Senior Application Security Engineer
GDH · St Louis, MO · Yesterday
Information Technology$60–$72/hrInternship
About the Role
This position focuses on securing AI/ML systems throughout their entire lifecycle, including data ingestion, training, deployment, and inference. The role involves identifying and mitigating AI-specific security threats, ensuring the integrity of AI supply chains, and establishing best practices and policies for AI security. The individual will collaborate with cross-functional teams to integrate security measures, monitor emerging threats, and provide guidance on compliance and AI governance.
Responsibilities
- Conduct threat modeling for AI/ML systems across all stages of development and deployment.
- Assess and mitigate risks related to prompt injection, jailbreaks, data poisoning, adversarial attacks, and insecure use of AI tools.
- Secure the AI supply chain, including model provenance, third-party, and open-source model evaluation.
- Develop and implement AI security policies, standards, and secure development practices for engineering teams.
- Partner with detection and response teams to monitor AI-related threats and incidents.
- Review and harden third-party AI vendors and integrations, ensuring compliance with relevant standards.
- Create controls around AI prompts, data workflows, and AI guardrails across organizational systems.
- Continuously analyze the AI threat landscape and translate research into practical security mitigations.
- Provide technical expertise and guidance to IT and other cross-functional teams on secure AI adoption and use.
- Develop AI security guidance, reference materials, and support customer engagements through workshops and briefings.
Requirements
- Bachelor’s degree in Computer Science, Software Engineering, Information Security, or related field, or equivalent hands-on experience.
- Minimum of 8 years in security engineering, information security, or related disciplines, with a focus on AI/ML systems security.
- Proven experience developing and executing enterprise security strategies for AI/ML technologies.
- Deep understanding of AI/ML technical concepts and security frameworks such as NIST AI RMF, MITRE ATLAS, and OWASP.
- Experience securing cloud, hybrid, or on-premises organizational tool stacks.
- Strong knowledge of AI security threats, risks, and mitigation strategies.
- Hands-on experience with threat modeling, secure design, and access controls applied to AI/ML systems.
- Practical experience with AI red-teaming, prompt injection, data poisoning, and model extraction techniques.
- Proficiency in programming, particularly Python, for security tooling and automation across AI/ML workflows.
- Experience securing cloud environments like AWS, Azure, GCP, and containerized platforms such as Kubernetes.
- Ability to integrate security into MLOps pipelines, including model and dataset integrity checks and automated security testing.
- Excellent communication skills for interacting with technical teams, leadership, and customers.
- Track record mentoring engineers and serving as a technical authority in AI security.
Preferred Qualifications
- Experience with AI/ML security tooling and AI security posture management platforms, such as Wiz AI-SPM, Protect AI, or similar solutions.
- Familiarity with OWASP Top 10 for LLM Applications, Agentic AI security frameworks, and enterprise AI risk management.
- Practical knowledge of agent frameworks like LangChain, AutoGen, or custom agent architectures.
- Experience working within governance, risk, and compliance frameworks for AI.
- Client-facing experience in translating AI security concepts through briefings, workshops, or advisory roles.
- Industry certifications such as CISSP, OSCP, or cloud security certifications, with emerging credentials in AI security being a plus.
Candidates must be legally authorized to work in the United States without employer sponsorship, now or in the future.
Pay
$60.00 – $72.00 hourly
Schedule
This is a fully remote role and can be performed from an approved location.