Staff Information Security Engineer - AI First

6 hours, 47 minutes ago
Full-time
Lead
Artificial Intelligence and Machine Learning
Rithum

Rithum

End to End E Commerce Solutions for Brands & Retailers | Rithum CommerceHub and ChannelAdvisor are now united as Rithum. We empower top brands, suppliers, and retailers with durable, profitable e commerce solutions. Rithum is the hottest place for free...

Internet Software & Services
$13M raised

Description

  • Act as the bridge between security requirements and feasible implementation, proposing compensating controls and helping register, track, and remediate residual risks.
  • Implement preventive, default-on security controls across cloud and enterprise environments using policy-as-code and infrastructure-as-code.
  • Implement and enforce identity and access controls, including access boundaries for AI systems and non-human or agent identities.
  • Maintain the information security risk register and translate emerging threats into actionable guidance for engineering teams.
  • Support third-party and vendor risk assessments, especially for vendors processing data through AI pipelines.
  • Automate repetitive security workflows such as evidence collection, access reviews, and alert enrichment.
  • Build or operate AI-assisted security agents with human-in-the-loop approval gates and least-privilege credentials.
  • Integrate security tooling such as SIEM, CSPM, DAST/SAST, and vulnerability scanners with LLM layers to surface actionable insight and automated responses.
  • Define and enforce security requirements for AI-powered features, including model access controls, prompt-injection mitigations, output validation, and data-handling boundaries.
  • Conduct threat modeling for agentic and LLM-based systems, including tool misuse, indirect prompt injection, and supply chain risk.

Requirements

  • 5+ years of security engineering experience with demonstrated AI/ML security depth, including prompt injection, model supply chain, adversarial inputs, and RAG.
  • Experience using AI tools such as ChatGPT, Copilot, Claude, or similar, and LLM frameworks/APIs such as OpenAI, Anthropic, or LangChain.
  • Hands-on identity and access management expertise across modern enterprise and cloud identity stacks, including access models for AI systems and non-human identities.
  • Experience with infrastructure-as-code and policy-as-code, such as Terraform and OPA/Rego, plus proficiency in a scripting language for automation, with Python preferred.
  • Cloud security expertise, such as AWS Solutions Architect or Security Specialty level knowledge, including multi-account governance and preventive guardrails.
  • Application security knowledge covering OWASP Top 10, OWASP LLM/GenAI Top 10, secure SDLC, and threat modeling methods such as STRIDE or PASTA.
  • Practical experience building or operating AI agents and integrating security tooling such as SIEM, CSPM, SAST/DAST/SCA to drive action rather than raw alerts.
  • Working knowledge of SOC 2 and/or ISO 27001 control frameworks.
  • Experience building or operating AI agents in a production environment, preferred.
  • Awareness of privacy regulations such as GDPR and CCPA as they apply to AI, preferred.
  • Red teaming or adversarial ML research background, preferred.
  • Experience implementing privileged access, key management, posture management, or data protection programs, preferred.
  • Experience with EDR, CASB, DLP, and security automation tools including SAST, DAST, IAST, and SCA, preferred.
  • Cloud architecture or security certifications such as CCSK, TAISE, or AWS certifications, preferred.
  • Ability to travel up to 10%.

Benefits

  • Expected base salary range of $170,000 to $220,000 per year.
  • Discretionary bonus of 12% of annual base salary.
  • Medical, dental, and vision coverage with company HSA contributions starting on Day 1.
  • 6% 401(k) match.
  • Competitive time off package including 20 PTO days, 9 company holidays, 2 floating holidays, 7 sick days, 2 wellness days, and 1 paid volunteer day, with increased PTO at 3 and 5 years of service.
  • 12 weeks of primary caregiver leave and 4 weeks of secondary caregiver leave.
  • Remote-first working conditions with a $65/month remote work internet stipend.
  • Access to the Calm app, Employee Assistance Program, tuition assistance, career development opportunities, pet insurance, legal assistance, identity theft insurance, life insurance, and charitable contribution matching.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Senior Software Engineer II, AI Native, Experimentation & ML

Life360 251-1K Family Services

Life360 is hiring a remote-first Senior Software Engineer II to build and evolve the backend experimentation, recommendation, and AI-native engineering infrastructure that powers personalized experiences at consumer scale.

AWS CI/CD Datadog Flink GitHub Actions Grafana Java Kafka LLM Maven Microservices Prometheus Spring Boot
6 hours, 47 minutes ago

Mid-Senior IT Professional (Multiple Opportunities)

Hire Resolve US Internet Software & Services

Hire Resolve is assisting IT organizations in hiring mid- to senior-level IT professionals to support U.S.-based operations across infrastructure, cloud, cybersecurity, systems, applications, and technical project delivery.

Active Directory AWS Azure Bash CloudFormation DHCP DNS GCP PowerShell Python SIEM Terraform
7 hours, 2 minutes ago

Mid-Senior IT Professional (Multiple Opportunities)

Hire Resolve US Internet Software & Services

Hire Resolve is hiring mid- to senior-level IT professionals for U.S.-based operations across infrastructure, cloud, cybersecurity, systems, applications, and service delivery, with opportunities to grow into senior leadership roles.

Active Directory AWS Azure Bash CloudFormation Cybersecurity DHCP DNS GCP PowerShell Python SIEM Terraform
7 hours, 2 minutes ago

Mid-Senior IT Professional (Multiple Opportunities)

Hire Resolve US Internet Software & Services

Hire Resolve is assisting IT organizations with mid- to senior-level U.S.-based roles spanning infrastructure, cloud, cybersecurity, systems, networking, IT service management, applications, data platforms, and technical project delivery.

Active Directory AWS Azure Bash CloudFormation Cybersecurity DHCP DNS GCP PowerShell Python SIEM Terraform
7 hours, 17 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers