Staff Information Security Engineer - AI First

1 month, 1 week ago
Full-time
Senior
Artificial Intelligence and Machine Learning
Rithum

Rithum

End to End E Commerce Solutions for Brands & Retailers | Rithum CommerceHub and ChannelAdvisor are now united as Rithum. We empower top brands, suppliers, and retailers with durable, profitable e commerce solutions. Rithum is the hottest place for free...

Internet Software & Services
$13M raised

Description

  • Act as the bridge between architectural intent and operational reality, resolving gaps between security requirements and feasible implementation.
  • Implement preventive, default-on security controls across cloud and enterprise environments using policy-as-code and infrastructure-as-code.
  • Implement and enforce identity and access controls, including boundaries for AI systems and non-human identities.
  • Maintain the information security risk register and translate emerging threats into actionable guidance for engineering teams.
  • Support third-party and vendor risk assessments, especially for vendors that process data through AI pipelines.
  • Automate repetitive security workflows such as evidence collection, access reviews, and alert enrichment.
  • Build or operate AI-assisted security agents with human-in-the-loop approval gates and least-privilege access.
  • Integrate security tooling such as SIEM, CSPM, DAST/SAST, and vulnerability scanners with LLM layers to surface actionable insight.
  • Define and enforce security requirements for AI-powered features, including model access controls, prompt-injection mitigations, output validation, and data-handling boundaries.
  • Conduct threat modeling for agentic and LLM-based systems, including tool misuse, indirect prompt injection, and supply chain risk.

Requirements

  • 5+ years of security engineering experience with demonstrated AI/ML security depth, including prompt injection, model supply chain, adversarial inputs, and RAG.
  • Experience using AI tools such as ChatGPT, Copilot, or Claude, and LLM frameworks/APIs such as OpenAI, Anthropic, or LangChain.
  • Hands-on identity and access expertise across modern enterprise and cloud identity stacks, including access models for AI systems and non-human identities.
  • Experience with infrastructure-as-code and policy-as-code tools such as Terraform and OPA/Rego, plus proficiency in a scripting language for automation, with Python preferred.
  • Cloud security expertise, including AWS Solutions Architect or Security Specialty-level knowledge, multi-account governance, preventive guardrails, and policy-as-code.
  • Application security knowledge covering OWASP Top 10, OWASP LLM/GenAI Top 10, secure SDLC, and threat modeling methodologies such as STRIDE or PASTA.
  • Practical experience building or operating AI agents and integrating security tooling such as SIEM, CSPM, SAST/DAST/SCA so it produces action rather than raw alerts.
  • Working knowledge of SOC 2 and/or ISO 27001 control frameworks.
  • Experience building or operating AI agents in a production environment, preferred.
  • Awareness of privacy regulations such as GDPR and CCPA as they relate to AI, including privacy-by-design and DPIAs, preferred.
  • Red teaming or adversarial ML research background, preferred.
  • Experience implementing privileged access, key management, posture management, or data protection programs, preferred.
  • Experience with EDR, CASB, DLP, security automation, and IAST tools, preferred.
  • Cloud architecture or security certifications such as CCSK, TAISE, or AWS, preferred.
  • Travel up to 10%.

Benefits

  • Base salary range of $170,000 to $220,000 per year.
  • Discretionary bonus of 12% of annual base salary for non-sales roles.
  • Comprehensive benefits package.
  • Medical, dental, and vision coverage with company HSA contributions starting on Day 1.
  • 6% 401(k) match.
  • Generous time off, including 20 PTO days, 9 company-paid holidays, 2 floating holidays, 7 sick days, 2 wellness days, and 1 paid volunteer day, with PTO increasing to 22 days at 3 years and 25 days at 5 years.
  • 12 weeks of primary caregiver leave and 4 weeks of secondary caregiver leave.
  • Remote-first working conditions with a $65/month internet stipend.
  • Access to the Calm app and the Employee Assistance Program.
  • Tuition assistance and career development opportunities.
  • Charitable contribution match up to $250 per year.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Senior AI Engineer

RegScale 11-50 Utilities

RegScale is hiring a Senior AI Engineer to design and deliver production AI systems for its continuous controls monitoring platform, supporting compliance automation across the product and integration ecosystem.

Azure CI/CD Databricks Machine Learning Snowflake
1 minute ago

Senior Risk & Compliance Engineer - Data

instacart.careers 1K-5K Internet Software & Services

Instacart is hiring a Senior Risk & Compliance Engineer to build automated, data-driven risk quantification systems that support security decisions, executive reporting, and board-level visibility.

Machine Learning PostgreSQL Presto Python SQL
1 minute ago

Cloud Engineer I/II - (W2PE) - Remote

Trace3 1K-5K Internet Software & Services

Trace3 is hiring a Cloud Engineer I/II to support government cloud migration and modernization work from a remote, clearance-required environment.

Active Directory AWS Docker EC2
16 minutes ago

Full Stack Lead – IAM Solutions

AHEAD 1K-5K IT Services

The Full Stack Lead, IAM Solutions at the company designs and maintains custom identity and access management systems that automate secure access and integrate across enterprise platforms.

Agile AWS Azure C# CI/CD Cybersecurity Git Java JavaScript JIRA Python REST API Salesforce
16 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers