Backblaze
, , Colombia / Global
, , Colombia / Global
Backblaze is seeking a Senior AI Security Engineer to design and implement safeguards for internal AI usage , with a focus on agentic systems, developer protection, and runtime security .
What You’ll Do
Agentic AI Safeguards
Architect and implement guardrails for tool-using AI systems, including:
Tool access controls and allowlists
Context and memory isolation
Step-level validation of agent actions
Apply mitigations aligned to the OWASP Agentic AI Top 10 (e.g., prompt injection, unsafe tool use, data leakage, excessive autonomy).
Runtime Security Controls
Build enforcement mechanisms that govern AI behavior at execution time:
Interceptors, proxies, or middleware for tool/API calls
Policy decision and enforcement layers
Rate limits, execution bounds, and kill-switches
Prevent unsafe or unauthorized actions initiated by AI systems.
Non-Human Identity (NHI)
Design and implement identity and access controls for agents and automation, including:
Short-lived credentials and scoped permissions
Clear separation between human and non-human access
Strong binding of identity to task context and execution
Ensure all AI actions are attributable and auditable.
Observability & Detection
Implement logging and tracing for AI activity:
Prompts, tool usage, and decision flows
Build detection capabilities using:
Behavioral baselining and anomaly detection techniques
Identify and alert on:
Abnormal tool usage
Suspicious prompt patterns
Unexpected data access
Threat Modeling (MAESTRO)
Perform agentic system threat modeling using MAESTRO, including:
Mapping agent capabilities, trust boundaries, and attack paths
Modeling misuse and adversarial scenarios
Translate findings into practical safeguards and detection logic.
Developer Safeguards
Protect developers using AI tools by:
Preventing sensitive data exposure
Validating AI-generated code and actions
Constraining unsafe automation
Enable safe usage of AI‑assisted development tools (e.g., Claude Code, Codex, Cursor) with:
Security validation layers
Controlled prompting and output handling patterns
The Right Fit
7+ years in security engineering or backend systems
Proven experience designing and deploying security controls, such as:
Runtime enforcement layers (proxies, middleware, policy engines)
Identity and access systems, especially for non-human entities
Strong programming skills (Python preferred; Go, Java, or TypeScript a plus)
Experience using AI‑assisted development tools such as Claude Code in real workflows, including understanding associated security risks and safeguards
Experience with:
Logging, monitoring, and detection systems
Building or securing API/service interactions
Practical familiarity with:
Agentic AI systems or tool-integrated LLM workflows
OWASP guidance for AI/agent risks
Practitioner Knowledge
Experience applying (not just referencing):
OWASP Agentic AI / LLM risk guidance
NIST AI RMF concepts in real systems
CSA guidance on workload and machine identity
Strong understanding of:
Zero Trust for non-human identities
Secrets management and credential scoping
Observability tooling (e.g., OpenTelemetry, ELK)
Bonus Points For
Experience securing internal AI platforms or developer‑facing AI tools
Background in detection engineering, threat hunting, or adversarial testing
Familiarity with agent frameworks (e.g., LangChain, LlamaIndex)
Experience mentoring engineers and guiding secure design
We are proud to be an Equal Opportunity Employer.
We are committed to fostering a workforce where all employees feel a sense of belonging regardless of race, ethnicity, nationality, gender, sexual orientation, age, religion, socio-economic status, ability, veteran status, and education.
#J-18808-Ljbffr
Bogotá, Distrito Capital / Global
, Colombia / Global
Bogotá / Global
Bogotá / Global
Bogotá / Global
Bogotá / Global