Unknown Company

Staff Information Security Engineer - AI First

northern, ky • Posted 1 weeks ago
Remote Full Time IT & Technology

Staff Information Security Engineer - AI First

Strong AI-first focus — integrates LLMs and AI assistants into security tooling and builds AI-assisted security agents with human-in-the-loop controls.

About the Role

Rithum is hiring a Staff Information Security Engineer focused on securing AI adoption across products and operations. The role designs and implements preventive, policy- and infrastructure-as-code security controls, automates security workflows and integrates LLMs/AI into security tooling to enable safe, scalable AI usage across the company.

Job Description

Role

Rithum seeks a Staff AI-First Information Security Engineer to own the intersection of AI adoption and information security. You will design guardrails for AI-powered products and workforce use, build automated security tooling, codify controls as policy- and infrastructure-as-code, and enable fast, low-risk AI usage across engineering and platform teams.

Key Responsibilities

  • Bridge architectural intent and operational reality; propose compensating controls and manage residual risk tracking and remediation.
  • Implement preventive, default-on security controls across cloud and enterprise environments, codified as policy- and infrastructure-as-code.
  • Implement and enforce identity and access controls, including access boundaries for AI systems and non-human/agent identities.
  • Maintain the InfoSec risk register; track emerging threats and translate them into actionable guidance.
  • Support third-party/vendor risk assessments with emphasis on vendors processing data through AI pipelines.
  • Automate repetitive security workflows (evidence collection, access reviews, alert enrichment) and build/operate AI-assisted security agents with human-in-the-loop gates and least-privilege credentials.
  • Integrate security tooling (SIEM, CSPM, DAST/SAST, vulnerability scanners) with LLM layers to surface actionable insight and automated response.
  • Define and enforce security requirements for AI features: model access controls, prompt-injection mitigations, output validation, and data-handling boundaries.
  • Conduct threat modeling for agentic and LLM-based systems, addressing novel attack surfaces like tool misuse, indirect prompt injection, and supply chain risk.

Qualifications

Minimum Qualifications

  • 5+ years of security engineering experience with demonstrated AI/ML security depth (prompt injection, model supply chain, adversarial inputs, RAG).
  • Experience using AI tools (ChatGPT, Copilot, Claude) and LLM frameworks/APIs (OpenAI, Anthropic, LangChain) to accelerate work.
  • Hands-on identity and access expertise across modern enterprise and cloud identity stacks, including access models for AI and non-human identities.
  • Experience with infrastructure and policy-as-code (e.g., Terraform, OPA/Rego) and proficiency in a scripting language for automation (Python preferred).
  • Cloud security expertise (AWS-focused experience/certification or equivalent), including multi-account governance and preventive guardrails.
  • Application security knowledge (OWASP Top 10, OWASP LLM/GenAI Top 10), secure SDLC, and threat-modeling methodologies (STRIDE, PASTA, or equivalent).
  • Practical experience building or operating AI agents and integrating security tooling (SIEM, CSPM, SAST/DAST/SCA) for actionable outputs.
  • Working knowledge of SOC 2 and/or ISO 27001 control frameworks.

Preferred Qualifications

  • Production experience building or operating AI agents.
  • Awareness of privacy regulations affecting AI (GDPR/CCPA), privacy-by-design, and DPIAs.
  • Red teaming or adversarial ML research experience.
  • Experience implementing privileged-access, key-management, posture-management, or data-protection programs.Experience with EDR, CASB, DLP, security automation, and SAST/DAST/IAST/SCA tools.Cloud architecture or security certifications (e.g., CCSK, TAIS E, AWS certifications).

    Compensation & Travel

    • Expected base pay range (U.S.): $170,000 - $220,000 per year.
    • Expected discretionary bonus: 12% of annual base salary.
    • Travel: Up to 10%.

    Benefits (select)

    • Medical, dental, and vision plans with company HSA contributions starting Day 1
    • 6% 401(k) match
    • PTO and paid holidays (20 days PTO, 9 company-paid holidays, 2 floating holidays, 7 sick days, 2 wellness days, 1 paid volunteer day; increases with tenure)
    • Parental leave (12 weeks primary, 4 weeks secondary)
    • Accident, critical illness, and hospital indemnity insurance
    • Pet insurance; legal assistance and identity-theft insuranceLife insurance (2x salary)Calm app and Employee Assistance Program$65/month remote work stipend for internet

    ChatGPT Copilot Claude OpenAI Anthropic LangChain Terraform OPA/Rego Python AWS SIEM CSPM DAST SAST Vulnerability scanners RAG EDR CASB DLP IAST SCA STRIDE PASTA OWASP LLM/GenAI Top 10

    Skills

    Information Security Security Engineering Identity and Access Management Threat Modeling Cloud Security Policy-as-Code Infrastructure-as-Code Automation Scripting Risk Management Vendor/Third-Party Risk Assessment Security Tooling Integration Application Security Compliance (SOC 2 / ISO 27001) Collaboration Research

    Experience Level

    USD 170,000 - 220,000/year

    Employment Type

    {Full-Time}

    • Remote-first working conditions
    • Remote work stipend ($65/month)
    • Medical insurance
    • Dental insurance
    • Company HSA contributions
    • 20 days PTO (increases with tenure)
    • 2 paid floating holidays
    • 2 wellness days
    • 12 weeks primary caregiver leave
    • 4 weeks secondary caregiver leave
    • Critical illness insurance
    • Hospital indemnity insurance
    • Legal assistance insurance
    • Identity theft insurance
    • Life insurance (2x salary)
    • Calm app access and Employee Assistance Program
    • Tuition assistance
    • Culture and team-building activities
    • Charitable contribution match (up to $250/year)

#J-18808-Ljbffr

Staff Information Security Engineer - AI First in northern at Unknown Company

This position is listed as full time and able to be worked remotely.

Back to Job Search