Senior AI Security Engineer
Job Description
Teleion Consulting is hiring a hands-on, client-facing Senior AI Security Engineer to help protect AI workloads across the full AI stack. You will focus on securing AI workloads, agentic systems, and enterprise AI deployments, including LLMs, AI gateway/proxy layers, agentic pipelines, and zero trust controls. The role is onsite in Seattle, WA and offered on a contract basis with a salary range of USD 155,000 to 200,000 per year.
In this position, you’ll strengthen production security by evaluating AI and LLM attack surfaces, deploying centralized controls, and building monitoring and adversarial testing to identify weaknesses early. You’ll also support clients with AI governance guidance aligned to industry frameworks.
Responsibilities
- Assess and address the AI and LLM attack surface in production environments, including prompt injection (direct and indirect), data leakage through model output, insecure tool use, jailbreaking, and model supply chain risk.
- Deploy, configure, and operate AI gateways and LLM proxy layers with centralized control, including model allowlists, per-team API keys, rate and budget limits, centralized audit logging, and inline input/output guardrails for prompt injection, sensitive data egress, credential leakage, and unsafe output.
- Design and implement governance frameworks for agentic systems and MCP (Model Context Protocol) tooling, including registries, approval workflows, runtime policy enforcement, and identity and authorization patterns for non-human identities.
- Implement OAuth-based access, token lifecycle management, and scoped tool permissions for AI agents using least-privilege principles.
- Extend zero trust controls to AI workloads across identity, device, network, application, and data pillars, with Azure preferred (Entra ID, Defender for Cloud, Key Vault, Purview, Conditional Access).
- Build monitoring and detection capabilities for AI systems, including prompt behavior analysis, tool invocation patterns, anomalous output detection, and data movement tracking.
- Perform AI red team and adversarial testing using PyRIT, Garak, or equivalent tooling to identify vulnerabilities before adversaries do.
- Lead shadow AI discovery programs to identify unsanctioned AI applications and browser extensions across the enterprise.
- Conduct third-party AI vendor security reviews and assess M365 Copilot security posture, including oversharing remediation and sensitivity label enforcement.
- Advise clients on AI governance frameworks including OWASP Top 10 for LLM Applications, MITRE ATLAS, NIST AI RMF, and relevant compliance standards.
- Perform tasks as assigned.
Requirements
- 7+ years of security engineering experience, including at least 2 years directly securing AI, ML, or GenAI systems in production environments.
- Hands-on experience securing LLM and agent attack surfaces, including prompt injection, jailbreaking, data extraction, capability chaining, and supply chain risk.
- Experience deploying or operating an AI gateway, LLM proxy, or centralized AI control plane with production-grade input/output guardrails and audit logging.
- Familiarity with agentic AI risk classes: excessive agency, capability chaining, tool and memory poisoning, and unsafe autonomous action.
- Experience implementing identity and authorization patterns for non-human identities in an AI or service-oriented context.
- Strong cloud security background with Azure preferred, including Entra ID, Defender for Cloud, Key Vault, Purview, and Conditional Access.
- AI red team experience using PyRIT, Garak, or equivalent adversarial testing tools.
- Proficiency in Python, with experience working with LLM APIs (OpenAI, Anthropic, Azure OpenAI) and security evaluation tooling.
- Knowledge of OWASP Top 10 for LLM Applications, MITRE ATLAS, and NIST AI RMF.
- Certifications preferred: CISSP, AZ-500, SC-100, or CCSP. Familiarity with ISO/IEC 42001 or EU AI Act is a plus.
Benefits
- full benefits
- PTO
- holiday
- 401(k)
Technologies: Python, OAuth, PyRIT, Garak, MCP (Model Context Protocol), OpenAI, Anthropic, Azure OpenAI, Azure, Entra ID, Defender for Cloud, Key Vault, Purview, Conditional Access, M365 Copilot, OWASP Top 10 for LLM Applications, MITRE ATLAS, NIST AI RMF, ISO/IEC 42001, EU AI Act, CISSP, AZ-500, SC-100, CCSP