Staff Information Security Engineer - AI First

9 hours, 31 minutes ago
Full-time
Lead
Artificial Intelligence and Machine Learning
Rithum

Rithum

End to End E Commerce Solutions for Brands & Retailers | Rithum CommerceHub and ChannelAdvisor are now united as Rithum. We empower top brands, suppliers, and retailers with durable, profitable e commerce solutions. Rithum is the hottest place for free...

Internet Software & Services
$13M raised

Description

  • Design and implement preventive, default-on security controls using policy-as-code and infrastructure-as-code.
  • Define access controls and security boundaries for AI systems, agents, models, and non-human identities.
  • Automate security workflows such as evidence collection, access reviews, and alert enrichment.
  • Build and operate AI-assisted security agents with human approval gates, least-privilege access, and controlled blast radius.
  • Integrate SIEM, CSPM, SAST/DAST, vulnerability, and related security tools with LLM-based analysis and response workflows.
  • Define security requirements for AI features, including prompt-injection mitigation, output validation, model access, and data-handling controls.
  • Conduct threat modeling for LLM and agentic systems, including tool misuse, indirect prompt injection, and supply-chain risks.
  • Advise on security architecture, compensating controls, residual risk tracking, emerging threats, and vendor assessments.
  • Collaborate with Platform Engineering, IT, Security Champions, and external auditors to align security implementation with architectural requirements.

Requirements

  • 5+ years of security engineering experience with demonstrated AI/ML security expertise, including prompt injection, model supply chains, adversarial inputs, and RAG.
  • Experience using AI tools and LLM frameworks or APIs such as ChatGPT, Copilot, Claude, OpenAI, Anthropic, or LangChain.
  • Hands-on identity and access management experience across enterprise and cloud environments, including AI and non-human identities.
  • Experience with infrastructure-as-code and policy-as-code tools such as Terraform and OPA/Rego.
  • Proficiency in a scripting language for automation; Python preferred.
  • Cloud security expertise, including AWS multi-account governance, preventive guardrails, and policy-as-code; AWS certification or equivalent expertise.
  • Knowledge of application security, OWASP Top 10, OWASP LLM/GenAI Top 10, secure SDLC, and threat-modeling methods such as STRIDE or PASTA.
  • Experience with AI agents and security tooling including SIEM, CSPM, SAST, DAST, SCA, or vulnerability scanners.
  • Working knowledge of SOC 2 and/or ISO 27001 frameworks.
  • Preferred: production AI-agent experience, GDPR/CCPA and DPIAs, red teaming or adversarial ML, privileged access or data protection programs, EDR/CASB/DLP, and relevant cloud security certifications.
  • Up to 10% travel required.

Benefits

  • Base salary of $170,000-$220,000 annually, plus a 12% discretionary bonus for non-sales roles.
  • Medical, dental, and vision coverage with HSA contributions starting on day one.
  • 6% 401(k) match.
  • Remote-first work, $65 monthly internet stipend, generous PTO, paid holidays, wellness days, sick leave, and volunteer time.
  • 12 weeks of primary caregiver leave and 4 weeks of secondary caregiver leave.
  • Life, accident, critical illness, hospital indemnity, pet, legal assistance, and identity theft insurance.
  • Calm app access, Employee Assistance Program, tuition assistance, career development, and team-building activities.
  • Charitable contribution matching up to $250 annually.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

DevSecOps Engineer

Sparksoft 51-250 Internet Software & Services

Sparksoft is hiring a DevOps and Cloud Infrastructure professional to support government clients by managing AWS infrastructure, deployment pipelines, configuration controls, and software release activities.

Agile AWS CI/CD Git GitHub Jenkins SonarQube SVN
8 hours, 46 minutes ago

Cybersecurity & Software Engineering Specialist (AI Projects)

Gramian Consultancy Group Professional Services

Gramian Consultancy is seeking remote Cybersecurity and Software Engineering Specialists to debug code, identify vulnerabilities, improve backend systems, and provide technical insights for an AI training project.

C++ Cybersecurity Go Java Penetration Testing Python Rust TypeScript
10 hours, 1 minute ago

Security Operations Engineer - PCI DSS

teamified.com Hotels, Restaurants & Leisure

A three-month contract Security Engineer will own the PCI DSS v4.0.1 compliance cycle for a cloud-hosted payments platform, implementing controls, preparing evidence, and completing executive sign-off alongside engineering and operations teams.

AWS Encryption JIRA Penetration Testing Secrets Management SIEM
10 hours, 1 minute ago

Senior Security Engineer Cryptography

Trail of Bits 51-250 Internet Software & Services

Trail of Bits is hiring a remote Senior Security Engineer for its Cryptography practice to assess and strengthen high-assurance cryptographic software and systems for clients across technology, finance, defense, and blockchain.

C C++ Cybersecurity Git Go Rust
10 hours, 1 minute ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers