Information Security Engineer - AI First
Listed on 2026-09-17
-
IT/Tech
AI Engineer (Applied/Software), Cybersecurity, Information Security & Data Protection
Staff Information Security Engineer - AI First
Strong AI-first focus — integrates LLMs and AI assistants into security tooling and builds AI-assisted security agents with human-in-the-loop controls.
About the RoleRithum is hiring a Staff Information Security Engineer focused on securing AI adoption across products and operations. The role designs and implements preventive, policy- and infrastructure-as-code security controls, automates security workflows and integrates LLMs/AI into security tooling to enable safe, scalable AI usage across the company.
Job Description RoleRithum seeks a Staff AI-First Information Security Engineer to own the intersection of AI adoption and information security. You will design guardrails for AI-powered products and workforce use, build automated security tooling, codify controls as policy- and infrastructure-as-code, and enable fast, low-risk AI usage across engineering and platform teams.
Key Responsibilities- Bridge architectural intent and operational reality; propose compensating controls and manage residual risk tracking and remediation.
- Implement preventive, default-on security controls across cloud and enterprise environments, codified as policy- and infrastructure-as-code.
- Implement and enforce identity and access controls, including access boundaries for AI systems and non-human/agent identities.
- Maintain the Info Sec risk register; track emerging threats and translate them into actionable guidance.
- Support third-party/vendor risk assessments with emphasis on vendors processing data through AI pipelines.
- Automate repetitive security workflows (evidence collection, access reviews, alert enrichment) and build/operate AI-assisted security agents with human-in-the-loop gates and least-privilege credentials.
- Integrate security tooling (SIEM, CSPM, DAST/SAST, vulnerability scanners) with LLM layers to surface actionable insight and automated response.
- Define and enforce security requirements for AI features: model access controls, prompt-injection mitigations, output validation, and data-handling boundaries.
- Conduct threat modeling for agentic and LLM-based systems, addressing novel attack surfaces like tool misuse, indirect prompt injection, and supply chain risk.
Minimum Qualifications
- 5+ years of security engineering experience with demonstrated AI/ML security depth (prompt injection, model supply chain, adversarial inputs, RAG).
- Experience using AI tools (ChatGPT, Copilot, Claude) and LLM frameworks/APIs (OpenAI, Anthropic, Lang Chain) to accelerate work.
- Hands-on identity and access expertise across modern enterprise and cloud identity stacks, including access models for AI and non-human identities.
- Experience with infrastructure and policy-as-code (e.g., Terraform, OPA/Rego) and proficiency in a scripting language for automation (Python preferred).
- Cloud security expertise (AWS-focused experience/certification or equivalent), including multi-account governance and preventive guardrails.
- Application security knowledge (OWASP Top 10, OWASP LLM/GenAI Top 10), secure SDLC, and threat-modeling methodologies (STRIDE, PASTA, or equivalent).
- Practical experience building or operating AI agents and integrating security tooling (SIEM, CSPM, SAST/DAST/SCA) for actionable outputs.
- Working knowledge of SOC 2 and/or ISO 27001 control frameworks.
- Production experience building or operating AI agents.
- Awareness of privacy regulations affecting AI (GDPR/CCPA), privacy-by-design, and DPIAs.
- Red teaming or adversarial ML research experience.
- Experience implementing privileged-access, key-management, posture-management, or data-protection programs.
Experience with EDR, CASB, DLP, security automation, and SAST/DAST/IAST/SCA tools.
Cloud…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).