Box

Senior Enterprise AI Security Engineer

Box
Apply
21 hours ago
Redwood City, CA, USASenior
H1B sponsor

Base Salary

$190k - $263k/yr

Responsibilities

  • Design, build, deploy, and maintain security systems for workforce AI tools and agents.
  • Architect and operate AI gateways, prompt and response logging, and egress controls.
  • Extend identity and access management to agentic and non-human identities, including credential lifecycle, delegation, OAuth grant review, and revocation.
  • Create approval paths for MCP servers and connectors, scoped tool permissions, and isolated execution for code-running agents.
  • Harden enterprise browser policies, extensions, AI-assisted developer tooling, and local agent runtimes.
  • Build policy engines, brokers, approval registries, and internal libraries to detect injected instructions, restriction bypasses, misuse, sensitive-data movement, and anomalous agent behavior.
  • Lead security architecture reviews and threat modeling for AI vendors, SaaS AI features, and internal agent deployments.
  • Define AI security standards, reference architectures, approved usage patterns, and reusable controls.
  • Partner with cross-functional teams to mature AI governance and response playbooks.
  • Automate security workflows through scripting, infrastructure-as-code, orchestration, and AI-assisted investigation tooling.
  • Provide design and code reviews, mentoring, and technical guidance.

Requirements

  • Bachelor’s or Master’s degree in computer science, information security, or a related field, or equivalent practical experience.
  • 6+ years of enterprise or corporate security engineering, security platform engineering, application or product security experience, including meaningful recent work with AI or agentic systems.
  • Hands-on experience securing enterprise assistants, internal agents, tool ecosystems, grounded search or RAG over company data, or AI coding tools.
  • Strong understanding of how AI systems are abused and how to analyze AI workflows for appropriate guardrails.
  • Strong identity and access management fundamentals.
  • Experience with security automation in Python, Go, or a similar language and with building tooling, libraries, or platform controls.
  • Fluency in shadow AI, agentic and non-human identity, SaaS-to-SaaS integration risk, browser security, and data-exfiltration paths.
  • Exceptional communication skills and the ability to explain AI risk and business impact.
  • Ability to work independently, manage ambiguity, and recommend secure, risk-profiled decisions.
  • Preferred experience shipping internal security platforms.
  • Preferred exposure to isolation and permissioning for autonomous workloads or AI red teaming and evaluation work.

Benefits

  • Healthcare benefits and other Box benefits and perks are provided.
  • Hybrid work arrangement requiring employees to work from their assigned office at least 3 days per week.

Tech Stack

Categories

Box

About Box

1,001-5,000 employees

Box builds a cloud content management platform for enterprises, combining secure file storage and sharing with collaboration, governance, e-signature, and workflow automation. It sells subscriptions (SaaS) to organizations that need to manage the lifecycle of business content and integrate with productivity apps. Founded in 2005 and headquartered in Redwood City, CA, Box is a public company (NYSE: BOX) used by customers such as JLL, Morgan Stanley, and Nationwide.

Contact me