rithumliboard

Staff Information Security Engineer - AI First

Apply Now

At a Glance

Location
United States
Work Regime
remote
Experience
5+ years
Compensation
e expected base pay range is: $170,000-$220,000 per year. This range represen
Posted
2026-06-18T17:04:57-04:00

Key Requirements

Required Skills

AWSPythonTerraform

Certifications

  • ISO

Domain Knowledge

  • Automation
  • Engineering
  • Supply Chain

Requirements

5+ years of security engineering experience with demonstrated AI/ML security depth (prompt injection, model supply chain, adversarial inputs, RAG).

Experience using AI tools (ChatGPT, Copilot, Claude, etc.) and LLM frameworks and APIs (OpenAI, Anthropic, LangChain, or similar) to accelerate and elevate your work.

Hands-on identity and access expertise across modern enterprise and cloud identity stacks, including access models for AI systems and non-human identities.

Infrastructure and policy-as-code (e.g.

Terraform, OPA/Rego) and proficiency in a scripting language for automation (Python preferred).

Cloud security expertise: AWS Solutions Architect / Security Specialty or equivalent demonstrated expertise, including multi-account governance, preventive guardrails, and policy-as-code.

Compensation & Benefits

Medical, dental and vision benefits: Affordable health care plans and company HSA contributions, starting on Day 1

A 6% 401(k) match

Competitive time off package with 20 days of Paid Time Off, 9 Company-Paid holidays, 2 paid floating holidays, 7 paid sick days, 2 Wellness days, and 1 Paid Volunteer Day; at 3 years of service PTO increases to 22 days, and at 5 years it increases to 25 days

12 weeks primary caregiver leave & 4 weeks secondary caregiver leave

Accident, critical illness, and hospital indemnity insurance

Pet insurance

Responsibilities

Act as the bridge between architectural intent and operational reality; mediate conflicts between security requirements and feasible implementation, propose compensating controls where gaps exist and help register, track and remediate residual risks.

Implement preventive, default-on security controls across cloud and enterprise environments, codified as policy- and infrastructure-as-code so security is enforced by design, including controls that govern how AI tools and models may be used.

Implement and enforce identity and access controls to an agreed standard, including access boundaries for AI systems and non-human/agent identities by partnering with Platform Engineering and IT to align tooling and policy to the architecture.

Assist in maintaining the InfoSec risk register; track emerging threats and translate them into actionable guidance for engineering teams.

Support third-party and vendor risk assessments, with a focus on vendors who process data through AI pipelines.

Automate repetitive security workflows (evidence collection, access reviews, alert enrichment) and build or operate AI-assisted security agents — with human-in-the-loop approval gates, least-privilege credentials, and explicit attention to each agent's own blast radius.