Start Your Search Here

Job Search

Backblaze

, , Colombia / Global

Sr. AI Security Engineer

Job Description

Backblaze is seeking a Senior AI Security Engineer to design and implement safeguards for internal AI usage , with a focus on agentic systems, developer protection, and runtime security .

What You’ll Do

Agentic AI Safeguards

Architect and implement guardrails for tool-using AI systems, including:

Tool access controls and allowlists

Context and memory isolation

Step-level validation of agent actions

Apply mitigations aligned to the OWASP Agentic AI Top 10 (e.g., prompt injection, unsafe tool use, data leakage, excessive autonomy).

Runtime Security Controls

Build enforcement mechanisms that govern AI behavior at execution time:

Interceptors, proxies, or middleware for tool/API calls

Policy decision and enforcement layers

Rate limits, execution bounds, and kill-switches

Prevent unsafe or unauthorized actions initiated by AI systems.

Non-Human Identity (NHI)

Design and implement identity and access controls for agents and automation, including:

Short-lived credentials and scoped permissions

Clear separation between human and non-human access

Strong binding of identity to task context and execution

Ensure all AI actions are attributable and auditable.

Observability & Detection

Implement logging and tracing for AI activity:

Prompts, tool usage, and decision flows

Build detection capabilities using:

Behavioral baselining and anomaly detection techniques

Identify and alert on:

Abnormal tool usage

Suspicious prompt patterns

Unexpected data access

Threat Modeling (MAESTRO)

Perform agentic system threat modeling using MAESTRO, including:

Mapping agent capabilities, trust boundaries, and attack paths

Modeling misuse and adversarial scenarios

Translate findings into practical safeguards and detection logic.

Developer Safeguards

Protect developers using AI tools by:

Preventing sensitive data exposure

Validating AI-generated code and actions

Constraining unsafe automation

Enable safe usage of AI‑assisted development tools (e.g., Claude Code, Codex, Cursor) with:

Security validation layers

Controlled prompting and output handling patterns

The Right Fit

7+ years in security engineering or backend systems

Proven experience designing and deploying security controls, such as:

Runtime enforcement layers (proxies, middleware, policy engines)

Identity and access systems, especially for non-human entities

Strong programming skills (Python preferred; Go, Java, or TypeScript a plus)

Experience using AI‑assisted development tools such as Claude Code in real workflows, including understanding associated security risks and safeguards

Experience with:

Logging, monitoring, and detection systems

Building or securing API/service interactions

Practical familiarity with:

Agentic AI systems or tool-integrated LLM workflows

OWASP guidance for AI/agent risks

Practitioner Knowledge

Experience applying (not just referencing):

OWASP Agentic AI / LLM risk guidance

NIST AI RMF concepts in real systems

CSA guidance on workload and machine identity

Strong understanding of:

Zero Trust for non-human identities

Secrets management and credential scoping

Observability tooling (e.g., OpenTelemetry, ELK)

Bonus Points For

Experience securing internal AI platforms or developer‑facing AI tools

Background in detection engineering, threat hunting, or adversarial testing

Familiarity with agent frameworks (e.g., LangChain, LlamaIndex)

Experience mentoring engineers and guiding secure design

We are proud to be an Equal Opportunity Employer.

We are committed to fostering a workforce where all employees feel a sense of belonging regardless of race, ethnicity, nationality, gender, sexual orientation, age, religion, socio-economic status, ability, veteran status, and education.

#J-18808-Ljbffr

Aplicar Now

Similar Opportunities

View all jobs