Staff Information Security Engineer - AI First
Core
Designing guardrails for AI-powered products, building automated security tooling, and enforcing security controls for an AI-first workforce.
Role type
Staff AI-First Information Security Engineer
Builds
Automated security tooling, AI-assisted security agents, and infrastructure-as-code security controls
Domain
E-commerce, AI/ML Security, Cloud Security
Deliverable
production ML models | infrastructure
Required skills
AI/ML security (prompt injection, model supply chain, adversarial inputs, RAG), Identity and access management (including non-human/agent identities), Infrastructure and policy-as-code (Terraform, OPA/Rego), Python scripting, Cloud security (AWS), Application security (OWASP Top 10, OWASP LLM/GenAI Top 10), Threat modelling (STRIDE, PASTA), Security automation (SIEM, CSPM, SAST/DAST/SCA integration)
Preferred skills
Production AI agent development, Privacy regulation awareness (GDPR/CCPA), Red teaming or adversarial ML research, Privileged-access and key-management programs, EDR/CASB/DLP tools, Cloud Architecture or Security certifications (CCSK, TAISE, AWS)
Technologies
Terraform, OPA/Rego, Python, AWS, OpenAI, Anthropic, LangChain, SIEM, CSPM, SAST, DAST, SCA, EDR, CASB, DLP
Responsibilities
Mediate conflicts between security requirements and feasible implementation; Implement preventive, default-on security controls codified as policy- and infrastructure-as-code; Enforce identity and access controls for AI systems and non-human identities; Maintain the InfoSec risk register and track emerging threats; Support third-party and vendor risk assessments for AI pipelines; Automate security workflows and build AI-assisted security agents; Integrate security tooling with LLM layers; Define security requirements for AI-powered features (model access, prompt injection, output validation); Conduct threat modelling on agentic and LLM-based systems
Seniority
Staff, hands-on IC with strategic scope