AI Cloud Security Engineer
Estuate Inc.
- Job
- 28942
- Posted
- Location
- Remote
- Work type
- Contract
- Tax terms
- W2, C2C, 1099
- Experience
- Experience open
- Openings
- 1 opening
Opens your email app with a message to the employer, its subject naming this job. Attach your resume and send it from your own email.
Skills
- REST
- Python
- AWS
- Azure
- ServiceNow
- IAM
About the job
Job description:
Role: AI Cloud Security Engineer
REMOTE
Role Summary
We are looking for an AI Security Engineer with a strong cloud security foundation to secure our growing portfolio of agentic AI systems across AWS and multi-cloud environments. You will own security for LLM-based agents, agentic workflows, and AI-integrated infrastructure from design through runtime and working closely with VM, App Sec, and Cloud Security teams.
Key Responsibilities
- Design and enforce Agentic IAM policies with least privilege agent identity lifecycle management
- Implement sandboxing and containment architectures to limit blast radius from compromised agents
- Apply the OWASP Agentic Security Framework to assess prompt injection, tool misuse, and uncontrolled recursion risks
- Define Agentic Guardrails input/output validation, scope enforcement, and human-in-the-loop controls
- Build Agent Auditing, Detection, and Response capabilities for anomalous agent behavior and unauthorized data exfiltration
- Secure AI Harness infrastructure such as orchestration layers, memory stores, vector DBs, and API integrations
- Conduct LLM Security assessments including prompt injection testing and inference abuse detection
- Harden protocol and tool security for agent-to-tool communication (MCP, REST, function calling, webhooks)
Required Qualifications
- 4+ years in cloud security (AWS, Google Cloud Platform, Azure)
- 2+ years in AI Security Governance and GPT
- Hands-on experience securing AWS-native AI services (Bedrock, SageMaker, Lambda)
- Deep knowledge of OWASP LLM Top 10 and the OWASP Agentic Security Framework
- Experience designing IAM for non-human identities agent roles, service accounts, workload identity
- Proficiency in Python for detection and auditing tooling
- Working knowledge of container/Lambda sandboxing and network segmentation for agent isolation
Preferred Qualifications
- Exposure to agentic frameworks (n8n, LangChain, AutoGen)
- Familiarity with Upwind CNAPP or similar runtime cloud security platforms
- Experience integrating security findings into ServiceNow VRM
- CIP compliance awareness in OT/energy environments