise, and detection-as-code experience.