AI Security Engineer (Offensive & Defensive)
Summary
Coins, a regulated Philippine crypto exchange, seeks an AI Security Engineer to run offensive and defensive security for AI agents — pen-testing agents against prompt injection and context poisoning, building AI-driven security detection tools, and hardening cloud-native (K8s/Docker) agent runtimes. Requires 3+ years security experience, 1+ year in LLM security, and Python/Go/C++ skills.
Responsibilities:
- Responsible for AI Agent security review and penetration testing, including defense design and implementation against emerging threats such as AI tool misuse, context poisoning, various forms of data/prompt poisoning, and prompt injection.
- Responsible for designing and developing AI-based automated security detection tools, enabling automated alert triage, attack attribution, and improved security operations efficiency.
- Participate in building Agent behavior auditing and anomaly detection systems, identifying abnormal behavior chains during Agent runtime, constructing an AI-driven security operations platform, and exploring, designing, and implementing defense and countermeasure solutions based on real business scenarios.
- Combine security risks of cloud-native infrastructure (K8S, Docker, cloud services) to assess the attack surface of Agent runtime environments and design defense-in-depth solutions.
Requirements:
- At least 3+ years of security offense/defense experience (penetration testing/red team practice), with 1+ years of experience in LLM (large model) security offense/defense; extensive hands-on red team experience preferred.
- Familiar with network architecture and cloud-native technology stacks, including K8S, Docker container security, and cloud security (IAM, network isolation, cloud-native threat models, etc.), with the ability to assess security risks in complex infrastructure.
- Possess practical Agent development capability, able to independently build/modify AI Agents (e.g., based on frameworks such as LangChain), as well as hands-on offensive capability against Agents (practical construction and validation of attack techniques such as tool misuse, prompt injection, context poisoning).
- Familiar with security frameworks such as OWASP Top 10 for LLM and MITRE ATT&CK, familiar with common AI attack techniques, adversarial logic, and defense solutions, with a strong passion for AI security.
- Proficient in at least one programming language such as Python/Go/C++, with the ability to develop security offense/defense tools or perform deep secondary development on open-source security platforms.
Nice to Have
- Familiar with mainstream AI frameworks (PyTorch, TensorFlow, LangChain, etc.), with practical experience in local deployment and optimization of large language models.
- Hands-on cloud security (AWS) experience or related certifications.
Skills
As published by lever
Resume/CV, Full name, Pronouns, Email, Phone, Current location, Current company, Other website, LinkedIn URL, Twitter URL, GitHub URL, Portfolio URL