Staff Security Engineer - AI Security & Platforms
Job description
About the role
Ridgeline is seeking a highly experienced Staff Security Engineer to take a leadership role in developing and securing AI platforms within the organization. This position involves designing and implementing security solutions that facilitate the safe adoption of AI technologies while proactively addressing emerging security threats specific to AI systems. You will be instrumental in shaping security practices for AI across the company, working closely with engineering, product teams, and leadership to ensure security is integrated into every stage of AI development and deployment. The role requires a deep understanding of security principles, AI systems, and the unique challenges they present, with an emphasis on building scalable, reliable, and secure AI infrastructure. You will also serve as a mentor and technical leader, guiding teams on best practices for AI security and helping to foster a security-first mindset across the organization.
Key facts
What you'll do
- Lead the design and implementation of secure platforms and frameworks that enable safe AI integration across Ridgeline's products and services.
- Identify and address vulnerabilities unique to AI systems, including prompt injection, data leakage, model poisoning, and other emerging threats that traditional security tools may not cover effectively.
- Establish and enforce trust boundaries within AI systems, ensuring proper isolation and access controls to prevent unauthorized data access or manipulation.
- Develop and maintain guardrails for internal AI development tools, enabling rapid engineering and experimentation without compromising security standards.
- Collaborate closely with product managers, engineers, and data scientists to define security requirements for new AI features, ensuring security considerations are integrated from the outset.
- Build AI-enhanced security tools that improve operational efficiency, such as automated threat detection, security monitoring, and risk assessment systems, while minimizing false positives and false negatives.
- Set organizational standards and best practices for secure and responsible AI usage, focusing on reducing risks associated with AI deployment and ensuring compliance with relevant policies and regulations.
- Influence security practices across engineering teams through technical expertise, mentorship, and the promotion of security-aware development processes, rather than through mandates or directives.
- Mentor team members on AI security principles, secure coding practices, and effective AI usage, helping to elevate the overall security maturity of the organization.
- Regularly incorporate AI into your own work, leveraging AI tools to enhance security processes, ensure the accuracy and security of outputs, and serve as a role model for responsible AI usage within the company.
- Participate in security incident response and threat modeling specific to AI systems, ensuring the organization can respond effectively to AI-related security incidents.
- Stay current with the latest developments in AI security, threat landscape, and best practices, sharing knowledge with the team and integrating new insights into security strategies.
Requirements
- Over 8 years of experience in application security, cloud security, or security-focused software development, with a proven track record of leading complex security projects.
- Demonstrated expertise in at least one core area such as secure code review, cloud security (AWS, IAM), or security-focused software development, with the ability to apply this knowledge to AI security challenges.
- Strong proficiency in at least one programming language, with a preference for Python; experience with Kotlin or TypeScript is considered a plus.
- Practical experience working with AI/LLM tools, including building or securing AI systems, and the ability to evaluate AI outputs for accuracy and potential security risks.
- Experience in securing or developing AI/LLM systems, or a demonstrated ability to quickly learn new technical areas related to AI security.
- Solid understanding of security architecture principles, including threat modeling, risk assessment, and security controls, with a focus on scalable and reliable solutions.
- Excellent communication skills, capable of articulating complex security concepts and trade-offs to both technical and non-technical stakeholders.
- Ability to work collaboratively across teams, influencing security practices through technical expertise rather than mandates.
- Strong problem-solving skills, with a focus on thorough analysis and resolution of security findings.
- Experience working in fast-paced environments with evolving security threats and technologies.
Nice to have
- Experience with techniques to prevent prompt injection, sanitize LLM inputs and outputs, or secure AI tool usage in production environments.
- Background in developing platforms or security frameworks that scale across organizations, including infrastructure-as-code practices.
- Contributions to AI security research, open-source security projects, or community forums focused on AI safety and security.
- Familiarity with large-scale cloud security practices, including managing security in cloud environments like AWS, GCP, or Azure, and using infrastructure-as-code tools such as Terraform.
- Knowledge of compliance standards and regulations relevant to AI deployment, such as GDPR, HIPAA, or other industry-specific requirements.
Skills & tools
- Application security best practices and principles
- Cloud security, especially AWS and IAM
- Programming in Python, with additional experience in Kotlin or TypeScript preferred
- AI/LLM tools and systems security, including evaluation and mitigation of AI-specific vulnerabilities
- Security architecture, threat modeling, and risk assessment
- Infrastructure-as-code tools like Terraform (preferred)
- Security monitoring and automated threat detection tools
- Familiarity with security frameworks and standards relevant to AI and cloud environments
Practical notes
Candidates must have authorization to work in the United States without requiring employer sponsorship.
Ridgeline is committed to fostering a diverse and inclusive workplace, providing equal opportunities to all applicants regardless of background.
All application information will be handled in accordance with our Applicant Privacy Statement.
This role is based on-site at our offices in San Ramon, CA, or Reno, NV, and involves working in a collaborative environment with a focus on security and AI innovation.
Candidates should be prepared to demonstrate their expertise through technical interviews, including security assessments and scenario-based discussions.
We encourage candidates with a passion for AI security and a desire to influence the future of secure AI systems to apply.