Backblaze is seeking a Senior AI Security Engineer to design and implement safeguards for internal AI usage, with a focus on agentic systems, developer protection, and runtime security.
What You’ll Do
Agentic AI Safeguards
- Architect and implement guardrails for tool-using AI systems, including:
- Tool access controls and allowlists
- Context and memory isolation
- Step-level validation of agent actions
- Apply mitigations aligned to the OWASP Agentic AI Top 10 (e.g., prompt injection, unsafe tool use, data leakage, excessive autonomy).
Runtime Security Controls
- Build enforcement mechanisms that govern AI behavior at execution time:
- Interceptors, proxies, or middleware for tool/API calls
- Policy decision and enforcement layers
- Rate limits, execution bounds, and kill-switches
- Prevent unsafe or unauthorized actions initiated by AI systems.
Non-Human Identity (NHI)
- Design and implement identity and access controls for agents and automation, including:
- Short-lived credentials and scoped permissions
- Clear separation between human and non-human access
- Strong binding of identity to task context and execution
- Ensure all AI actions are attributable and auditable.
Observability & Detection
- Implement logging and tracing for AI activity:
- Prompts, tool usage, and decision flows
- Build detection capabilities using:
- Behavioral baselining and anomaly detection techniques
- Identify and alert on:
- Abnormal tool usage
- Suspicious prompt patterns
- Unexpected data access
Threat Modeling (MAESTRO)
- Perform agentic system threat modeling using MAESTRO, including:
- Mapping agent capabilities, trust boundaries, and attack paths
- Modeling misuse and adversarial scenarios
- Translate findings into practical safeguards and detection logic.
Developer Safeguards
- Protect developers using AI tools by:
- Preventing sensitive data exposure
- Validating AI-generated code and actions
- Constraining unsafe automation
- Enable safe usage of AI‑assisted development tools (e.g., Claude Code, Codex, Cursor) with:
- Security validation layers
- Controlled prompting and output handling patterns
The Right Fit
- 7+ years in security engineering or backend systems
- Proven experience designing and deploying security controls, such as:
- Runtime enforcement layers (proxies, middleware, policy engines)
- Identity and access systems, especially for non-human entities
- Strong programming skills (Python preferred; Go, Java, or TypeScript a plus)
- Experience using AI‑assisted development tools such as Claude Code in real workflows, including understanding associated security risks and safeguards
- Experience with:
- Logging, monitoring, and detection systems
- Building or securing API/service interactions
- Practical familiarity with:
- Agentic AI systems or tool-integrated LLM workflows
- OWASP guidance for AI/agent risks
Practitioner Knowledge
- Experience applying (not just referencing):
- OWASP Agentic AI / LLM risk guidance
- NIST AI RMF concepts in real systems
- CSA guidance on workload and machine identity
- Strong understanding of:
- Zero Trust for non-human identities
- Secrets management and credential scoping
- Observability tooling (e.g., OpenTelemetry, ELK)
Bonus Points For
- Experience securing internal AI platforms or developer‑facing AI tools
- Background in detection engineering, threat hunting, or adversarial testing
- Familiarity with agent frameworks (e.g., LangChain, LlamaIndex)
- Experience mentoring engineers and guiding secure design
We are proud to be an Equal Opportunity Employer.
We are committed to fostering a workforce where all employees feel a sense of belonging regardless of race, ethnicity, nationality, gender, sexual orientation, age, religion, socio-economic status, ability, veteran status, and education.