- Full-time
Sr. AI/ML Security Engineer
Remote
Requirements:
- 10+ years of security (cyber security, platform security, etc.) engineering experience using tools such as SIEM, IAM/PAM, RBAC/ABAC, etc.
- 3+ years of AI Security engineering experience with specific focus on AI/ML platforms, generative AI/LLM technologies, and/or model-serving ecosystems
- Hands on experience with Kong, LiteLLM, or similar API gateway/LLM proxy technologies (e.g. Apigee, Portkey, etc.)
- Hands on experience with AWS (preferred), Azure, or GCP cloud services
- Hands on platform engineering experience with IaC, CI/CD security, and other operational tasks
- Hands on experience with threat modeling, AI/LLM/Agentic system guardrails, identity verification and authorization
- Strong communication and documentation experience
- Experience with AI/LLM platform engineering is a strong plus (e.g. RAG, AI Agents, LangChaing, LangGraph, MCP ecosystems, A2A communications, etc.)
- Security certifications such as CISSP, OSCP, CEH, CASP+, CISM are highly desired
Key Responsibilities
AI Gateway Architecture & Engineering
• Design and implement enterprise AI gateway solutions using Kong AI Gateway, LiteLLM, and related technologies.
• Establish secure routing patterns for LLM traffic across internal, third-party, and cloud-hosted foundation models.
• Develop standardized onboarding patterns for applications, agents, copilots, and autonomous systems using centralized gateway controls.
• Define scalable gateway architectures supporting high availability, failover, token management, model routing, provider abstraction, rate limiting, and policy enforcement.
• Create security standards for AI API management, service-to-service authentication, gateway plugins, and runtime governance.
AI Runtime Security Controls
• Engineer and deploy runtime controls governing prompts, responses, tool usage, memory access, retrieval operations, model calls, and agent actions.
• Integrate AI guardrail solutions with gateway enforcement layers for inline inspection and policy decisions.
• Design controls to detect and prevent prompt injection, jailbreak attacks, data exfiltration, sensitive data leakage, malicious tool invocation, agent privilege escalation, and unsafe autonomous actions.
• Implement policy-driven outcomes including allow, detect, block, redact, modify, quarantine, and human approval workflows.
• Define anti-bypass controls that reduce direct-to-model access outside approved enterprise pathways.
Agentic AI & Identity Security
• Develop security architectures for AI agents, agent-to-agent communication, MCP servers, plugins, tools, and autonomous workflows.
• Design identity-aware enforcement using OAuth 2.0, OpenID Connect, workload identity, machine identities, just-in-time authorization, RBAC, and ABAC.
• Establish delegated authorization patterns that constrain agent actions based on user authority, application risk, tool sensitivity, and business context.
• Define standards for tool registration, access governance, privilege boundaries, approval gates, and kill-switch capabilities.
API, Cloud & Platform Security
• Secure AI-facing APIs, gateway plugins, MCP integrations, model endpoints, and service-to-service communication.
• Perform threat modeling and security design reviews for AI platforms, applications, and distributed runtime architectures.
• Partner with cloud and platform engineering teams to implement Zero Trust patterns, network segmentation, secrets management, certificate management, and secure workload authentication.
• Drive secure deployment patterns across AWS, Azure, Kubernetes, container platforms, and cloud-native AI services.
• Embed security testing and policy validation into CI/CD and infrastructure-as-code workflows.
Monitoring, Detection & Response
• Build centralized observability across AI gateways and runtime enforcement points.
• Integrate gateway, guardrail, identity, application, and model telemetry into enterprise SIEM and detection engineering platforms.
• Develop detections for prompt attacks, policy violations, data leakage, unauthorized model usage, anomalous token consumption, excessive permissions, and agent misuse.
• Define operational metrics for control coverage, control efficacy, false positives, false negatives, bypass resistance, latency, availability, and failure modes.
• Create incident response playbooks for AI security events, gateway failures, guardrail bypasses, compromised identities, and unsafe autonomous behavior.
Strategic & Technical Leadership
• Serve as the AI gateway and runtime security subject matter expert.
• Partner with architecture, platform engineering, application security, identity, data security, and AI governance teams on enterprise AI strategy.
• Evaluate emerging AI security technologies, frameworks, gateway capabilities, and vendor solutions through structured technical assessments and proofs of concept.
• Define reusable reference architectures, engineering standards, implementation patterns, operational runbooks, and control requirements.
• Mentor engineers and help advance organizational AI security maturity.
Qualifications
Required Qualifications
• 7+ years of experience in cybersecurity, cloud security, application security, platform security, or security engineering.
• 3+ years working with AI/ML platforms, generative AI technologies, LLM applications, or model-serving ecosystems.
• Hands-on experience with Kong, LiteLLM, or comparable API gateway and LLM proxy technologies.
• Experience with Kubernetes, containers, REST APIs, service-to-service communication, and cloud platforms such as AWS or Azure.
• Strong knowledge of OAuth 2.0, OpenID Connect, secrets management, workload identity, and authorization models.
• Experience threat modeling distributed systems, APIs, AI applications, and cloud-native architectures.
• Strong software engineering or automation experience using Python, Go, Java, or a similar language.
• Experience with infrastructure as code, CI/CD security, logging, monitoring, and operational support.
Preferred Qualifications
• Experience securing LLM applications, AI agents, LangChain, LangGraph, MCP ecosystems, RAG pipelines, and autonomous workflows.
• Experience implementing AI guardrails, runtime policy engines, DLP integrations, content inspection, and AI governance platforms.
• Familiarity with NIST AI RMF, ISO/IEC 42001, OWASP guidance for LLM and GenAI applications, MITRE ATLAS, and Zero Trust Architecture.
• Experience operating enterprise API management, service mesh, model routing, or multi-provider AI platforms.
• Background supporting regulated or large-scale enterprise AI initiatives.
Thanks,
vikas@tekleaders.com