Staff Security Engineer - AI Enablement

TrustlySan Francisco, CaliforniaOn-siteFull-timeStaff, 8–12 yearsListed 2 months ago

Apply now

About this role

WHAT YOU'LL DO

- Own security assessment and risk management for Trustly's AI and LLM systems — including Claude, MCP server implementations, agentic workflows, and AI-assisted developer tooling.

- Define and implement security controls, access governance, and monitoring frameworks for AI systems — covering prompt injection, data leakage, model misuse, and agentic system abuse scenarios.

- Partner closely with the AI Enablement team to embed security from the start of AI feature development — conducting threat modeling, reviewing architectures, and advising on safe deployment patterns.

- Build and maintain tooling for AI-specific security monitoring — detecting anomalous model behavior, unauthorized data access, and policy violations in real time.

- Develop and maintain AI security standards, guidelines, and training resources for engineering teams across Trustly — making it easy for engineers to build with AI safely.

- Stay at the leading edge of AI security research — tracking emerging attack vectors, defensive techniques, and regulatory developments relevant to LLM and agentic system security.

WHO YOU ARE

- 8+ years of security engineering experience, with at least 2-3 years focused on AI/ML security, LLM security, or security for data-intensive systems.

- Deep, hands-on understanding of the AI security threat landscape — prompt injection, jailbreaking, data poisoning, model exfiltration, insecure agentic tool use, and MCP-specific attack surfaces.

- Strong security engineering fundamentals — experienced in threat modeling, secure design review, penetration testing, and building security monitoring infrastructure.

- Familiarity with MCP (Model Context Protocol) architecture, LLM orchestration frameworks, and agentic AI deployment patterns — you can reason about security at the level of individual tool calls and context windows.

- Track record of operating at Staff+ IC scope — driving security decisions that span multiple teams, influencing architecture through technical credibility rather than authority.

- Excellent communicator — able to explain novel AI security risks clearly to both technical and non-technical audiences, and to earn trust with engineering teams as a partner rather than a gatekeeper.