
[EJV] Lead AI Safety & Security Engineer (with Joining Bonus)
Bosch Global6 hours ago
Ho Chi Minh City, VietnamStaff+
Responsibilities
- Design and run safety evaluations, red-team exercises, jailbreak tests, guardrail-bypass tests, and benchmarks for LLM features and AI agents.
- Conduct security testing for prompt injection, excessive agency, tool/plugin abuse, confused-deputy risks, data leakage, and MCP-style tool-calling architectures.
- Build and maintain threat models spanning user input, model reasoning, and tool execution.
- Verify the architectural soundness of human-in-the-loop controls and guardrails for consequential agent actions.
- Scope, brief, and review external red-team and penetration-testing engagements, including test specifications and acceptance criteria.
- Track OWASP, NIST AI RMF, ISO/IEC 42001, and EU AI Act developments and translate them into internal testing requirements.
- Partner with AI/ML engineering teams to incorporate safety and security into system design.
- Produce AI governance, compliance, risk-assessment, and responsible-AI documentation.
- Build adversarial-prompt harnesses, automated jailbreak/red-team pipelines, and MCP or tool-schema fuzzers.
- Mentor engineers and grow the AI safety and security testing practice across teams and products.
Requirements
- Bachelor’s or master’s degree in Computer Science, Machine Learning, or a related field.
- 6+ years of experience in security testing, AI/ML safety research, or a closely related discipline, with evidence of finding issues in real systems.
- Practical experience testing or red-teaming LLM or agentic AI systems, including prompt injection, jailbreaks, excessive agency, or tool/plugin abuse.
- Working knowledge of at least one AI safety or governance framework, such as NIST AI RMF, ISO/IEC 42001, or the EU AI Act.
- Coding ability in Python and/or JavaScript/Node for building evaluation harnesses and test tooling.
- Strong technical writing skills for producing actionable findings and specifications for engineering and governance stakeholders.
- Experience with Model Context Protocol or comparable agent tool-calling frameworks is preferred.
- Traditional web, API, or network penetration-testing experience and OSCP or equivalent certification are preferred.
- Experience with AI governance or compliance programs, security publications, CTF or red-team results, or open-source security tooling is preferred.
- Mentoring or experience building a safety or security testing team is preferred.
- Relevant certifications such as OSCP, OSWE, OSEP, GPEN, GWAPT, CEH, ISC2 AI Security Certificate, CAISP, ISO/IEC 42001 Lead Auditor or Lead Implementer, or IAPP AIGP are a plus.
Benefits
- Joining bonus equivalent to one month of gross salary for eligible employees joining by 31 December 2026, subject to program terms.
- 13th-month salary bonus, performance bonus, and annual performance appraisal.
- 100% salary and mandatory social insurance during the two-month probation period.
- More than 15 days of annual leave plus one birthday leave day.
- Premium health insurance for the employee and two family members.
- Flexible working time and working model.
- Lunch and parking allowance.
- English-speaking environment, global projects, training programs, and potential short- and long-term assignments at worldwide offices.
- Company activities including football, badminton, yoga, aerobics, and team building.
Tech Stack
Categories
About Bosch Global
Bosch Global (Robert Bosch GmbH) develops and sells mobility components and software, industrial automation and sensors, home appliances and power tools, and energy and building technologies to automakers, manufacturers, builders, and consumers. It monetizes through product sales and connected services spanning IoT, AI, and embedded software. Founded in 1886 and headquartered in Gerlingen-Schillerhöhe, Germany, the privately held Bosch Group operates worldwide across Mobility, Industrial Technology, Consumer Goods, and Energy and Building Technology sectors.