5 hours ago
Bengaluru, IndiaMid Level
Responsibilities
- Adversarially test AI agents and workflows for prompt injection, context poisoning, unsafe tool use, data leakage, unauthorized access, and unintended behavior.
- Threat-model AI features, agent workflows, model integrations, tool calling, customer-facing applications, and security-sensitive architecture changes.
- Build automated adversarial evaluations, security regression tests, test harnesses, monitoring, and reusable platform guardrails.
- Implement least-privilege access, scoped credentials, sandboxing, runtime policy enforcement, human approval, output validation, containment, and kill switches.
- Review and secure applications, APIs, file uploads, webhooks, exports, third-party integrations, authentication, authorization, tenant isolation, and data handling.
- Harden cloud permissions, service identities, secrets, storage, networking, deployment pipelines, and production access.
- Improve model-provider routing, retries, timeouts, fallbacks, quotas, rate limits, cost controls, and observability.
- Reproduce vulnerabilities, assess real-world impact, implement production-ready fixes, support debugging, and investigate application, infrastructure, and AI-security incidents.
Requirements
- 2–3 years of hands-on experience across AI engineering, backend or platform engineering, application security, infrastructure security, DevSecOps, or a related engineering role.
- Experience building, operating, or securing production AI systems using LLM APIs, agents, tool calling, RAG, model gateways, or similar technologies.
- Strong programming ability in Python, TypeScript, Go, or another relevant language.
- Understanding of authentication, authorization, injection, tenant isolation, secrets, unsafe data handling, and common web and API security risks.
- Practical experience with cloud infrastructure, CI/CD, containers, monitoring, or infrastructure-as-code.
- Ability to investigate, reproduce, assess, and remediate suspected vulnerabilities using source code, logs, traces, metrics, and database queries.
- Ability to reason about trust boundaries among users, models, customer data, application code, tools, and third-party services.
- Hands-on AI red teaming, adversarial model testing, prompt-injection defense, agent sandboxing, multi-tenant SaaS security, security test harnesses, fuzzers, SAST, DAST, dependency scanning, secret scanning, infrastructure scanning, model gateways, AI observability, LLM evaluations, bug bounties, CTFs, security research, or relevant open-source experience are preferred.
- Familiarity with OAuth, webhooks, file processing, MCP, third-party integrations, SOC 2, or ISO 27001 from an engineering implementation perspective is preferred.
Tech Stack
Categories
About Metaforms
Metaforms builds an AI‑agent research operations platform that speeds up survey design, programming, testing, data cleaning/coding, tabulation, and reporting for market research agencies and in‑house insights teams. It sells a SaaS workflow that plugs into tools such as Qualtrics, Confirmit, Decipher, and Dimensions. Founded in 2023 and headquartered in New York, the company is privately held.
