
Senior Security Engineer, AI/ML
Qualys, Inc.1 hour ago
Foster City, CA, USASenior
Base Salary
$115k - $140k/yr
Responsibilities
- Build and deploy GenAI applications with LangChain, LlamaIndex, or similar frameworks.
- Orchestrate multi-agent and autonomous AI workflows using tools such as AutoGen, CrewAI, or custom architectures.
- Design, train, evaluate, and deploy classical ML and deep learning models through end-to-end data and ML pipelines.
- Implement secure RAG pipelines using embeddings and vector databases such as FAISS, Pinecone, and Qdrant.
- Write Python backend APIs for model serving, data processing, and cloud integration, and monitor production model performance.
- Research vulnerabilities in LLMs and AI systems, including prompt injection, jailbreaks, data leakage, model theft, and adversarial attacks.
- Conduct offensive security assessments and red teaming against GenAI and ML-powered systems.
- Identify threat vectors targeting model inference, training pipelines, and model-serving architectures.
- Build internal tooling for scanning, fuzzing, and automating LLM vulnerability discovery.
- Develop proof-of-concepts, technical whitepapers, and blog posts; monitor AI security threat intelligence and research.
- Define secure AI hardening strategies, represent the company in security and AI research communities, and mentor engineers.
Requirements
- 6+ years of combined experience in software engineering or machine learning and security research, penetration testing, or exploit development, focused on application or cloud security.
- Strong Python programming skills, including backend APIs, scripting, automation, testing, and proof-of-concept development.
- Experience training ML models with Scikit-learn, TensorFlow, or PyTorch.
- Strong knowledge of LLM architectures, transformers, embeddings, fine-tuning, and RAG.
- Hands-on experience with LangChain, LlamaIndex, or other GenAI frameworks and multi-agent or autonomous AI workflows.
- Familiarity with GenAI risks including prompt injection, model evasion, hallucination-based exploits, data leakage, and model theft.
- Experience with LLM deployment scenarios involving OpenAI, HuggingFace, or custom-hosted models.
- Ability to analyze logs, API interactions, inference responses, and prompt chains for anomalous or risky behavior.
- Working knowledge of SQL, Pandas, and large-scale data processing, plus experience deploying ML systems in Agile environments.
- Strong analytical and technical writing skills and familiarity with responsible disclosure, bug bounty programs, or security research ethics.
- Preferred: AI/ML security red teaming or adversarial ML experience; knowledge of vector database risks, insecure RAG, model fingerprinting, and AI supply chain attacks.
- Preferred: experience with AutoGen, CrewAI, MetaGPT, Guardrails.ai, LLM Guard, or Tracer.
- Preferred: familiarity with GPT-4, Claude, Mistral, LLaMA, or Falcon and API integrations.
- Preferred: AWS, GCP, Azure, containerized deployments, MLOps monitoring and retraining, and CI/CD automation.
- Preferred: Secure SDLC, threat modeling frameworks such as STRIDE and MITRE ATLAS, AI security checklists, and relevant conference publications or presentations.
Benefits
- Comprehensive benefits package including healthcare and retirement plans.
- Access to mentorship, certifications, broad resources, and exposure to cutting-edge research.
- Collaborative virtual work environment with pairing and knowledge sharing.
- Inclusive culture focused on diverse perspectives, professional growth, and continuous improvement.