4 days ago
Jičín, CzechiaSenior
Responsibilities
- Shape the AI Platform’s security architecture and own substantial security components end to end.
- Design and build identity, authorization, delegated-access, and policy-enforcement controls for tenant, user, document, and tool permissions.
- Protect retrieval, tool use, and execution from prompt injection, unauthorized actions, data leakage, and other AI-specific threats.
- Implement risk-based approval gates, isolation, execution limits, and recovery mechanisms.
- Build audit and monitoring capabilities for traceability, detection, investigation, and review of high-risk activity.
- Conduct threat modeling and adversarial testing and translate findings into reusable platform controls and secure defaults.
- Collaborate with cloud platform, security, compliance, and product engineering teams to integrate practical controls.
Requirements
- At least 5 years of software engineering experience, including securing cloud, distributed, or platform services.
- Strong experience designing, building, and operating secure production systems in Python, TypeScript, or a similar language.
- Experience with authentication, authorization, policy enforcement, and multi-tenant isolation.
- Practical experience with threat modeling, application security testing, and implementing engineering controls from identified risks.
- Experience designing or building systems using LLMs, retrieval-augmented generation, or agents and understanding their security failure modes.
- Experience building reusable platform controls, APIs, or shared services for multiple engineering teams.
- Ability to balance security, usability, and operational complexity and recognize when stronger isolation or human approval is needed.
- Ability to communicate security decisions and tradeoffs across engineering, security, compliance, and product stakeholders.
- Undergraduate, Master’s degree, or PhD in Computer Science, Machine Learning, Data Science, Artificial Intelligence, or a related discipline.
- Preferred experience with multi-tenant enterprise SaaS platforms, permission-aware retrieval, tool-calling systems, workflow automation, adversarial AI testing, sandboxing untrusted files or code, MCP or similar protocols, and content-centric platforms.
Benefits
- Prague hybrid work or remote work within the Czech Republic.
- Opportunity to join an experienced engineering hub and collaborate internationally across multiple product teams.
- Opportunity to shape and grow the MLOps function as an internal expert.
- Career growth, rewards, recognition, and a culture of continuous improvement.
