
Principal Software Engineer
DigitalOcean2 hours ago
Responsibilities
- Define how AI security controls are integrated into DigitalOcean’s customer-facing products.
- Build and deploy detection strategies, guardrails, security tooling, and automation with Security Data Science and Security Engineering.
- Implement and monitor online and batch inference endpoints for in-house AI/ML models, including drift detection and performance improvements.
- Lead AI red-team testing covering jailbreaks, prompt injection, evasion, poisoning, and model extraction.
- Lead security reviews and provide architectural sign-off and escalation guidance for major AI product initiatives.
- Threat model the full AI lifecycle, including data ingestion, training, fine-tuning, evaluation, serving, RAG, agent frameworks, and monitoring.
- Own the AI security strategy, multi-year roadmap, and AI Risk & Governance framework.
- Represent AI security in executive and board-level briefings and define positions on emerging AI security topics.
Requirements
- 15+ years of cybersecurity experience, including at least 4–5 years in AI/ML security, adversarial machine learning, or security data science in a production cloud or technology environment.
- Organizational experience defining and driving AI or security programs and owning strategy and roadmaps.
- Practitioner-level expertise in adversarial ML attacks and defenses, including evasion, poisoning, model extraction, membership inference, and prompt injection.
- Ability to evaluate AI security research and translate it into engineering guidance and organizational policy.
- Experience communicating technical risk to executives and senior leadership in business terms.
- Strong programming skills in Python and Go, including building security tooling and automation.
- Experience reviewing AI/ML architectures covering data ingestion, feature engineering, training pipelines, model serving, and continuous monitoring.
- Hands-on experience with AI red-team, defensive, and model supply-chain tooling.
- Bachelor’s or Master’s degree in Computer Science, Information Security, Mathematics, or a related field, or equivalent depth of practical experience.
- Fluency in OWASP LLM Top 10, MITRE ATLAS, NIST AI RMF, ISO/IEC 42001, and the EU AI Act.
- Experience with a cloud provider, security product company, or large-scale internet platform operating AI/ML systems at customer-facing scale.
- Familiarity with production LLM security, including securing RAG pipelines, agentic frameworks, and model APIs against prompt injection, jailbreaking, and data exfiltration.
Benefits
- Reimbursement for relevant conferences, training, and education.
- Access to LinkedIn Learning’s 10,000+ courses.
- Employee Assistance Program, local employee meetups, and flexible time off.
- Bonus eligibility, equity compensation, equity grants upon hire, and an Employee Stock Purchase Program.
- Located in Bengaluru, India, with a hybrid work arrangement.
About DigitalOcean
DigitalOcean is the AI-Native Cloud purpose-built for the inference and agentic era. Its five-layer integrated platform—spanning GPU and CPU infrastructure, core cloud, inference, data, and managed agent orchestration—is open throughout with no vendor lock-in, giving builders everything they need to start fast, scale production AI workloads, and improve unit economics. More than 650,000 customers and millions of developers globally trust DigitalOcean to build, ship, and scale their applications.