Veeam logo
VeeamPosted 1 week ago

Staff AI Security Engineer

$293,100–$544,200 year

On-siteSan Jose, California, United States

Full TimeSenior LevelLargeData Protection

Job Summary

Design and ship data-handling controls, code filters, and infrastructure guardrails for internal AI tooling and product features, redacting sensitive data from prompts, logs, and outputs before reaching third-party providers. Build and productionize an AI-enhanced vulnerability reduction capability integrated into CI/CD to surface defects with low false positives, while publishing self-serve secure-LLM-use patterns for engineering teams. Threat-model internal tools for prompt injection, indirect attacks, and model exfiltration, partnering with red teams to build fixes and audit evidence for compliance frameworks. Set direction on emerging LLM security tools and workflows, adopting or building in-house solutions based on risk and utility.

Required Qualifications

  • 10+ years across security and engineering, with recent focus on AI/ML systems in production (LLM deployments, model risk, or AI-driven security tooling)
  • Hands-on experience shipping controls (Code, infra or data gaurdrails) that operate on LLM inputs and outputs (redaction, filtering, output validation, prompt-injection defense)
  • Build and tune detection systems that catch PII and secrets (API keys, credentials, personal data) across large, messy datasets, knowing when a regex rule is good enough, when you need a trained classifier, and when only an LLM can catch it, and justifying that choice on cost, latency, and accuracy grounds
  • Track record of taking AI/security work from concept to production, including designing for developer trust and false-positive management
  • Strong cloud security fundamentals across Azure and AWS: RBAC, secret management, key handling, network egress controls
  • Turn ad-hoc 'is this LLM use case safe?' questions into a reusable mechanism (a scoring rubric in PR templates, a lint rule, an approval gate) that teams run themselves, instead of a doc they read once or a person they ping
  • Comfort building and hardening security tooling in Python and Go
  • Familiarity with regulated-industry evidentiary expectations (SOC 2 Type 2, ISO 27001, FedRAMP, HITRUST) and how AI-generated evidence intersects with them
  • Hands-on experience with agentic AI development environments (Claude Code, Cursor, GitHub Copilot Enterprise) and their operational security implications
  • A demonstrable track record of shipping production code (a code portfolio, open-source contributions, or internal build history). This is a hands-on building role, not an advisory one

Desired Qualifications

  • Familiarity with LLM attack techniques (prompt injection, indirect prompt attacks, tool-boundary abuse, model exfiltration) enough to threat-model and build defenses
  • Background in traditional AppSec or SAST that translates cleanly to LLM-augmented vulnerability finding
  • Contributions to open-source LLM safety or evaluation projects (Presidio, PromptFoo, Garak, etc.)
  • Prior work with Azure OpenAI Service enterprise data-handling controls and LLM governance patterns
  • Experience integrating security tooling into developer workflows without becoming a merge-blocking bottleneck

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce