Staff Information Security Engineer - AI First

2 hours, 39 minutes ago
Full-time
Lead
Artificial Intelligence and Machine Learning
Rithum

Rithum

End to End E Commerce Solutions for Brands & Retailers | Rithum CommerceHub and ChannelAdvisor are now united as Rithum. We empower top brands, suppliers, and retailers with durable, profitable e commerce solutions. Rithum is the hottest place for free...

Internet Software & Services
$13M raised

Description

  • Bridge security architecture and operational implementation, resolving feasibility gaps and tracking residual risks.
  • Implement preventive, default-on cloud and enterprise security controls using policy-as-code and infrastructure-as-code.
  • Enforce identity and access controls for AI systems, cloud environments, and non-human or agent identities.
  • Maintain risk tracking, monitor emerging threats, and provide actionable guidance to engineering teams.
  • Support third-party and vendor risk assessments, particularly for AI data-processing vendors.
  • Automate evidence collection, access reviews, alert enrichment, and other repetitive security workflows.
  • Build or operate AI-assisted security agents with human approval gates, least-privilege credentials, and controlled blast radius.
  • Integrate SIEM, CSPM, SAST/DAST, and vulnerability-scanning tools with LLM capabilities.
  • Define security requirements for AI features, including model access, prompt-injection mitigation, output validation, and data boundaries.
  • Threat-model agentic and LLM systems, including tool misuse, indirect prompt injection, and supply-chain risks.

Requirements

  • 5+ years of security engineering experience with demonstrated AI/ML security expertise, including prompt injection, model supply chain, adversarial inputs, and RAG.
  • Experience using AI tools and LLM frameworks or APIs such as ChatGPT, Copilot, Claude, OpenAI, Anthropic, or LangChain.
  • Hands-on expertise with enterprise and cloud identity systems, including AI and non-human identity access models.
  • Experience with infrastructure-as-code and policy-as-code, such as Terraform and OPA/Rego, plus scripting skills; Python preferred.
  • Cloud security expertise equivalent to AWS Solutions Architect or Security Specialty, including multi-account governance and preventive guardrails.
  • Knowledge of OWASP Top 10, OWASP LLM/GenAI Top 10, secure SDLC, and threat-modeling methods such as STRIDE or PASTA.
  • Practical experience operating AI agents and integrating SIEM, CSPM, SAST/DAST/SCA, or related tooling.
  • Working knowledge of SOC 2 and/or ISO 27001 frameworks.
  • Preferred: production AI-agent experience, GDPR/CCPA privacy-by-design, red teaming or adversarial ML, privileged access, key management, DLP, EDR, CASB, or security automation experience.
  • Preferred: CCSK, TAISE, AWS, or other cloud security certifications; willingness to travel up to 10%.

Benefits

  • $170,000–$220,000 annual base salary plus a 12% discretionary bonus.
  • Medical, dental, and vision coverage with company HSA contributions starting on day one.
  • 6% 401(k) match.
  • Remote-first work with a $65/month internet stipend.
  • Paid time off, company holidays, sick days, wellness days, and a volunteer day.
  • 12 weeks of primary caregiver leave and 4 weeks of secondary caregiver leave.
  • Tuition assistance, career development opportunities, wellness and mental health resources, and additional insurance programs.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Cybersecurity Engineer III (Cleared)

Rise8 11-50 Internet Software & Services

Rise8 is hiring a Cybersecurity Engineer III to secure cloud-based government systems and integrate security practices into delivery of critical federal missions.

Agile Ansible AWS Azure Bash Cybersecurity DNS Encryption Kubernetes Linux Python Terraform
3 hours, 9 minutes ago

Staff Security Engineer - Data Security

Aledade 1K-5K Health Care Providers & Services

Aledade PBC is seeking a Staff Security Engineer to build and operate scalable security services and data-protection solutions for its remote-first healthcare technology environment.

AWS Azure C# C++ CI/CD Databricks Encryption Go HIPAA Java PostgreSQL Python Scala Snowflake
3 hours, 24 minutes ago

Sr. Security Engineer I (Identity Access Management)

Aledade 1K-5K Health Care Providers & Services

Aledade PBC is hiring a remote Senior Security Engineer I to strengthen enterprise and cloud-native security, with a primary focus on identity and access management across the organization.

AWS Azure PowerShell Python Terraform
3 hours, 39 minutes ago

Staff Security Engineer

Digitalzone 251-1K Media

As DigitalZone’s senior individual-contributor security engineer, you will set technical security direction across its platform, protecting applications, cloud infrastructure, payment systems, and identity flows through hands-on engineering and organizational enablement.

AWS OWASP Penetration Testing Secrets Management
4 hours, 9 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers