At AdvanceWorks, we learn, grow, and have fun together. And we do all this while creating great software solutions for clients across many industries and geographies.
We are constantly challenging ourselves and each other to use the latest technologies and the best methodologies and make sure we walk the talk.
Exciting as it may sound, we also have our red lines: each of us is a unique person, with unique opinions, beliefs, options, interests, hopes, and fears. With the right to speak its mind, be mindful of the common goals, and always be constructive.
The way we respect each other, discuss different points of view, and challenge ourselves and each other while tackling our common challenges makes us strong. United. Brave. And sure that there will be a better tomorrow, even when we do mistakes. Because we learn from our failures and successes.
What will be your role
We are looking for an experienced AI Security Engineer to support the cybersecurity infrastructure of a client in the regulatory compliance sector, through the implementation of robust security controls, the deployment of innovative security solutions, and the investigation of security incidents. A key focus of this role is the security of AI/ML systems and pipelines, the assessment of risks introduced by large language models and generative AI tools, and the definition of security standards for AI adoption across the organization.
This role is critical to maintaining a strong security posture through meticulous incident analysis and effective mitigation strategies. Beyond the technical responsibilities, the position requires excellent collaboration and communication with multiple departments to align security policies and procedures with overall business objectives and compliance regulations. You will work closely with the AI, Application Engineering, and Cloud Platform teams to embed security throughout the entire software development lifecycle and across cloud infrastructure environments. The ideal candidate will provide guidance on secure design patterns, conduct comprehensive security reviews of application code, cloud architectures, and managed AI services, and support the responsible development, deployment, and operation of AI-powered features and products.
Key Responsibilities:
- Define, implement, and govern security standards, policies, and frameworks for AI/ML adoption across all business units.
- Act as the lead security partner for the Platform, Application Engineering, and Product teams, supporting the responsible development and deployment of AI-powered features.
- Foster a strong security culture by coordinating activities with Tech Leads, Engineering Managers, and the Security Champions network, providing guidance on secure design patterns for AI workloads.
- Architect and ensure the integration of advanced security controls, automated testing, and vulnerability management into CI/CD pipelines and into DevSecOps and MLSecOps workflows.
- Conduct comprehensive security architecture reviews and risk assessments focused on Large Language Models (LLMs) and Generative AI, mitigating risks such as prompt injection, data poisoning, and model supply chain vulnerabilities (OWASP LLM Top 10).
- Lead investigation, mitigation, and recovery efforts for complex security incidents, with a specialized focus on threats targeting AI infrastructure, inference endpoints, and managed cloud AI services (e.G., Azure OpenAI, AWS Bedrock).
- Monitor emerging cybersecurity trends, adversarial ML tactics, and global compliance regulations to proactively evolve the security infrastructure against future threat vectors.
Who will work by your side?
You will work as part of a team on a project and also with the AdvanceWorks team, a team of experts, and thus become part of a team of people who care about each other. Amazing people and professionals who are proud of their technology and leadership skills yet eager to learn from you and be challenged.
You'll also work side by side with our clients, spanning a wide range of industries and countries. And that means working with more bright minds, being empathetic about each other, and always keeping in mind that every brilliant piece of software we produce has two objectives: to achieve a specific business goal, and to make the people who built it as successful as you want to be.
What should you bring to the team?
- Bachelor's or advanced degree in Computer Science, Artificial Intelligence, Mathematics, or a related field, or professional cybersecurity certifications in lieu of a formal degree.
- At least 3 years of experience as a cybersecurity professional, with at least 1 year in AI/ML security, LLM security, or security for AI-driven systems.
- Application Security (AppSec) and Secure Software Development Lifecycle (SSDLC): familiarity with integrating security practices into CI/CD pipelines, code review processes, and DevSecOps/MLSecOps workflows.
- OWASP Top 10 and OWASP LLM Top 10: solid understanding of common web application vulnerabilities and their AI/LLM-specific equivalents (e.G., prompt injection, insecure output handling, model supply chain risks).
- AI/ML security: understanding of threat vectors specific to AI systems, including adversarial attacks, data poisoning, model inversion, and inference endpoint security.
- Networking knowledge (TCP/IP, LAN/WAN): solid understanding of network fundamentals, including TCP/IP protocols and the configuration and operation of Local Area Networks (LAN) and Wide Area Networks (WAN), and their security implications.
- Basic familiarity with the OSI (Open Systems Interconnection) model, including its seven layers and how they support network communications and cybersecurity practices.
- Security protocols, such as HTTPS, DNS, SMTP, FTP, and SSH.
- Firewalls (IDS/IPS): familiarity with the concepts and purposes of these tools.
- Understanding of information security principles such as confidentiality, integrity, and availability.
- Familiarity with operating systems, especially Windows, Linux or Unix, and MacOS.
- Knowledge and familiarity with incident investigation and response processes.
- Specific technical knowledge, such as programming languages (Python, PowerShell), and familiarity with API security testing and secure coding best practices across web application stacks.
- Knowledge of cloud security (AWS, Azure, GCP), including experience securing AI/ML workloads and managed AI services (e.G., Azure OpenAI, AWS Bedrock, GCP Vertex AI).
- Familiarity with concepts such as IAM (Identity and Access Management), encryption in transit and at rest, and shared responsibility models.
- Understanding of virtual machine and containerized environment security.
- Fluency in English. Knowledge of additional languages is an advantage.
- Creativity, dynamism, and the ability to work independently, yet transparently with colleagues, to thrive in a collaborative, international environment.
What is in it for you?
- Work with an international team;
- An amazing informal culture of smart hardworking and friendly people that support and care about each other;
- Be involved in strategic and operational initiatives beyond the scope of your main mission;
- Formal trainingand certifications in technology, methodology, and relational skills;
- Challenging projects with exciting clients and state-of-the‑art technology;
- A dynamiccompany where you can make a difference and where talent and results matter (and politics do not);
- Flexibility with responsibility;
- Happy hours andafter-hours feel‑good actions.