AI Security Engineer
Job Description
We are seeking a skilled AI Security Engineer to help design, implement, and maintain secure cloud-native AI platforms and applications. This role focuses on securing AI/ML workloads, cloud infrastructure, APIs, data pipelines, and modern software supply chains across enterprise environments.
The ideal candidate will have a strong background in cloud security engineering, combined with practical exposure to AI/ML technologies, AI security risks, and MLSecOps practices. You will work closely with cloud, engineering, DevOps, and AI/ML teams to implement scalable security controls and support secure adoption of AI-enabled solutions.
This role also includes supporting software and AI supply chain security initiatives through management and validation of SBOM, CBOM, AIBOM, and KBOM artifacts.
Key Responsibilities
• Cloud Security Engineering
• Design, implement, and maintain security controls for cloud-native environments and AI/ML workloads.
• Secure cloud infrastructure, services, APIs, containers, and workloads across public cloud platforms.
• Experience in managing CSPM tools such as Prisma, wiz, orca etc.
• Implement and manage:
• IAM and least-privilege access controls
• Network segmentation and secure connectivity
• Encryption and key management
• Secrets management and workload isolation
• Logging, monitoring, and alerting controls
• Conduct cloud security assessments, configuration reviews, and risk analysis.
• Support security hardening for cloud-hosted AI services and model-serving infrastructure.
• AI/ML Security
• Support secure deployment and operation of AI/ML systems, including:
• LLM-based applications
• RAG systems
• Model APIs and inference services
• Agentic AI workflows
• Identify and assess AI-specific security risks such as:
• Prompt injection and jailbreak attacks
• Model abuse and unauthorized access
• Data poisoning and sensitive data leakage
• Model inversion and extraction attacks
• Implement AI security controls including:
• Prompt filtering and validation
• Output sanitization
• Access restrictions and guardrails
• Data protection and context isolation
• Participate in AI threat modeling and security design reviews.
• MLSecOps / DevSecOps
• Integrate security controls into AI/ML and cloud CI/CD pipelines.
• Support secure practices for:
• Model training and deployment
• Container security
• Infrastructure as Code (IaC)
• Dependency and artifact validation
• Implement automated security checks for:
• Models and datasets
• APIs and infrastructure
• Containers and cloud workloads
• Assist with secure model versioning, rollback, and deployment validation.
• Software & AI Supply Chain Security
• Support secure software and AI supply chain initiatives.
• Generate, validate, and manage:
• SBOM (Software Bill of Materials)
• CBOM (Cryptography Bill of Materials)
• AIBOM (AI Bill of Materials)
• KBOM (Knowledge Bill of Materials)
• Integrate BOM generation and validation into CI/CD and deployment workflows.
• Track dependencies, model provenance, datasets, third-party AI integrations, and cryptographic components.
• Support vulnerability management and compliance activities related to software and AI supply chains.
Required Qualifications
• Bachelor’s degree in Computer Science, Cybersecurity, Information Security, or related field (or equivalent practical experience).
• 4–7 years of experience in:
• Cloud security engineering
• Security operations or security engineering
• Application or infrastructure security
• Hands-on experience with cloud-native security controls, architectures and CSPM tools.
• Understanding of:
• IAM, encryption, network security, and secrets management
• Secure SDLC and vulnerability management
• Containers, APIs, and CI/CD security
• Familiarity with AI/ML concepts and AI security risks.
• Experience with scripting/programming languages such as:
• Python (preferred)
• Bash, Go, or JavaScript/TypeScript
Preferred Qualifications
• Experience with:
• AI/ML platforms and orchestration frameworks
• RAG systems, vector databases, and model-serving platforms
• Infrastructure as Code (Terraform, CloudFormation, etc.)
• Security automation and cloud compliance tooling
• Familiarity with:
• OWASP Top 10 for LLMs
• NIST AI RMF
• MITRE ATLAS
• MLSecOps and MLOps concepts
• Experience working with:
• BOM standards and tooling (CycloneDX, SPDX, etc.)
• Container and artifact security solutions
• Secure software supply chain practices
• Relevant cloud or security certifications are a plus.
Core Competencies
• Strong analytical and troubleshooting skills
• Ability to identify and mitigate cloud and AI security risks
• Effective communication and collaboration across technical teams
• Strong ownership mindset and attention to detail
• Ability to work in fast-paced, engineering-driven environments
