Staff Information Security Engineer - AI First

8 hours, 31 minutes ago
Full-time
Senior
Artificial Intelligence and Machine Learning
Rithum

Rithum

End to End E Commerce Solutions for Brands & Retailers | Rithum CommerceHub and ChannelAdvisor are now united as Rithum. We empower top brands, suppliers, and retailers with durable, profitable e commerce solutions. Rithum is the hottest place for free...

Internet Software & Services
$13M raised

Description

  • Act as the bridge between architectural intent and operational reality, resolving security gaps and helping track and remediate residual risks.
  • Implement preventive, default-on security controls across cloud and enterprise environments using policy-as-code and infrastructure-as-code.
  • Implement and enforce identity and access controls for AI systems and non-human identities in partnership with Platform Engineering and IT.
  • Maintain the information security risk register and translate emerging threats into actionable guidance for engineering teams.
  • Support third-party and vendor risk assessments, especially for vendors processing data through AI pipelines.
  • Automate repetitive security workflows such as evidence collection, access reviews, and alert enrichment.
  • Build or operate AI-assisted security agents with human-in-the-loop approval gates and least-privilege access.
  • Integrate security tools such as SIEM, CSPM, DAST/SAST, and vulnerability scanners with LLM layers to produce actionable insights and responses.
  • Define and enforce security requirements for AI-powered features, including model access controls, prompt-injection mitigations, output validation, and data-handling boundaries.
  • Conduct threat modeling for agentic and LLM-based systems, including tool misuse, indirect prompt injection, and supply chain risk.

Requirements

  • 5+ years of security engineering experience with demonstrated AI/ML security depth, including prompt injection, model supply chain, adversarial inputs, and RAG.
  • Experience using AI tools such as ChatGPT, Copilot, Claude, and LLM frameworks/APIs such as OpenAI, Anthropic, or LangChain.
  • Hands-on identity and access management expertise across modern enterprise and cloud identity stacks, including AI systems and non-human identities.
  • Experience with infrastructure-as-code and policy-as-code tools such as Terraform and OPA/Rego, plus scripting ability in Python or a similar language.
  • Cloud security expertise, including AWS Solutions Architect / Security Specialty or equivalent demonstrated experience with multi-account governance and preventive guardrails.
  • Application security knowledge covering OWASP Top 10, OWASP LLM/GenAI Top 10, secure SDLC, and threat modeling methodologies such as STRIDE or PASTA.
  • Practical experience building or operating AI agents and integrating security tooling such as SIEM, CSPM, SAST/DAST/SCA so it produces actionable output.
  • Working knowledge of SOC 2 and/or ISO 27001 control frameworks.
  • Preferred: experience building or operating AI agents in a production environment.
  • Preferred: awareness of privacy regulations such as GDPR and CCPA as they relate to AI, including privacy-by-design and DPIAs.
  • Preferred: red teaming or adversarial ML research background.
  • Preferred: experience implementing privileged access, key management, posture management, or data protection programs.
  • Preferred: experience with EDR, CASB, DLP, security automation, and SAST/DAST/IAST/SCA tools.
  • Preferred: cloud architecture or security certifications such as CCSK, TAISE, or AWS.

Benefits

  • Expected base salary range of $170,000 to $220,000 per year.
  • 12% discretionary annual bonus for non-sales roles.
  • Medical, dental, and vision coverage with company HSA contributions starting on Day 1.
  • 6% 401(k) match.
  • Competitive time off package including 20 PTO days, 9 company-paid holidays, 2 floating holidays, 7 sick days, 2 wellness days, and 1 paid volunteer day, with PTO increasing to 22 days at 3 years and 25 days at 5 years.
  • 12 weeks primary caregiver leave and 4 weeks secondary caregiver leave.
  • Remote-first working conditions with a $65/month internet stipend.
  • Access to the Calm app and the Employee Assistance Program.
  • Tuition assistance, career development opportunities, and charitable contribution match up to $250 per year.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Mid-Senior IT Professional (Multiple Opportunities)

Hire Resolve US Internet Software & Services

Hire Resolve is assisting IT organizations in hiring mid- to senior-level IT professionals to support U.S.-based operations across infrastructure, cloud, cybersecurity, systems, applications, and technical project delivery.

Active Directory AWS Azure Bash CloudFormation DHCP DNS GCP PowerShell Python SIEM Terraform
8 hours, 16 minutes ago

Mid-Senior IT Professional (Multiple Opportunities)

Hire Resolve US Internet Software & Services

Hire Resolve is hiring mid- to senior-level IT professionals for U.S.-based operations across infrastructure, cloud, cybersecurity, systems, applications, and service delivery, with opportunities to grow into senior leadership roles.

Active Directory AWS Azure Bash CloudFormation Cybersecurity DHCP DNS GCP PowerShell Python SIEM Terraform
8 hours, 16 minutes ago

Mid-Senior IT Professional (Multiple Opportunities)

Hire Resolve US Internet Software & Services

Hire Resolve is assisting IT organizations with mid- to senior-level U.S.-based roles spanning infrastructure, cloud, cybersecurity, systems, networking, IT service management, applications, data platforms, and technical project delivery.

Active Directory AWS Azure Bash CloudFormation Cybersecurity DHCP DNS GCP PowerShell Python SIEM Terraform
8 hours, 31 minutes ago

Mid-Senior IT Professional (Multiple Opportunities)

Hire Resolve US Internet Software & Services

Hire Resolve is helping U.S.-based IT organizations hire mid- to senior-level professionals to support multi-functional technology operations across infrastructure, cloud, cybersecurity, systems, networks, and enterprise applications.

Active Directory AWS Azure Bash CloudFormation Cybersecurity DHCP DNS GCP PowerShell Python SIEM Terraform
8 hours, 31 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers