Back to Jobs

AI Security Engineer / Application Security Engineer

Not Disclosed

Job Description & Details

This is a specialized contract role focusing on the bleeding edge of security: safeguarding complex AI/LLM integrations, autonomous agents, and cloud architectures. If you enjoy breaking things before malicious actors do and want to dive deep into adversarial testing of AI systems, this gig offers a chance to make an immediate impact on modern AI infrastructure.

What You'll Actually Be Doing

You'll spend your days tearing apart system architectures, data flows, and API integrations to find where things break. A lot of your time will go into threat modeling for critical services and running hands-on adversarial tests against AI agents. You won't just be writing reports; you'll partner directly with engineering teams to walk them through your findings, explain why an attack vector matters, and help them ship secure code without slowing them down.

The Core Tech Stack

You need a solid foundation in traditional AppSec—think threat modeling, API security, IAM, and cloud services (microservices and distributed systems). But what really sets this role apart is the AI component. You must understand how to test LLM applications for prompt injection, excessive agency, tool misuse, and data leakage. Knowing your way around Python, Go, or Bash for security automation is also a huge plus for scaling these assessments.

Interview Expectations

Expect the hiring team to test both your traditional AppSec chops and your understanding of AI-specific failure modes. They will likely ask you to walk through a threat model for a hypothetical distributed system or describe how you would perform an adversarial test on an LLM agent with tool-calling capabilities. They aren't looking for textbook definitions; they want to see your practical methodology for identifying risk, tracing attack paths, and communicating remediation strategies to developers.

Application Advice

To get past the ATS, your resume needs to explicitly highlight your hands-on experience with threat modeling, penetration testing, and secure design reviews. Don't just list tools—focus on outcomes. If you've previously tested AI/LLM integrations, prompt injection vulnerabilities, or complex cloud APIs, put those front and center. Emphasize your technical communication skills, as this role requires bridging the gap between deep technical findings and engineering execution.