Bjak
Bjak
New

AI Security Engineer

Brak informacji o wynagrodzeniu
SeniorFull-time
#446783·Dodano 3 dni temu·2
Źródło: Bjak
Aplikuj teraz

Tech Stack / Keywords

AIprompt injectionLLMPythonTypeScriptNode.jsAWSGCPAPIs

Firma i stanowisko

BJAK is a leading mobile-first insurance platform founded in 2019 that enables insurance accessibility online by millions in Southeast Asia. The company is expanding its financial product offerings to include spending, saving, investing, exchanging, and travelling services. BJAK has a diverse global team with over 20 nationalities, working remotely and from offices.

Wymagania

  • Degree in Computer Science, Cybersecurity, AI, or related field, or equivalent experience.
  • 3+ years in application security, product security, security engineering, or AI system security.
  • Experience implementing or owning SC TRM and BNM RMiT controls, technology risk, or regulatory control evidence.
  • Understanding of third-party LLM integrations, model APIs, agent tools, RAG, and AI application architectures.
  • Knowledge of prompt injection, indirect injection, cross-user data leakage, excessive agent permissions, and vendor data disclosure risks.
  • Programming or scripting skills, preferably in Python and TypeScript/Node.js, plus APIs and AWS or GCP.
  • Able to collaborate with Product, Legal, Compliance, Data, and Engineering teams on practical controls and risk communication.

Obowiązki

  • Assess customer data sent to third-party model vendors, including minimization, vendor controls, retention, logging, and approved use.
  • Design controls limiting AI agent permissions, tools, actions, and system access using least privilege and explicit authorization.
  • Implement and test tenant and user data isolation across prompts, conversation history, retrieval, memory, and AI-connected services.
  • Threat model and test prompt injection and indirect injection through uploaded documents, retrieved content, links, and other untrusted inputs.
  • Partner with Product and Engineering on safe document ingestion, content handling, output validation, and approval for sensitive actions.
  • Support SC TRM and BNM RMiT for AI technology risks, including assessments, third-party oversight, control evidence, and remediation.
  • Build security tests, monitoring, and response procedures for AI misuse, data exposure, unauthorized actions, and vendor incidents.
Bjak

Bjak

100 aktywnych ofert

Zobacz wszystkie oferty
Aplikuj teraz