Senior AI Security Engineer
The Senior AI Security Engineer will secure internal LLM, agent, MCP connector, and AI integration environments through threat modeling, controls engineering, red teaming, governance, and compliance evidence. Requires 5+ years of security engineering experience, hands-on AI/ML depth, Python, AWS security, and familiarity with AI risk frameworks.
About the job
Responsibilities
AI Security Engineering & Threat Modeling
- Apply AI security design patterns and reference architectures to LLM integrations, agent frameworks, MCP connectors, and data pipelines.
- Lead threat modeling for new AI capabilities, identify architectural risks, and drive mitigations into the design phase.
- Implement controls for agent isolation, least-privilege execution, credential scoping, and data-boundary enforcement.
- Maintain an inventory of AI tools and integrations, including data flows, permission scopes, and access controls.
- Track emerging AI security research, attack techniques, and defensive tooling.
AI Security Program Execution
- Run risk assessments for internal AI tools, integrations, and third-party model providers.
- Execute AI red-team testing for prompt injection, data exfiltration, model manipulation, and jailbreaking; drive remediation.
- Operate the agent and MCP connector lifecycle from proposal through approval, deployment, monitoring, and retirement.
- Evaluate new AI tool requests, including vendor risk, data handling, and baseline configuration; identify and govern unapproved tools.
- Maintain AI security incident-response runbooks and support incident response.
- Track and report AI security metrics.
Trust, Compliance & Collaboration
- Produce compliance evidence and documentation for SOC 2 Type II examinations and ISO 42001 certification.
- Translate technical decisions into auditor-ready explanations.
- Partner with AI Operations and Corporate IT on inference API access controls, isolation for cloud-hosted agentic workloads, and endpoint/DLP configuration.
- Contribute employee guidance on safe AI use.
Requirements
- 5+ years of experience in security engineering, application security, or infrastructure security, with hands-on exposure to AI/ML systems.
- Experience securing or building LLM-based systems, agentic frameworks, or ML pipelines in cloud environments.
- Understanding of AI-specific attack surfaces, including prompt injection, tool-use exploitation, privilege escalation through inherited access, data poisoning, and model or training-data leakage.
- Hands-on experience building with AI systems.
- Strong Python proficiency and experience building security tooling, automation, and testing.
- Strong knowledge of AWS security, including IAM, networking, container isolation, encryption, and monitoring.
- Familiarity with SOC 2, ISO 27001, ISO 42001, and NIST AI RMF, including mapping technical controls to audit requirements.
- Ability to communicate technical risk to engineers, auditors, and stakeholders.
Nice-to-Haves
- Experience with AI red-teaming or adversarial testing.
- Experience with MCPs, agent orchestration frameworks, or similar agentic infrastructure.
- Background in DLP, monitoring, or observability for AI or cloud workloads.
- Experience at a growth-stage B2B SaaS company.
Compensation & Benefits
- Annual base salary range: $121,000–$226,000 USD.
- Equity grants for all employees.
- 4% matching 401(k) program.
- Medical, dental, vision, disability, and life insurance for employees working 30+ hours per week.
- Monthly wellness stipend.
- Paid parental leave.
- Flexible vacation policy.
Skills
Python, AWS, Aws Iam, Aws Networking, Container Isolation, Encryption, Monitoring, Llm Security, Ai Red Teaming, Mcp, Agent Orchestration, Dlp, SOC 2, Iso 42001, Nist Ai Rmf
Similar jobs
Security Engineering jobsSenior Cloud Security Engineer responsible for designing, implementing, and assessing security controls across a multi-cloud environment. The role requires 5+ years of security solution implementation experience, strong cloud and cybersecurity expertise, and proficiency in risk assessment, infrastructure as code, and security technologies.
The Senior Security Analyst will manage security governance, risk, and compliance activities, including audits, risk assessments, remediation, vendor reviews, and operational security. The role requires 5+ years of relevant experience, a bachelor’s degree, cloud-security knowledge, and hands-on AI-assisted GRC automation experience.
Own and scale Sardine’s security compliance and GRC function across major security, privacy, and resilience frameworks, including FedRAMP. The role leads audits, risk management, customer assurance, executive reporting, and a growing compliance team while partnering closely with technical and business stakeholders.
Build detection, threat-hunting, and automated incident-response capabilities for AI infrastructure, including GPU clusters, training pipelines, and model deployments. The role requires substantial security operations experience, strong programming skills, and expertise in distributed systems or AI/ML environments.
The Senior Information Security Engineer will lead threat hunting, detection engineering, incident response, vulnerability management, and security-platform ownership across cloud and enterprise environments. The role requires 5+ years of security experience, strong attacker-TTP knowledge, and hands-on expertise with enterprise security technologies and automation.