Rithum is the heartbeat of commerce
Staff Information Security Engineer – AI First
Location
United States
Posted
3 days ago
Salary
$170K - $220K / year
Seniority
Lead
Job Description
Staff Information Security Engineer – AI First
Rithum
• Act as the bridge between architectural intent and operational reality; mediate conflicts between security requirements and feasible implementation, propose compensating controls where gaps exist and help register, track and remediate residual risks. • Implement preventive, default-on security controls across cloud and enterprise environments, codified as policy- and infrastructure-as-code so security is enforced by design, including controls that govern how AI tools and models may be used. • Implement and enforce identity and access controls to an agreed standard, including access boundaries for AI systems and non-human/agent identities by partnering with Platform Engineering and IT to align tooling and policy to the architecture. • Assist in maintaining the InfoSec risk register; track emerging threats and translate them into actionable guidance for engineering teams. • Support third-party and vendor risk assessments, with a focus on vendors who process data through AI pipelines. • Automate repetitive security workflows (evidence collection, access reviews, alert enrichment) and build or operate AI-assisted security agents — with human-in-the-loop approval gates, least-privilege credentials, and explicit attention to each agent's own blast radius. • Integrate security tooling (SIEM, CSPM, DAST/SAST, vulnerability scanners) with LLM layers to surface actionable insight and automated responses. • Define and enforce security requirements for AI-powered features: model access controls, prompt-injection mitigations, output validation, and data-handling boundaries. • Conduct threat modelling on agentic and LLM-based systems, accounting for novel attack surfaces such as tool misuse, indirect prompt injection, and supply chain risk.
Job Requirements
- 5+ years of security engineering experience with demonstrated AI/ML security depth (prompt injection, model supply chain, adversarial inputs, RAG).
- Experience using AI tools (ChatGPT, Copilot, Claude, etc.) and LLM frameworks and APIs (OpenAI, Anthropic, LangChain, or similar) to accelerate and elevate your work.
- Hands-on identity and access expertise across modern enterprise and cloud identity stacks, including access models for AI systems and non-human identities.
- Infrastructure and policy-as-code (e.g. Terraform, OPA/Rego) and proficiency in a scripting language for automation (Python preferred).
- Cloud security expertise: AWS Solutions Architect / Security Specialty or equivalent demonstrated expertise, including multi-account governance, preventive guardrails, and policy-as-code.
- Application security (OWASP Top 10 and the OWASP LLM/GenAI Top 10, secure SDLC) and threat-modelling methodologies (STRIDE, PASTA, or equivalent). Practical experience building or operating AI agents, and integrating security tooling (SIEM, CSPM, SAST/DAST/SCA) so it surfaces action rather than raw alerts.
- Working knowledge of SOC 2 and/or ISO 27001 control frameworks.
Benefits
- Medical, dental and vision benefits: Affordable health care plans and company HSA contributions, starting on Day 1
- A 6% 401(k) match
- Competitive time off package with 20 days of Paid Time Off, 9 Company-Paid holidays, 2 paid floating holidays, 7 paid sick days, 2 Wellness days, and 1 Paid Volunteer Day; at 3 years of service PTO increases to 22 days, and at 5 years it increases to 25 days
- 12 weeks primary caregiver leave & 4 weeks secondary caregiver leave
- Accident, critical illness, and hospital indemnity insurance
- Pet insurance
- Legal assistance and identity theft insurance plans
- Life insurance 2x salary
- Access to the Calm app and the Employee Assistance Program
- $65/month Remote work stipend for internet
- Culture and team-building activities
- Tuition assistance
- Career development opportunities
- Charitable contribution match up to $250 per year
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
• Reviewing the current information risk program, including improvements to processes that identify, measure, track, and remediate risks with business owners. • Working collaboratively with other information security risk personnel across Instructure to help identify enterprise-level risks for the CISO and work on finding enterprise-level solutions. • Assisting in annual audits for industry-specific reports, such as ISO27001, PCI, SOC 1 and SOC 2 Type I and Type II reports where risk controls are affected. • Developing and executing information security for internal control testing across the enterprise. • Work with product Engineering teams to secure solutions and ensure that Instructure procedures comply with regulatory framework requirements. • Partner with engineering teams to design and implement technical solutions to mitigate security risks • Collaborate with internal teams to establish metrics and dashboards that effectively measure the success of security programs. • Coordinate between external auditors and internal controls owners, ensuring smooth communication and efficient evidence gathering. • Documenting findings and assessing risk where deviations exist resulting from internal and external testing. • Evaluating third-party vendors to ensure compliance with established standards and risk tolerance levels. • Presenting results and findings of audits to peers and leadership when necessary. • Writing and editing policies and reports to maintain an industry-leading risk program. • Communicating the value of GRC and information risk management at Instructure. • Acting as an information security risk leader for Instructure, ensuring a world-class security posture. • Reviewing new tools for security risks during the procurement process.
• Design, implement, and maintain DLP controls across email, endpoint, cloud, web, and collaboration platforms • Engineer and tune custom DLP detections using regex, Exact Data Matching (EDM), Indexed Document Matching (IDM), classifiers, and contextual telemetry • Own the full DLP policy lifecycle, including policy creation, normalization, testing, deployment, tuning, version control, and change management • Analyze and triage DLP and insider risk alerts, conduct root cause analysis, and recommend mitigation strategies to improve control effectiveness • Partner with Security Operations, Incident Response, Risk, Legal, Compliance, and Information Protection teams to investigate potential data exfiltration and insider risk events • Build and enhance automation workflows, dashboards, and reporting to improve visibility into data movement, user behavior, and program performance • Serve as a technical subject matter expert for DLP platforms and data protection capabilities across the enterprise • Translate regulatory requirements, business needs, and risk scenarios into practical, enforceable technical controls • Continuously improve detection quality, operational processes, and reporting to advance program maturity and business alignment • Contribute to the evaluation and responsible use of AI-enabled security capabilities that improve detection, analysis, and operational efficiency within data protection workflows
Senior Product Security Engineer
InstacartInstacart invites the world to share love through food. This is how homemade is made.
• Design and conduct offensive security operations / engagements for product and internal tools across Instacart. • Deploy and operationalize a variety of open-source and commercially available security tools that can scale out and be maintained long term. • Collaborate with cross-functional teams, including engineering and product, to integrate security testing into their SDLC cycle. • Share knowledge and mentor other team members, promoting a culture of continuous learning and growth.
Senior Product Security Engineer II
InstacartInstacart invites the world to share love through food. This is how homemade is made.
• Design and conduct offensive security operations / engagements for product and internal tools across Instacart. • Deploy and operationalize a variety of open-source and commercially available security tools that can scale out and be maintained long term. • Collaborate with cross-functional teams, including engineering and product, to integrate security testing into their SDLC cycle. • Share knowledge and mentor other team members, promoting a culture of continuous learning and growth.



