AI Security Engineer (AI & Agentic Security)
strategic-systems-international
Mexico
Posted Sep 2, 2026
- Contract
Job description
AI Security Engineer — AI & Agentic Security We are seeking an experienced, hands-on, AI Security engineer / developer, to support our Enterprise AI Security Program. Our AI landscape spans everything from internal chatbot pilot to a full agentic workflow with tool access, Code Assistant rollout to thousands of developers to new Agentic platform. Externally, the tools and protocols worth worrying about change every few months. You'll be the person who can look at both ends of that spread ensuring safe and secure adoption of AI. What You'll Do Use-case-driven security guidance Understand the range of ways internal teams are using or want to use AI — chatbots, RAG, copilots, fine-tuning, agentic workflows — and provide security guidance calibrated to the actual risk of each use case rather than a one-size-fits-all policy. Act as a security thought partner to internal teams standing up new AI capability: help them design securely from the start instead of retrofitting controls after launch. Translate ambiguous, fast-moving AI adoption patterns into concrete, written security requirements that engineering and product teams can implement and be evaluated against. Policy creation and enforcement Author AI security policies and standards (ex. acceptable use, data handling, model/tool approval, agent registration) that are specific enough to be testable, not just aspirational. Design and build automated enforcement wherever possible — policy-as-code, CI/CD gates, gateway/proxy-level blocking, DLP integration — rather than relying on manual review or the honor system. Identify and close gaps where current tooling can't enforce a policy (e.g., caller-controlled trace headers, unmanaged BYOAI tools) and propose compensating controls or architecture changes. Emerging AI landscape & threat tracking Continuously track new AI tools, frameworks, and protocols entering the enterprise or the broader ecosystem (e.g., MCP, A2A, agent frameworks, autonomous local agents like OpenClaw/Hermes) — understand their architecture, trust model, and where they break assumptions our existing controls rely on. Turn that research into practical guidance quickly: what the tool does, what its attack surface looks like, whether/how to allow it, detect it, or block it, and what compensating controls apply in the interim. Maintain awareness of the broader AI security vendor and threat landscape (AI-native platforms, guardrail products, CVEs affecting AI frameworks) to keep CVSH's posture current rather than reactive. Agentic AI & gateway security Design, implement, and operate security controls for AI/ML, GenAI, and agentic systems spanning model-level, data-level, and platform-level protections across AWS Bedrock, GCP Vertex AI, Azure, and SaaS AI tools. Engineer and enforce guardrails mitigating prompt injection, unsafe outputs, unauthorized tool execution, data leakage, and insecure agentic workflows, with explicit focus on PHI/PII exposure. Support and maintain CVSH AI Gateway Requirements — evaluating vendor capabilities against MoSCoW-prioritized criteria across identity, MCP/A2A protocol security, prompt/payload security, and runtime governance. Support the Agentic Identity Control Framework: treating AI agents as first-class identities with zero standing privilege, SPIFFE/SVID workload identity, JIT access, and registry-enforced lifecycle state. Extend IAM principles to non-human identities — defining authentication, authorization, scoped delegation, and revocation for autonomous agents distinct from human or service-account models. Evaluate and stand up runtime detection for excessive agency, action-trajectory violations, tool poisoning, and MCP supply-chain risk, working with vendors such as Straiker, Prisma AIRS, and Virtue AI. Delivery, detection & compliance Embed security controls into CI/CD and agentic delivery pipelines; partner with platform engineering and application teams from design through deployment gate. Apply NIST AI RMF, MITRE ATLAS, and OWASP LLM/Agentic Top 10 to threat-model AI systems and shape enterprise reference architecture. Investigate AI-specific incidents (prompt injection, jailbreak, data exfiltration via agent, unsanctioned/shadow AI tools) and contribute to detection engineering and IR playbooks. Partner with Legal, Privacy, and Compliance on HIPAA Security Rule mapping, BAA/subprocessor review, and audit-ready control documentation. Contribute to vendor RFI/RFP evaluation, scoring, and POC design for AI Gateway and AI-native runtime security platforms. What You'll Need Required: Strong SWE, with 5+ years of experience; proficiency in Python (or equivalent) 3+ years in AI/ML or GenAI security (prompt injection defense, unsafe output handling, tool-use abuse, data leakage), or equivalent hands-on infosec experience with a demonstrated pivot into AI security. Demonstrated ability to write security policy that is specific and testable, and to translate it into automated enforcement (policy-as-code, CI/CD gates, gateway-level controls, DLP rules) rather than a document that relies on voluntary compliance. A track record of self-directed learning on fast-moving technical topics — comfortable digging into how a brand-new tool, protocol, or framework actually works (architecture, trust boundaries, auth model) well enough to give a defensible security opinion on it within days, not months. Working knowledge of AI/LLM security risks: prompt injection, jailbreaking, unsafe outputs, tool-use abuse, identity misuse, agentic workflow escalation. Hands-on familiarity with AI security frameworks: NIST AI RMF, MITRE ATLAS, OWASP LLM Top 10 / OWASP Agentic Top 10. Experience with cloud security across at least two of AWS, GCP, and Azure, including native AI/ML security tooling (Bedrock Guardrails, Vertex AI floor settings, Azure AI Content Safety). Identity and access management fundamentals — OAuth 2.0/2.1, OIDC, mTLS — with interest in or exposure to non-human/workload identity (SPIFFE/SPIRE) and agent identity models. Experience in a highly regulated industry (healthcare, financial services) with HIPAA or equivalent compliance obligations. Strong technical writing — you can turn a vendor capability gap or a new tool's risk profile into a control requirement someone else can implement and test. Preferred: Direct experience with MCP (Model Context Protocol) or A2A protocol security, or with AI gateway products (Kong AI Gateway, Azure APIM GenAI Gateway, Apigee). Exposure to AI-native runtime security platforms (Straiker, Palo Alto Prisma AIRS, Virtue AI) or classic content guardrail products. Familiarity with shadow-AI / BYOAI risk — e.g., locally-run autonomous agent frameworks (OpenClaw and similar), unsanctioned browser extensions, personal AI accounts used for work — and how to discover and govern them at scale (CrowdStrike Falcon, Wiz, CASB, or similar). AI red-team tooling experience (PyRIT, Promptfoo, AgentDojo, or custom harnesses). Familiarity with Microsoft Purview DSPM for AI or equivalent DLP-for-AI tooling. Relevant certification (CAISP, ISACA AAISM) or equivalent demonstrated skill. Experience with detection engineering, SIEM integration, and telemetry design for AI/agent behavior.