23 ago
|
Strategic Systems International
|
México
23 ago
Strategic Systems International
México
What You'll Need
Required:
- Strong SWE, with 5+ years of experience; proficiency in Python (or equivalent)
- 3+ years in AI/ML or GenAI security (prompt injection defense, unsafe output handling, tool-use abuse, data leakage), or equivalent hands-on infosec experience with a demonstrated pivot into AI security.
- Demonstrated ability to write security policy that is specific and testable, and to translate it into automated enforcement (policy-as-code, CI/CD gates, gateway-level controls, DLP rules) rather than a document that relies on voluntary compliance.
- A track record of self-directed learning on fast-moving technical topics — comfortable digging into how a brand-new tool, protocol, or framework actually works (architecture, trust boundaries, auth model) well enough to give a defensible security opinion on it within days, not months.
- Working knowledge of AI/LLM security risks: prompt injection, jailbreaking, unsafe outputs, tool-use abuse, identity misuse, agentic workflow escalation.
- Hands-on familiarity with AI security frameworks: NIST AI RMF, MITRE ATLAS, OWASP LLM Top 10 / OWASP Agentic Top 10.
- Experience with cloud security across at least two of AWS, GCP, and Azure, including native AI/ML security tooling (Bedrock Guardrails, Vertex AI floor settings, Azure AI Content Safety).
- Identity and access management fundamentals — OAuth 2.0/2.1, OIDC,
mTLS — with interest in or exposure to non-human/workload identity (SPIFFE/SPIRE) and agent identity models.
- Experience in a highly regulated industry (healthcare, financial services) with HIPAA or equivalent compliance obligations.
- Strong technical writing — you can turn a vendor capability gap or a new tool's risk profile into a control requirement someone else can implement and test.
Preferred:
- Direct experience with MCP (Model Context Protocol) or A2A protocol security, or with AI gateway products (Kong AI Gateway, Azure APIM GenAI Gateway, Apigee).
- Exposure to AI-native runtime security platforms (Straiker, Palo Alto Prisma AIRS, Virtue AI) or classic content guardrail products.
- Familiarity with shadow-AI / BYOAI risk — e.g., locally-run autonomous agent frameworks (OpenClaw and similar), unsanctioned browser extensions, personal AI accounts used for work — and how to discover and govern them at scale (CrowdStrike Falcon, Wiz, CASB, or similar).
- AI red-team tooling experience (PyRIT, Promptfoo, AgentDojo, or custom harnesses).
- Familiarity with Microsoft Purview DSPM for AI or equivalent DLP-for-AI tooling.
- Relevant certification (CAISP, ISACA AAISM) or equivalent demonstrated skill.
- Experience with detection engineering, SIEM integration, and telemetry design for AI/agent behavior.
📌 AI Security Engineer (AI & Agentic Security) (México)
🏢 Strategic Systems International
📍 México