Software Engineer –AI Security & Quality (GenAI)
Seeking a highly technical Software Engineer focused on strengthening the security posture, compliance controls, and quality assurance practices of enterprise Generative AI and agent orchestration solutions. The role centers on AI security testing, governance, assurance, risk assessment, and solution review, while also supporting software test automation initiatives.
Primary DutiesAI Security Assessments
- Perform security and safety assessments of LLM, RAG, and agentic applications.
- Evaluate risks including prompt injection, jailbreak attempts, unauthorized data disclosure, unsafe outputs, excessive permissions, tool misuse, and tenant isolation weaknesses.
- Conduct AI-focused assurance activities and threat assessments.
- Implement Moonshot and Litmus testing for applicable AI solutions.
- Configure baseline and use-case-specific testing scenarios.
- Develop adversarial test cases, analyze outcomes, and maintain assurance evidence.
- Create representative datasets for security, safety, and functional validation.
- Generate and manage synthetic test data securely.
- Ensure data classification, masking, anonymization, retention, and disposal controls are enforced.
- Translate organizational, security, and AI governance requirements into practical controls and testing activities.
- Advise stakeholders regarding secure use of enterprise and sensitive data within AI solutions.
- Review data access, tenant isolation, retention policies, logging, integrations, retrieval boundaries, and service selection risks.
- Support security reviews, audits, remediation efforts, and production readiness assessments.
- Evaluate proposed AI solution architectures.
- Identify privacy, security, and compliance concerns.
- Recommend mitigation measures and security-by-design practices throughout the development lifecycle.
- Document vulnerabilities, control weaknesses, impacts, risks, and remediation recommendations.
- Verify remediation effectiveness with engineering teams.
- Communicate technical and non-technical risks to stakeholders.
- Track trends, recurring issues, and assurance metrics.
- Embed automated AI security validation into CI/CD workflows.
- Establish release gates, regression checks, and security acceptance criteria.
- Prevent material risks from reaching production environments.
Test Automation Engineering
- Develop automated API, regression, functional, and end-to-end tests.
- Utilize tools such as Pytest, Playwright, Cypress, Postman, or equivalent technologies.
- Investigate defects and operational issues.
- Review application logs and cloud environments to identify root causes.
- Produce actionable defect documentation.
- Promote consistent testing standards and reusable testing assets.
- Support shared ownership of product quality across teams.
Professional Experience
- Minimum 3 years of experience in software engineering, cybersecurity, application security, AI assurance, software test engineering, or technical quality assurance.
- Strong understanding of security risks affecting LLM, RAG, and agentic systems.
- Knowledge of prompt injection, unsafe outputs, excessive privileges, data leakage, application abuse, and insecure tool integrations.
- Experience working with Moonshot, Litmus, or comparable AI evaluation and adversarial testing frameworks.
- Ability to design test scenarios and interpret assurance results.
- Experience translating privacy, security, and AI governance requirements into controls, risk assessments, assurance evidence, and testing plans.
- Experience evaluating system architectures, trust boundaries, cloud environments, and integration risks.
- Ability to recommend secure and proportionate technical solutions.
- Strong communication and consulting capabilities.
- Able to explain risks, challenge assumptions, and influence secure implementation decisions.
- Proficiency in Python.
- Working knowledge of JavaScript or TypeScript.
- Experience with API, regression, functional, and end-to-end test automation.
- Familiarity with AWS environments, SQL databases, container platforms, encryption, logging, access management, data classification, retention controls, and secure handling of sensitive information.
- AI red-team exercises, AI threat modeling, security assurance, or application security review experience.
- Familiarity with industry guidance such as OWASP GenAI Security Project, NIST AI Risk Management Framework, or MITRE ATLAS.
- Experience testing RAG architectures, agent tooling, model integrations, RBAC implementations, tenant isolation controls, and AI-specific attack surfaces.
- Experience supporting environments with stringent security and compliance requirements.