
AI Security Engineer - Taiwan
Obsidian SecurityResponsibilities
- Research how enterprise AI platforms and agentic frameworks authenticate, access data, request permissions, and interact with corporate SaaS applications.
- Research emerging AI security threats and develop threat models covering applications, agents, models, integrations, identities, permissions, tools, and data flows.
- Design data models for AI assets, identities, access relationships, permissions, activities, risks, and attack paths.
- Build production-grade AI security products, backend services, APIs, detection capabilities, and remediation features.
- Build scalable pipelines that ingest, normalize, enrich, correlate, and analyze high-volume security telemetry.
- Write queries and analysis logic that convert activity and configuration data into actionable security findings.
- Develop detection rules and behavioral models for suspicious AI and agentic activity.
- Evaluate AI platform APIs, audit logs, authentication mechanisms, OAuth permissions, and security controls.
- Work with product teams and customers to turn ambiguous security problems into practical product capabilities.
- Partner with Security Research, Detection Engineering, platform, and SRE teams to validate threats and improve detection coverage.
- Contribute to technical designs, code reviews, testing strategies, operational readiness, engineering standards, and long-term AI security strategy.
- Improve engineering productivity, pipeline performance, development velocity, and cloud cost efficiency.
Requirements
- Strong software engineering experience building production-quality backend services, cloud-native applications, data platforms, or security products.
- Hands-on programming experience in Python, Go, Java, Kotlin, or a comparable backend language.
- Experience designing and building scalable APIs, distributed systems, or data-processing pipelines.
- Strong data analysis skills using SQL or other query languages to investigate complex behavior.
- Familiarity with cloud infrastructure, SaaS platforms, identity systems, authentication, authorization, and OAuth.
- Understanding of security fundamentals including identities, permissions, access controls, vulnerabilities, attack techniques, and risk assessment.
- Ability to translate ambiguous security risks into threat models, data requirements, and production capabilities.
- Strong engineering judgment across scalability, reliability, security, performance, maintainability, and cost.
- Experience or interest in rapidly learning unfamiliar AI platforms, APIs, security models, and attack techniques.
- Ability to work independently and collaborate with security researchers, product managers, and engineers.
- Strong written and verbal communication skills in English.
- Preferred experience with cybersecurity, identity security, SaaS security, threat detection, SIEM, EDR, XDR, or security analytics products.
- Preferred experience researching or protecting AI applications, large language models, copilots, autonomous agents, LLM application frameworks, agent protocols, tool integrations, vector databases, or retrieval-augmented generation systems.
- Preferred experience with SaaS audit logs, identity telemetry, OAuth grants, application configurations, security events, detection rules, behavioral analytics, risk models, or attack-path analysis.
- Preferred experience with large-scale streaming or batch-processing technologies, machine learning, or generative AI for security analysis or investigation automation.
- Security research, open-source, technical publication, vulnerability disclosure, globally distributed-team, or Mandarin experience is a plus.
Benefits
- The role is based in Taiwan and involves collaboration with teams in Taiwan, the US, the UK, and Australia.
- Opportunity to work on emerging AI and agentic security problems and help shape the company’s long-term AI security strategy.
About Obsidian Security
Every enterprise runs on software it doesn't own: third-party apps, AI copilots, and agents logging in with OAuth tokens nobody's reviewing. Obsidian Security secures all of it, discovering every third-party app and AI feature connected to your business, governing risky permissions, and detecting threats in real time. Trusted by the world's most regulated, highest-scale enterprises. If you're adopting AI, you're adopting third-party software faster than ever we make sure that doesn't mean adopting its risk. SPECIALTIES AI Security Posture Management, AI Security, SaaS Security Posture Management, Identity Threat Detection & Response, AI & Agentic Security, Continuous Governance, OAuth & API Risk, Supply Chain Integration Risk, App-to-App Security Subscribe to our newsletter: https://www.linkedin.com/newsletters/true-positives-7435782529825038336/ Get a demo: https://www.obsidiansecurity.com/get-a-demo Sign up for a trial: https://www.obsidiansecurity.com/trial