We are seeking a Senior AI Security Engineer to join the AI Foundation team and secure Enterprise AI and Scientific AI workloads across Azure and GCP platforms. This is an implementation-focused role where you will translate AI Security Framework controls into working platform configurations, engineering security as code through Terraform, GitOps CI/CD security gates, and policy-as-code that continuously attests to compliance. You will collaborate closely with Senior AI Security auditors and AI Engineers in a high-talent-density domain, ensuring implementations consistently pass governance requirements.
Responsibilities
- Translate AI Security control descriptions into working platform configurations and defensible implementations
- Engineer security controls as code using Terraform, GitOps CI/CD pipelines, and policy-as-code frameworks
- Produce machine-verifiable evidence that proves adherence to control descriptions
- Implement Kubernetes GPU node pool segmentation, VNet/VPC isolation, and private endpoints across Azure and GCP
- Configure RBAC/ABAC least-privilege access, managed/workload identity, and risk-based access controls
- Build a hardened API integration layer and centralized gateway with tool-level access controls
- Deploy LLM guardrails for prompt/response injection, content filtering, kill-switches, and inference rate limits
- Set up observability pipelines for anomaly and drift detection, restricted-access logs, and end-to-end traceability
- Maintain training-data and model isolation to support robustness and prevent model theft
- Collaborate with Senior AI Security auditors and AI Engineers to ensure implementations pass governance consistently
- Support classification and compliance efforts aligned with ISO 27001, EU AI Act, and GDPR requirements
Requirements
- 5+ years of experience in SDLC foundations and cloud platform engineering with an AI/ML focus
- Security-first mindset with the ability to translate control intent into defensible implementations alongside senior specialists
- Hands-on experience with Azure, GCP, and Kubernetes (AKS/GKE) including GPU node pools and VNet/VPC segmentation
- Expertise in Terraform, GitOps workflows, and policy-as-code within CI/CD pipelines (Azure DevOps/GitHub Actions)
- Knowledge of IAM concepts including RBAC/ABAC least-privilege, managed/workload identity, and geo-aware risk-based access controls
- Familiarity with hardened API integration layers, centralized MCP gateways, and LLM guardrails for prompt/response injection and content filtering
- Proficiency in observability tools such as OpenTelemetry, Prometheus, Loki, Tempo, and Grafana for anomaly and drift detection
- Understanding of data classification, training-data/model isolation, and model-theft prevention practices
- Background in compliance frameworks including ISO 27001, EU AI Act, and GDPR
- English proficiency at B2 level or higher