about 2 months ago
Base Salary
$180k - $233k/yr
Responsibilities
- Conduct security assessments and threat models for first-party and third-party AI tools, agents, and AI-integrated systems.
- Design and validate guardrails and reusable patterns for safe agent behavior, tool and permission scoping, human-in-the-loop access, input and output controls, auditing, observability, MCP servers, integrations, trust boundaries, and AI data pipelines.
- Contribute to frameworks, tooling, paved paths, shared automation, and secure defaults for AI development and enterprise security.
- Harden enterprise IAM for service accounts, agent credentials, SaaS-to-SaaS OAuth, and SCIM federation using least-privilege and lifecycle-hygiene principles.
- Support SaaS security and posture management, third-party and integration security, data governance, endpoint security, and identity-centric controls.
- Lead cross-functional security initiatives and conduct security design and architecture reviews with IT, Engineering, Legal, Privacy, Procurement, and business stakeholders.
- Mentor engineers and partner-team members and support security incident response and post-incident analysis.
Requirements
- 6+ years of experience in security engineering, enterprise security, application security, cloud security, or a related field.
- Experience developing threat models and technical guardrails for AI tooling and agentic systems, including non-human identities and permission scoping.
- Deep expertise in authentication, authorization, SSO, OAuth/OIDC, SAML, federation, SCIM, API security, token handling, secrets management, least privilege, and SaaS security posture management.
- Strong experience evaluating risks and conducting security design and architecture reviews for enterprise applications, SaaS platforms, integrations, automation platforms, AI-connected workflows, and emerging patterns such as MCP.
- Strong experience securing modern cloud-native systems on AWS and/or GCP, with familiarity with audit logging, encryption, access control, data retention, and incident response.
- Ability to balance hands-on technical execution with mentoring, ownership, accountability, and measurable security improvements.
- Excellent written and verbal communication skills, including the ability to influence without authority and translate technical risk into actionable guidance.