About this role
About This Role
As Biogen's AI Security Engineer, you are a hands-on technical specialist responsible for securing the organization's rapidly expanding use of artificial intelligence, machine learning, and generative AI technologies. This role operates at the intersection of cybersecurity engineering and AI/ML systems — ensuring that AI deployments across Biogen are resilient against adversarial threats, data poisoning, model manipulation, prompt injection, and unauthorized data exposure.
The AI Security Engineer will design, implement, and operate security controls purpose-built for AI workloads — spanning model development pipelines, inference endpoints, training data protection, and AI-assisted automation platforms. This role is responsible for translating emerging AI threat frameworks (MITRE ATLAS, OWASP AI Top 10, NIST AI RMF) into actionable engineering controls that protect Biogen's AI investments without impeding innovation velocity.
This position requires a rare combination of software engineering depth, AI/ML systems knowledge, and cybersecurity expertise. The scope demands:
Deep technical proficiency across AI/ML security, cloud security, and application security — with the ability to build production-grade security tooling, not just assess or advise
Autonomous execution — independently identifying AI security gaps, designing solutions, and implementing them end-to-end without requiring constant direction
Adversarial mindset — thinking like an attacker to identify how AI systems can be subverted, manipulated, or exploited before threat actors do
Cross-domain fluency — bridging the gap between data science teams building AI and security teams protecting the enterprise, translating between both worlds.
What You’ll Do
AI Threat Detection & Response Engineering
- Design, build, and operate detection capabilities for AI-specific threats including prompt injection, model extraction, training data poisoning, and adversarial input attacks
- Develop and maintain AI security monitoring pipelines that correlate signals across LLM interactions, API gateways, and model inference endpoints
- Engineer automated response playbooks for AI security incidents — including model quarantine, token revocation, and session termination
- Continuously research emerging AI attack vectors and translate findings into detection signatures and prevention controls
- Operate and tune CrowdStrike AI Runtime Defense (AIRD) and Microsoft Purview AI governance controls across the environment
AI Platform Security Engineering
- Implement security controls across AI development and deployment platforms (AWS SageMaker, Azure OpenAI, Databricks, internal ML pipelines)
- Secure model training environments — including data access controls, compute isolation, artifact signing, and pipeline integrity verification
- Engineer guardrails for generative AI usage — content filtering, DLP integration, output validation, and session-level access controls
- Design and enforce AI model governance controls including model registry security, version control integrity, and deployment approval gates
- Perform security architecture reviews of new AI services and integrations before production deployment
AI Risk Assessment & Framework Implementation
- Conduct technical risk assessments of AI systems using MITRE ATLAS, OWASP AI Top 10, and NIST AI RMF frameworks
- Perform adversarial testing (red teaming) of AI models and AI-integrated applications to identify vulnerabilities before production deployment
- Develop and maintain AI security standards, reference architectures, and secure development guidelines for AI/ML teams
- Evaluate third-party AI services and vendor AI integrations for security posture, data handling practices, and supply chain integrity
Security Automation & AI-Augmented Defense
- Build and maintain AI-powered security tools that augment the cybersecurity team's detection and response capabilities
- Develop integrations between security platforms (CrowdStrike, Microsoft Defender, Okta, Zscaler) and AI/ML systems for intelligent threat correlation
- Engineer automated security workflows using LLMs and agentic AI for threat hunting, alert triage, and incident investigation acceleration
- Contribute to the security team's internal AI capabilities — including MCP server development, agent frameworks, and security data pipelines
- Build and maintain security scoring engines and risk quantification models that drive prioritization decisions
Required Skills
- 5+ years of combined experience in cybersecurity engineering, software engineering, and/or AI/ML systems
- Demonstrated expertise in at least three of the following domains:
- AI/ML Security: LLM security, prompt injection mitigation, model robustness testing, adversarial ML, AI supply chain integrity
- Cloud Security Engineering: AWS, Azure, or GCP security architecture and controls implementation at scale
- Application Security: Secure SDLC, API security, code review, penetration testing, threat modeling
- Security Operations: Detection engineering, SIEM/SOAR development, incident response, threat hunting
- Hands-on proficiency with Python and demonstrable experience building production security tooling and automation
- Experience with AI/ML frameworks (PyTorch, TensorFlow, Hugging Face, LangChain) and AI cloud services (SageMaker, Azure OpenAI, Bedrock, Databricks)
- Working knowledge of AI security frameworks: MITRE ATLAS, OWASP AI Top 10, NIST AI RMF
- Experience with enterprise security platforms (CrowdStrike, Microsoft Defender, Okta, Zscaler, CyberArk, or equivalent)
- Strong understanding of LLM architectures, retrieval-augmented generation (RAG), fine-tuning security implications, and agentic AI patterns
- Bachelor's Degree in Computer Science, Cybersecurity, Data Science, or related technical field required
Job Level: Management
Additional Information
The base compensation range for this role is: $140,000.00-$187,250.00
Base salary offered is determined through an analytical approach utilizing a combination of factors including, but not limited to, relevant skills & experience, job location, and internal equity.
Regular employees are eligible to receive both short term and long-term incentives, including cash bonus and equity incentive opportunities, designed to reward recent achievements and recognize your future potential based on individual, business unit and company performance.
In addition to compensation, Biogen offers a full and highly competitive range of benefits designed to support our employees’ and their families physical, financial, emotional, and social well-being ; including, but not limited to:
- Medical, Dental, Vision, & Life insurances
- Fitness & Wellness programs including a fitness reimbursement
- Short- and Long-Term Disability insurance
- A minimum of 15 days of paid vacation and an additional end-of-year shutdown time off (Dec 26-Dec 31)
- Up to 12 company paid holidays + 3 paid days off for Personal Significance
- 80 hours of sick time per calendar year
- Paid Maternity and Parental Leave benefit
- 401(k) program participation with company matched contributions
- Employee stock purchase plan
- Tuition reimbursement of up to $10,000 per calendar year
- Employee Resource Groups participation
Why Biogen?
We are a global team with a commitment to excellence, and a pioneering spirit. As a mid-sized biotechnology company, we provide the stability and resources of a well-established business while fostering an environment where individual contributions make a significant impact. Our team encompasses some of the most talented and passionate achievers who have unparalleled opportunities for learning, growth, and expanding their skills. Above all, we work together to deliver life-changing medicines, with every role playing a vital part in our mission. Caring Deeply. Achieving Excellence. Changing Lives.
At Biogen, we are committed to building on our culture of inclusion and belonging that reflects the communities where we operate and the patients we serve. We know that diverse backgrounds, cultures, and perspectives make us a stronger and more innovative company, and we are focused on building teams where every employee feels empowered and inspired. Read on to learn more about Biogen.
All qualified applicants will receive consideration for employment without regard to sex, gender identity or expression, sexual orientation, marital status, race, color, national origin, ancestry, ethnicity, religion, age, veteran status, disability, genetic information or any other basis protected by federal, state or local law. Biogen is an E-Verify Employer in the United States.