Backblaze is the cloud storage innovator delivering a modern alternative to traditional cloud providers.
Senior AI Security Engineer
Location
Argentina
Posted
6 days ago
Salary
0
Seniority
Senior
Job Description
Senior AI Security Engineer
Backblaze
• Architect and implement guardrails for tool-using AI systems, including: • Tool access controls and allowlists • Context and memory isolation • Step-level validation of agent actions • Apply mitigations aligned to the OWASP Agentic AI Top 10 (e.g., prompt injection, unsafe tool use, data leakage, excessive autonomy) • Build enforcement mechanisms that govern AI behavior at execution time: • Interceptors, proxies, or middleware for tool/API calls • Policy decision and enforcement layers • Rate limits, execution bounds, and kill-switches • Design and implement identity and access controls for agents and automation, including: • Short-lived credentials and scoped permissions • Clear separation between human and non-human access • Strong binding of identity to task context and execution • Ensure all AI actions are attributable and auditable • Implement logging and tracing for AI activity: • Prompts, tool usage, and decision flows • Build detection capabilities using: • Behavioral baselining and anomaly detection techniques • Identify and alert on: • Abnormal tool usage • Suspicious prompt patterns • Unexpected data access • Perform agentic system threat modeling using MAESTRO, including: • Mapping agent capabilities, trust boundaries, and attack paths • Modeling misuse and adversarial scenarios • Translate findings into practical safeguards and detection logic • Protect developers using AI tools by: • Preventing sensitive data exposure • Validating AI-generated code and actions • Constraining unsafe automation
Job Requirements
- 7+ years in security engineering or backend systems
- Proven experience designing and deploying security controls, such as:
- Runtime enforcement layers (proxies, middleware, policy engines)
- Identity and access systems, especially for non-human entities
- Strong programming skills (Python preferred; Go, Java, or TypeScript a plus)
- Experience using AI-assisted development tools such as Claude Code in real workflows, including understanding associated security risks and safeguards
- Experience with:
- Logging, monitoring, and detection systems
- Building or securing API/service interactions
- Practical familiarity with:
- Agentic AI systems or tool-integrated LLM workflows
- OWASP guidance for AI/agent risks.
Benefits
- Health insurance
- 401(k) matching
- Flexible work hours
- Paid time off
- Remote work options
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
• Lead threat modeling, hardening and operation of security services • Define and implement security standards and automated security controls • Partner with cross-functional teams to embed secure design practices • Lead technical direction and roadmap execution for assigned area • Maintain high Operational Excellence to minimize downtime • Participate in on-call rotation to respond to events • Manage lifecycle of product and cloud security vulnerabilities • Influence secure adoption of LLMs and AI tools • Mentor and coach earlier career engineers
• Implement and tune core security controls that protect employees across three global brands • Operate the day-to-day security stack, spanning endpoint detection and response (EDR), zero-trust network access, identity-aware proxies, browser security, and data loss prevention (DLP) • Use AI-assisted coding tools to automate security workflows, incident response, and compliance evidence collection • Address modern SaaS risk such as shadow IT, OAuth token sprawl, and high-risk application reviews • Help teams adopt secure-by-default baselines
Information Security Officer 3 – Security Architect, Application and Product Security
Government of AlbertaBringing you information about government news and services. Comment rules: http://alberta.ca/SMComments
• Development, maintenance, advocacy, and compliance for security architecture and DevSecOps framework and policy instruments such as directives, frameworks, policies, standards, and guidelines. • Security architecture subject matter expertise in the one or more following domains: Secure application development processes and tools. • Secure business architecture. Secure data architecture. Secure application architecture. Secure technology architecture. • Consultation, evaluation, and delivery of digital service products throughout the solution development life cycle (SDLC) for conformance to IMT cybersecurity policy instruments including formulation of options and recommendations. • Conduct security review, consult, and advise on secure coding, secrets management, on-premises, Amazon Web Services (AWS), Azure, Google Cloud Platform (GCP), and third-party hosted solutions with verbal and written report. • Provide security advice to business and technical stakeholders, including senior executives. • Participate in projects as an information security subject matter expert with a focus on security architecture and security capabilities within a DevSecOps framework to protect digital service development and operations. • Participate in the identification of information security requirements, as well as the development of strategies and solutions to meet these requirements across the organization. • Facilitate or perform identification, assessment, and treatment of information and technology security threats and risks.
• Act as the technical Cyber Security specialist for OT/ICS environments, supporting high-criticality industrial operations across different companies within the Cosan Group; • Lead initiatives to expand OT security monitoring, including onboarding new plants, industrial networks, critical assets, and operational technologies into the monitoring ecosystem; • Develop and refine detection use cases for industrial environments, using OT monitoring platforms, SIEM, EDR and specialized threat detection solutions; • Perform industrial network architecture analyses, evaluating segmentation, zones and conduits, communication flows, and adherence to security best practices for ICS environments; • Participate in defining and reviewing secure architectures for new industrial projects, operational expansions, and OT digital transformation initiatives; • Support identification, analysis and assessment of cyber threats, vulnerabilities and exposures in industrial environments, proposing prioritized mitigation plans based on risk; • Work with Engineering, Automation, Network and Operations teams to implement security controls for OT environments; • Provide technical support for the cyber incident response process involving industrial systems, contributing root cause analysis, containment and corrective actions; • Conduct technical assessments of maturity, hardening, industrial network segmentation and compliance with market frameworks and standards; • Manage vendors and partners specialized in OT security, ensuring technical quality, governance and continuous evolution of contracted services; • Prepare executive reports and presentations for different organizational levels, communicating risks, metrics, progress and investment needs; • Support the definition of the Group's OT Cyber Security strategy, contributing to the advancement of industrial security maturity.



