← Back to job listings
AI
Principal / Staff Security Engineer
AiDash · Palo Alto, United States
About The Role
Join AiDASH, a company dedicated to protecting critical infrastructure. As a Principal/Staff Security Engineer, you will lead our AppSec program and AI/LLM security hardening across the platform. You will embed security into every layer of the SDLC and work closely with various teams across the US and India. Your responsibilities will include managing the AppSec toolchain, enforcing risk-tiered dependency controls, hardening production GenAI deployments, and supporting the company's path to ISO 27001 and ISO 42001 certifications.
- Own and mature the AppSec toolchain across CI/CD, including SAST, DAST, SCA, secrets scanning, and IaC policy-as-code.
- Champion shift-left security by embedding threat modeling and secure-design reviews in PRs and sprint planning.
- Harden production GenAI deployments on AWS, including IAM, VPC routing, prompt-layer guardrails, output filtering, rate and cost controls.
- Cloud-native security experience in AWS — comfortable with Organizations/SCPs, Kubernetes security, container hardening, and CSPM tooling
- SF Bay Area based; able to work hybrid (2 days/week in Palo Alto)
- 10+ years in security engineering with meaningful AppSec depth — you have shipped and operated SAST/DAST/SCA (Semgrep, CodeQL, Snyk, Veracode, or equivalent) at production scale
- Hands-on experience securing production LLM or agentic AI deployments — IAM, guardrails, prompt injection controls, eval gating. RAG-demo experience alone does not meet the bar
- Compliance fluency: has personally contributed to a SOC 2 Type II or ISO 27001 audit — can read a control map without flinching
- IaC policy-as-code in a live pipeline (OPA/Rego, Checkov, Kyverno, tfsec, or equivalent)
- SBOM/AIBOM tooling at production scale (Interlynk, Anchore, Dependency-Track, or equivalent)
- Hands-on MCP work — design, hardening, or auth — even early-stage
- LLM eval-as-gate in CI (Promptfoo, Garak, DeepEval, Giskard) and AI red-teaming experience
- Prompt-layer DLP and AI runtime guardrails (Nightfall, Lakera Guard, Cyberhaven, Harmonic Security, Protect AI, NVIDIA NeMo Guardrails)
- ISO 42001 familiarity; NIST AI RMF and EU AI Act high-risk system requirements
- Experience securing SaaS sold into regulated sectors (utilities, energy, financial services, healthcare)
- EDR/XDR operations experience (CrowdStrike, SentinelOne, Defender) — helpful but not the primary focus of this role
- Comfort working across US/India time zones with a distributed team
- Public signals: conference talks, open-source contributions in CI/CD, MCP, or LLM-deployment security
This is an external listing. JobSpring does not represent or verify the employer. Report this listing
JobSpring