Summary
Applied Systems is an insurtech company developing software and services for the insurance industry. The Security Engineer, AI will help build and operate the company’s AI security program by securing large language models, generative AI systems, ML infrastructure, and related data pipelines. The role includes threat modeling, implementing security controls, addressing AI-specific vulnerabilities, and developing security policies and incident response practices.
Responsibilities
- Evaluate and assess the security posture of Large Language Models (LLMs) and generative AI systems used within or by Applied Systems
- Conduct threat modeling and security architecture reviews for AI/ML systems and their data pipelines
- Implement and maintain security controls for AI model training, fine-tuning, and inference infrastructure
- Develop and maintain security baselines and hardening configurations for AI platforms and frameworks
- Identify and help remediate security vulnerabilities specific to AI/ML systems (prompt injection, model poisoning, data exfiltration, adversarial attacks)
- Implement data security and privacy controls for AI training datasets and inference inputs
- Develop and maintain security runbooks for AI systems incident response
- Participate in security reviews of AI/ML applications and vendor AI services
- Contribute to the development of internal AI security policies and guidelines
- Assist with proof-of-concept builds for AI security solutions and controls
- Stay current with emerging AI security threats, research, and industry best practices
- Contribute to internal security training related to AI risks and secure AI development
Skills
- Minimum of 3-5 years' experience in security engineering or DevSecOps roles
- Demonstrated foundational understanding of machine learning concepts, ML workflows, and common frameworks (PyTorch, TensorFlow, scikit-learn)
- Working knowledge of Large Language Models, transformer architectures, and generative AI applications
- Experience with or strong understanding of LLM security concerns (prompt injection, jailbreaking, data poisoning, model extraction)
- Experience with container security, Kubernetes security, and securing AI workloads in containers
- Knowledge of cloud security in AI contexts (GPU security, distributed training security, data protection in ML pipelines)
- Understanding of secure software development practices and supply chain security as applied to ML models
- Knowledge of model governance, versioning, and secure model deployment
- Experience with infrastructure-as-code technologies (Terraform, Ansible)
- Experience with one or more scripting languages (Python, Bash, Go)
- Understanding of encryption, key management, and data privacy (especially PII in training data)
- Familiarity with vulnerability scanning and secure code practices
- Working knowledge of compliance frameworks and their application to AI systems (GDPR, SOC 2, etc.)
- Experience with securing data pipelines and ETL processes
- Excellent written and verbal communication skills
- Demonstrated ability to work independently and as part of a team
- Willingness to rapidly learn new AI technologies and security frameworks
- Certification in security (Security+, CISSP, etc.)
- Experience with specific LLM platforms (OpenAI API, Anthropic Claude, Google Vertex AI, Azure OpenAI)
- Experience with ML security tools and platforms (Robust Intelligence, Arthur AI, etc.)
- Participation in AI security research, publications, or conferences
- Experience in threat modeling for AI systems
- Background in security research or penetration testing
- Experience with red-teaming AI systems
Qualifications
Must Haves
- Minimum of 3-5 years' experience in security engineering or DevSecOps roles
- Demonstrated foundational understanding of machine learning concepts, ML workflows, and common frameworks (PyTorch, TensorFlow, scikit-learn)
- Working knowledge of Large Language Models, transformer architectures, and generative AI applications
- Experience with or strong understanding of LLM security concerns (prompt injection, jailbreaking, data poisoning, model extraction)
- Experience with container security, Kubernetes security, and securing AI workloads in containers
- Knowledge of cloud security in AI contexts (GPU security, distributed training security, data protection in ML pipelines)
- Understanding of secure software development practices and supply chain security as applied to ML models
- Knowledge of model governance, versioning, and secure model deployment
- Experience with infrastructure-as-code technologies (Terraform, Ansible)
- Experience with one or more scripting languages (Python, Bash, Go)
- Understanding of encryption, key management, and data privacy (especially PII in training data)
- Familiarity with vulnerability scanning and secure code practices
- Working knowledge of compliance frameworks and their application to AI systems (GDPR, SOC 2, etc.)
- Experience with securing data pipelines and ETL processes
- Excellent written and verbal communication skills
- Demonstrated ability to work independently and as part of a team
- Willingness to rapidly learn new AI technologies and security frameworks
Nice to Haves
- Certification in security (Security+, CISSP, etc.)
- Experience with specific LLM platforms (OpenAI API, Anthropic Claude, Google Vertex AI, Azure OpenAI)
- Experience with ML security tools and platforms (Robust Intelligence, Arthur AI, etc.)
- Participation in AI security research, publications, or conferences
- Experience in threat modeling for AI systems
- Background in security research or penetration testing
- Experience with red-teaming AI systems
Benefits
- Ability to work 100% remotely
- Medical, Dental, and Vision Coverage
- Holiday and Vacation Time
- Health & Wellness Days
- A Bonus Day for Your Birthday
- Depending on the role, team members may also be eligible to participate in additional compensation plans such as bonus and commission.