Sr. AI Security Engineer

WideNet Consulting Group

Seattle (WA)

Hybrid

USD 117,000 - 131,000

Full time

4 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health & Medical Benefits
401K
Employee Assistance Program
Sick Time

Job summary

WideNet Consulting Group in Seattle seeks an experienced security engineer to design, implement, and operate AI security controls for foundation model usage across major platforms. You will drive zero-trust integration, guardrails, and centralized AI control plane governance, partnering with engineering teams to reduce AI risk.

The role emphasizes Azure security, Python tooling, and collaboration with data teams to ensure secure AI deployments. Onsite 2-3 days; PST remote options may apply.

Qualifications

  • 7+ years in security engineering with production AI/ML security experience
  • Hands-on experience deploying or operating an AI gateway or centralized AI control plane
  • Understanding of LLM attack surfaces: prompt injection and data leakage
  • Familiarity with OWASP Top 10 for LLM Applications, MITRE ATLAS, and NIST AI RMF
  • Strong Azure-focused security background including identity, network, and workload controls
  • Python proficiency and experience with model APIs and SDKs
  • Experience advising engineering and data teams rather than gatekeeping

Responsibilities

  • Design, implement, and operate security controls for foundation model usage across Claude, ChatGPT, and Copilot
  • Deploy and harden the enterprise AI gateway, including allowlists, keys, rate limits, and audit logging
  • Create guardrails for prompts, data egress, and secret leakage
  • Integrate inline DLP and content inspection for AI traffic
  • Define governance for MCP servers and agent tooling with runtime policy enforcement
  • Extend zero trust controls to AI workloads across identity, device, network, and data pillars
  • Collaborate with identity engineering on access, workload identity, and privileged AI system access
  • Map controls to OWASP Top 10 for LLM Apps, MITRE ATLAS, and NIST RMF

Skills

Security engineering
AI security
Azure security
Python
OAuth & identity
Threat modeling
Cloud security

Tools

AI gateway
LLM proxy
Purview/Defender tools

Job description

Job Description:

Location: This position requires the candidate to work onsite 2-3 days a week in Seattle, WA. Potential opening for remote candidates in PST.

This position will support AI workloads across our client and reduce AI risk through stronger infrastructure hygiene, in partnership with zero trust engineering.

Responsibilities
AI workload protection:
  • Design, implement, and operate security controls for foundation model usage across Claude, ChatGPT, and Microsoft Copilot
  • Support deployment and hardening of the enterprise AI gateway, including model allowlists, per-team keys, rate and budget limits, and centralized audit logging
  • Engineer input and output guardrails covering prompt injection, sensitive data egress, credential and secret leakage, and unsafe output
  • Integrate inline DLP and content inspection at the gateway so AI traffic is subject to the same data controls as other egress paths
  • Establish security requirements for RAG architectures, including source grounding, index access control, and prevention of oversharing through model responses
Agentic and MCP security:
  • Define and enforce governance for MCP servers and agent tooling, including registry, approval, and runtime policy enforcement
  • Implement identity and authorization patterns for agents and other non-human identities: OAuth-based access, token lifecycle management, scoped tool permissions, and least privilege
  • Assess and mitigate agentic risk classes including excessive agency, capability chaining, tool and memory poisoning, and unsafe autonomous action
Zero trust integration:
  • Extend zero trust controls to AI workloads across identity, device, network, application, and data pillars
  • Partner with identity engineering on conditional access, workload identity, and privileged access for AI systems and service principals
  • Reduce AI risk through infrastructure hygiene: configuration baselines, egress control, secrets management, and dependency and supply chain integrity
Governance:
  • Map controls to recognized frameworks including the OWASP Top 10 for LLM Applications, MITRE ATLAS, and the NIST AI Risk Management Framework
  • Contribute to AI security standards, acceptable use guidance, architecture review criteria, and enablement material for engineering teams
Required Qualifications
  • 7+ years in security engineering, with 2+ years securing AI, ML, or generative AI systems in production
  • Hands‑on experience deploying or operating an AI gateway, LLM proxy, or equivalent centralized AI control plane
  • Demonstrated understanding of LLM and agent attack surface: prompt injection, data leakage through model output, insecure tool use, supply chain risk in models and dependencies
  • Practical familiarity with OWASP Top 10 for LLM Applications, MITRE ATLAS, and NIST AI RMF
  • Strong cloud security background, Azure preferred, including identity, network, and workload controls
  • Python proficiency and comfort working with model APIs, SDKs, and evaluation tooling
  • Experience partnering with engineering and data teams as an advisor rather than a gatekeeper
Preferred
  • Experience with Microsoft 365 Copilot security posture, including oversharing remediation and sensitivity label enforcement
  • Familiarity with AI red team tooling such as PyRIT or Garak
  • Experience with MCP architecture and tool authorization patterns
  • Experience with Microsoft Defender for Cloud Apps, Purview, or an equivalent DSPM platform in an AI context
  • Working knowledge of ISO/IEC 42001 or the EU AI Act
  • Certifications: CISSP, AZ-500, SC-100, CCSP

Pay Range:$85.00 – $95.00 per hour, depending upon experience.

Health & Medical Benefits, 401K, Employee Assistance Program, and Sick Time applicable by state.

Accepted file types: doc, docx, pdf, Max. file size: 2 MB.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior AI Security Engineer
Senior AI Security Engineer

Plaster Group, LLC • Seattle (WA)

On-site
USD 150,000 - 190,000
AI Security Specialist
AI Security Specialist

MAP SSG • New York (NY)

On-site
USD 140,000 - 180,000
AI Security Specialist
AI Security Specialist

Milbank LLP • New York (NY)

On-site
USD 140,000 - 180,000
Security Architect - AI AppSec
Security Architect - AI AppSec

Sovereign Care Services LLP • Chicago (IL)

On-site
USD 110,000 - 150,000
401(k)
Employee discounts
Opportunity for advancement
+3
Senior AI Security Engineer
Senior AI Security Engineer

Prairie Consulting Services • Chicago (IL)

Hybrid
USD 120,000 - 150,000
AI Security Architect
AI Security Architect

Cadence • San Jose (CA)

On-site
USD 164,000 - 306,000
Paid vacation and holidays
401(k) plan with employer match
Employee stock purchase plan
+1
AI Security Engineer (GRC)
AI Security Engineer (GRC)

SCAN Group • United States

On-site
USD 120,000 - 180,000
Senior Security Engineer - AI Focus
Senior Security Engineer - AI Focus

Euna Solutions • Atlanta (GA)

On-site
USD 140,000 - 210,000
Security Architect AI AppSec
Security Architect AI AppSec

Sovereign Care Services • Chicago (IL)

On-site
USD 110,000 - 150,000
401(k)
Employee discounts
Opportunity for advancement
+2
Cybersecurity Engineer / AI Cloud Security Engineer
Cybersecurity Engineer / AI Cloud Security Engineer

Qualizeal • Dallas (TX)

Hybrid
USD 120,000 - 160,000