Senior AI Platform Security Engineer - Contract to Hire
About the role
Front is the customer operations platform built for B2B complexity, keeping every team, tool, and customer conversation in sync so companies can scale without losing connection. Over 9,000 companies, including Uber Freight, Navan, and Stripe, rely on Front because it's the only one that can run the operational layer that makes customer-facing work succeed.
GTM Engineers at Front are shipping internal tools and AI agents on top of Salesforce, Gong, Snowflake, Workato, Notion, and Claude—automations that revenue teams depend on. You'll decide how internal software at Front gets built, deployed, secured, and operated—the standards, the reference architecture, the review bar—and then implement them yourself as the estate grows. There is no separate team to hand a standards document to; writing it and building it are the same job.
Your users are other engineers, and your job is measured by how fast and safely they can move. You'll report into Corporate IT and work alongside the GTM Systems, Data, and product engineering teams whose tooling and engineers the platform depends on.
Responsibilities
- Define How We Build And Run Internal Software
- Set the standards for internal engineering at Front: how services are structured and deployed, how environments and secrets work, what gets logged, what "production-ready" means for an internal tool.
- Partner with product engineering to inherit their tooling, patterns, and processes wherever they apply. Extend Front’s existing production foundation to internal systems, not build a second one.
- Define the reference architecture for internal systems and the security requirements every internal tool must meet before touching governed data.
- Own the review bar: decide what needs review, what can ship freely, and say no when something isn’t ready—with a clear reason and path forward.
- Keep standards honest: revisit them when they cause friction, retire those that stop earning their keep, and ensure documentation matches reality.
- Build consensus for your opinions across GTM Systems, Data, Enterprise Security, and Legal.
- Own the infrastructure
- Own the cloud infrastructure (AWS & Snowflake) for internal tools and AI systems: compute, networking, data stores, DNS, certificates.
- Define infrastructure as code and eliminate manual provisioning. Manage state, modules, and drift.
- Own environments (production, staging, local) and make them consistent so "it worked in staging" is meaningful.
- Run the observability stack: metrics, logs, traces, and alerting that engineers can self-serve.
- Own platform cost: right-size infrastructure, attribute spend to teams/tools, and flag anomalies.
- Build the paved road
- Build and maintain CI/CD so GTM Engineers can ship without asking: pipelines, test/scan gates, deploy/rollback.
- Provide golden paths—templates, base images, shared modules/libraries—so the standard way is secure, observable, and cost-sane.
- Own secrets architecture: centralized storage, scoped short-lived credentials, and automated rotation.
- Reduce toil through automation and self-service.
- Secure the platform and the code that runs on it
- Own security of infrastructure and SDLC for internal systems: IaC scanning, container/image hygiene, dependency/supply-chain scanning, secret detection, CI/CD hardening.
- Harden cloud configuration against CIS or equivalent baselines, track drift, and remediate proactively.
- Run vulnerability management: scanning, triage, prioritization, patch coordination, and verification against SLAs.
- Be the security review for new infrastructure, integrations, and AI tooling before they touch governed data.
- Design access/network boundaries to limit blast radius. Enforce least privilege on the infrastructure layer.
- Respond to incidents: containment, evidence preservation, coordination with Enterprise Security.
- Own security monitoring/alerting: build/tune detections for anomalous patterns, unusual data egress, off-hours access, privilege escalation.
- Monitor audit logs from AI, Workato, and MCP layers; triage signal from noise and automate alerts.
- Define and implement Data Loss Prevention (DLP) controls for governed data leaving via AI clients or exports.
- Compliance, incident response, and RBAC
- Maintain and rehearse incident runbooks/tabletop exercises for scenarios like leaked credentials, over-broad access, prompt-injection data disclosure.
- Assist GRC with evidence collection for SOC 2, ISO, and other compliance frameworks.
- Scope reviews and access audits for MCP, Workato, and AI client integrations on a predictable cadence.
- Respond to access requests/incidents; replace standing access with just-in-time.
- Partner with GTM Systems/Data teams to define access requirements using RBAC, ABAC, or hybrid models.
- Partner with IAM to implement joiner-mover-leaver (JML) automations and leverage access governance tools.
- AI client layer
- Provide escalation support for troubleshooting MCP and tool integrations with AI clients (Claude, ChatGPT, Notion).
- Maintain semantic layer configuration: tool definitions, schema descriptions, semantic views.
- Treat unauthorized exposure through an AI client as a security incident, not a bug.
- Root-cause data quality complaints.
- Keep it running, and keep engineers unblocked
- Operate the AI/data plumbing (Workato recipes, MCP connectors, Snowflake access paths) and absorb upstream API/schema changes without downstream disruption.
- Serve as escalation point for platform problems with clear triage, communication, and resolution.
- Participate in on-call rotation (TBD: confirm details) and write postmortems with owned, dated follow-ups.
- Maintain runbooks and architecture documentation so the platform is operable by more than one person.
- Review other engineers’ infrastructure/deployment changes and raise the bar through review.
Requirements
- Required
- Established a platform, DevOps, or infrastructure practice where none existed (e.g., founding platform engineer, early infra hire). Can point to conventions you wrote that are still in use.
- Deep hands-on experience running production infrastructure in a major cloud (networking, IAM, compute, and their failure modes).
- Infrastructure as code in production at scale: Terraform, Pulumi, CloudFormation, or equivalent (including refactoring others’ modules).
- Owned CI/CD pipelines end-to-end: test, scan, and deploy gates. Experience with containers and orchestration.
- Strong Python or Go for automation, tooling, and debugging systems you didn’t write.
- Practical infrastructure security: cloud hardening, secrets management, vulnerability management, least-privilege access design.
- Clear written communication and judgment to enforce standards in pipelines vs. discussions. Experience writing documentation engineers actually use.
- Strong SQL experience (Snowflake or other BI tools).
- Hands-on security operations: log/audit analysis, alert triage, real incident response. Experience with SIEMs.
- Experience implementing SAML/OIDC SSO and SCIM for internal tools and integrating with identity providers like Okta.
- Strong secrets management experience: OAuth, API keys, JWT service accounts.
- Production iPaaS experience (e.g., repairing integrations you didn’t write).
- Bias toward documentation: write down what you do for others to reference.
- Nice to have
- Experience building an internal developer platform (customers = other engineers).
- Operated LLM/agent infrastructure in production: MCP servers, RAG pipelines, semantic layers, or AI tooling connected to enterprise data.
- Familiarity with AI-specific security risks: prompt injection, tool-use abuse, data leakage through model context, and mitigating controls.
- iPaaS or orchestration experience: Workato, Airflow, dbt, MuleSoft, or similar.
- Detection engineering or SIEM exposure (Splunk, Panther, Datadog Security).
- Snowflake or comparable cloud data warehouse operations (cost/performance tuning).
- Background supporting GTM/revenue organizations (Gong, HubSpot, Outreach, or similar GTM tooling).
- Master data management, entity resolution, or customer data platforms.
- Comfort with pipeline, ARR, and product-adoption metrics.
What This Role Is Not
- Not primarily an internal tools building role. GTM Engineers build the tools; you build and secure what they run on.
- Not a customer-facing product role. You won’t work on Front’s product or its production infrastructure.
- Not a research or model-training role. You won’t fine-tune models or publish papers.
- Not a standards-on-paper role. You’ll define practices, build them, enforce them in pipelines, and operate them.