Design and implement security controls throughout AI/ML and MLOps pipelines, including data ingestion, model development, validation, storage, deployment, and inference.
Assess security risks associated with machine learning models, LLM applications, AI agents, datasets, prompts, and AI-enabled applications.
Evaluate the security of AI coding assistants, coding agents, autonomous agents, and agentic workflows used within software engineering organizations.
Establish security guardrails for AI-assisted development platforms, agent orchestration frameworks, and autonomous development pipelines.
Help develop an enterprise framework for securing the Agentic Development Lifecycle (ADLC), incorporating threat modeling, secure development requirements, testing, deployment controls, approvals, and continuous monitoring.
Evaluate AI Security Posture Management (AI-SPM) capabilities and establish processes for discovering, classifying, prioritizing, and remediating AI-related security risks.
Assess emerging attacks against LLMs, frontier AI models, and autonomous agents and translate those risks into preventative and detective security controls.
Develop and maintain automation and security capabilities using Python and CI/CD technologies.
Integrate model and AI security scanning into development pipelines as part of a shift-left security strategy.
Analyze model-scanning and vulnerability-assessment results and partner with engineering teams on remediation.
Assess model inference and deployment architectures with consideration for security, performance, scalability, and resource utilization.
Evaluate security surrounding agent sandboxes, runtime environments, tool access, permissions, agent-to-tool communication, and execution workflows.
Establish controls governing autonomous agent behavior, including permissions, approval mechanisms, runtime restrictions, secrets management, and data-access boundaries.
Partner closely with application security, platform engineering, software development, data science, and machine learning teams.
Research emerging AI security threats and recommend improvements to enterprise security architecture and engineering practices.
8+ years of experience across software engineering, cybersecurity, application security, platform engineering, or related technical disciplines.
5+ years of hands-on software engineering or development experience.
Strong understanding of AI/ML security, GenAI security, and agentic AI risks.
Hands-on experience building or supporting MLOps pipelines and model deployment environments.
Experience with platforms such as MLflow, Kubeflow, AWS SageMaker, or comparable MLOps technologies.
Strong Python programming and automation skills.
Strong understanding of modern CI/CD pipelines and secure software-development practices.
Experience incorporating security testing or scanning into automated development pipelines.
Hands-on familiarity with AI-assisted development tools such as GitHub Copilot, Claude Code, Cursor, Windsurf, Microsoft Copilot, or similar platforms.
Experience using AI-assisted engineering techniques across one or more languages such as Python, Java, JavaScript, C#, .NET, or Go.
Strong understanding of LLMs, AI agents, autonomous workflows, RAG architectures, tool-calling systems, and agent orchestration.
Experience assessing the security implications of agent runtime environments, sandboxing, tool permissions, and autonomous execution.
Ability to assess and prioritize risks involving AI models, prompts, datasets, agents, and AI-enabled applications.
Strong understanding of AI/ML attack vectors, including:
Prompt injection
Data and model poisoning
Model extraction and inversion
Adversarial inputs and examples
AI/ML supply-chain vulnerabilities
Excessive agent permissions and unsafe tool usage
Sensitive-data exposure
Familiarity with industry guidance such as the OWASP security frameworks for LLM and machine-learning applications.
Experience with model vulnerability scanning, model security assessment, or similar AI security tooling.
Understanding of common ML model and serialization formats such as Pickle, TensorFlow formats, and SafeTensors.
Familiarity with both structured and unstructured data environments, including SQL databases, data warehouses, object storage, and NoSQL platforms.
Understanding of cloud, container, microservices, and application security principles.
Excellent analytical and problem-solving skills.