Obsidian Security

AI Security Engineer - Taiwan

Obsidian Security
Apply
3 hours ago
Taipei, TaiwanSenior
H1B Sponsor

Responsibilities

  • Research how enterprise AI platforms and agentic frameworks authenticate, access data, request permissions, and interact with corporate SaaS applications.
  • Research emerging AI security threats and develop threat models covering applications, agents, models, integrations, identities, permissions, tools, and data flows.
  • Design data models for AI assets, identities, access relationships, permissions, activities, risks, and attack paths.
  • Build production-grade AI security products, backend services, APIs, detection capabilities, and remediation features.
  • Build scalable pipelines that ingest, normalize, enrich, correlate, and analyze high-volume security telemetry.
  • Write queries and analysis logic that convert activity and configuration data into actionable security findings.
  • Develop detection rules and behavioral models for suspicious AI and agentic activity.
  • Evaluate AI platform APIs, audit logs, authentication mechanisms, OAuth permissions, and security controls.
  • Work with product teams and customers to turn ambiguous security problems into practical product capabilities.
  • Partner with Security Research, Detection Engineering, platform, and SRE teams to validate threats and improve detection coverage.
  • Contribute to technical designs, code reviews, testing strategies, operational readiness, engineering standards, and long-term AI security strategy.
  • Improve engineering productivity, pipeline performance, development velocity, and cloud cost efficiency.

Requirements

  • Strong software engineering experience building production-quality backend services, cloud-native applications, data platforms, or security products.
  • Hands-on programming experience in Python, Go, Java, Kotlin, or a comparable backend language.
  • Experience designing and building scalable APIs, distributed systems, or data-processing pipelines.
  • Strong data analysis skills using SQL or other query languages to investigate complex behavior.
  • Familiarity with cloud infrastructure, SaaS platforms, identity systems, authentication, authorization, and OAuth.
  • Understanding of security fundamentals including identities, permissions, access controls, vulnerabilities, attack techniques, and risk assessment.
  • Ability to translate ambiguous security risks into threat models, data requirements, and production capabilities.
  • Strong engineering judgment across scalability, reliability, security, performance, maintainability, and cost.
  • Experience or interest in rapidly learning unfamiliar AI platforms, APIs, security models, and attack techniques.
  • Ability to work independently and collaborate with security researchers, product managers, and engineers.
  • Strong written and verbal communication skills in English.
  • Preferred experience with cybersecurity, identity security, SaaS security, threat detection, SIEM, EDR, XDR, or security analytics products.
  • Preferred experience researching or protecting AI applications, large language models, copilots, autonomous agents, LLM application frameworks, agent protocols, tool integrations, vector databases, or retrieval-augmented generation systems.
  • Preferred experience with SaaS audit logs, identity telemetry, OAuth grants, application configurations, security events, detection rules, behavioral analytics, risk models, or attack-path analysis.
  • Preferred experience with large-scale streaming or batch-processing technologies, machine learning, or generative AI for security analysis or investigation automation.
  • Security research, open-source, technical publication, vulnerability disclosure, globally distributed-team, or Mandarin experience is a plus.

Benefits

  • The role is based in Taiwan and involves collaboration with teams in Taiwan, the US, the UK, and Australia.
  • Opportunity to work on emerging AI and agentic security problems and help shape the company’s long-term AI security strategy.
Obsidian Security

About Obsidian Security

51-200 employees

Every enterprise runs on software it doesn't own: third-party apps, AI copilots, and agents logging in with OAuth tokens nobody's reviewing. Obsidian Security secures all of it, discovering every third-party app and AI feature connected to your business, governing risky permissions, and detecting threats in real time. Trusted by the world's most regulated, highest-scale enterprises. If you're adopting AI, you're adopting third-party software faster than ever we make sure that doesn't mean adopting its risk. SPECIALTIES AI Security Posture Management, AI Security, SaaS Security Posture Management, Identity Threat Detection & Response, AI & Agentic Security, Continuous Governance, OAuth & API Risk, Supply Chain Integration Risk, App-to-App Security Subscribe to our newsletter: https://www.linkedin.com/newsletters/true-positives-7435782529825038336/ Get a demo: https://www.obsidiansecurity.com/get-a-demo Sign up for a trial: https://www.obsidiansecurity.com/trial

Contact me