Why This Role Stands Out
You'll thrive as an AI Gateway Architect/Engineer by designing and securing cutting-edge AI runtime security architectures, leveraging your extensive experience in AI security and API gateways within a hybrid work environment. This role offers significant growth potential and the opportunity to shape enterprise AI security, making it an exciting prospect for skilled security engineers eager to make an impact.
Quick Overview
Job Description
Sr. AI/ML Security Engineer
Dallas, TX or Malvern, PA are preferred (hybrid schedule), but open to well-qualified remote candidates
12+ month contract with potential to extend or convert FTE
Requirements:
- 10+ years of security (cyber security, platform security, etc.) engineering experience using tools such as SIEM, IAM/PAM, RBAC/ABAC, etc.
- 3+ years of AI Security engineering experience with specific focus on AI/ML platforms, generative AI/LLM technologies, and/or model-serving ecosystems
- Hands on experience with Kong, LiteLLM, or similar API gateway/LLM proxy technologies (e.g. Apigee, Portkey, etc.)
- Hands on experience with AWS (preferred), Azure, or Google Cloud Platform cloud services
- Hands on platform engineering experience with IaC, CI/CD security, and other operational tasks
- Hands on experience with threat modeling, AI/LLM/Agentic system guardrails, identity verification and authorization
- Strong communication and documentation experience
- Experience with AI/LLM platform engineering is a strong plus (e.g. RAG, AI Agents, LangChaing, LangGraph, MCP ecosystems, A2A communications, etc.)
- Security certifications such as CISSP, OSCP, CEH, CASP+, CISM are highly desired
Description:
POSITION SUMMARY
We are seeking a highly skilled Senior AI/ML Security Engineer to design, secure, and scale the enterprise AI runtime security architecture. This role will lead the security engineering and operationalization of centralized AI gateway platforms, including Kong AI Gateway, LiteLLM, and associated AI runtime security controls.
The ideal candidate brings deep expertise in AI/ML security, API security, identity and access management, cloud-native architecture, agentic AI systems, and runtime policy enforcement. This engineer will partner closely with platform engineering, security architecture, AI application teams, and infrastructure teams to establish secure-by-design patterns for LLMs, AI agents, MCP integrations, and emerging AI technologies.
This role is a key technical leader responsible for building the enterprise control plane for AI interactions and ensuring secure, observable, resilient, and governed AI consumption across cloud, SaaS, endpoint, and agentic environments.
Key Responsibilities
AI Gateway Architecture & Engineering
- Design and implement enterprise AI gateway solutions using Kong AI Gateway, LiteLLM, and related technologies.
- Establish secure routing patterns for LLM traffic across internal, third-party, and cloud-hosted foundation models.
- Develop standardized onboarding patterns for applications, agents, copilots, and autonomous systems using centralized gateway controls.
- Define scalable gateway architectures supporting high availability, failover, token management, model routing, provider abstraction, rate limiting, and policy enforcement.
- Create security standards for AI API management, service-to-service authentication, gateway plugins, and runtime governance.
AI Runtime Security Controls
- Engineer and deploy runtime controls governing prompts, responses, tool usage, memory access, retrieval operations, model calls, and agent actions.
- Integrate AI guardrail solutions with gateway enforcement layers for inline inspection and policy decisions.
- Design controls to detect and prevent prompt injection, jailbreak attacks, data exfiltration, sensitive data leakage, malicious tool invocation, agent privilege escalation, and unsafe autonomous actions.
- Implement policy-driven outcomes including allow, detect, block, redact, modify, quarantine, and human approval workflows.
- Define anti-bypass controls that reduce direct-to-model access outside approved enterprise pathways.
Agentic AI & Identity Security
- Develop security architectures for AI agents, agent-to-agent communication, MCP servers, plugins, tools, and autonomous workflows.
- Design identity-aware enforcement using OAuth 2.0, OpenID Connect, workload identity, machine identities, just-in-time authorization, RBAC, and ABAC.
- Establish delegated authorization patterns that constrain agent actions based on user authority, application risk, tool sensitivity, and business context.
- Define standards for tool registration, access governance, privilege boundaries, approval gates, and kill-switch capabilities.
API, Cloud & Platform Security
- Secure AI-facing APIs, gateway plugins, MCP integrations, model endpoints, and service-to-service communication.
- Perform threat modeling and security design reviews for AI platforms, applications, and distributed runtime architectures.
- Partner with cloud and platform engineering teams to implement Zero Trust patterns, network segmentation, secrets management, certificate management, and secure workload authentication.
- Drive secure deployment patterns across AWS, Azure, Kubernetes, container platforms, and cloud-native AI services.
- Embed security testing and policy validation into CI/CD and infrastructure-as-code workflows.
Monitoring, Detection & Response
- Build centralized observability across AI gateways and runtime enforcement points.
- Integrate gateway, guardrail, identity, application, and model telemetry into enterprise SIEM and detection engineering platforms.
- Develop detections for prompt attacks, policy violations, data leakage, unauthorized model usage, anomalous token consumption, excessive permissions, and agent misuse.
- Define operational metrics for control coverage, control efficacy, false positives, false negatives, bypass resistance, latency, availability, and failure modes.
- Create incident response playbooks for AI security events, gateway failures, guardrail bypasses, compromised identities, and unsafe autonomous behavior.
Strategic & Technical Leadership
- Serve as the AI gateway and runtime security subject matter expert.
- Partner with architecture, platform engineering, application security, identity, data security, and AI governance teams on enterprise AI strategy.
- Evaluate emerging AI security technologies, frameworks, gateway capabilities, and vendor solutions through structured technical assessments and proofs of concept.
- Define reusable reference architectures, engineering standards, implementation patterns, operational runbooks, and control requirements.
- Mentor engineers and help advance organizational AI security maturity.
Similar jobs
- MA
Azure Databricks & Agentic AI Architect
NewMagicforce
United States🇺🇸HybridYesterdaySQLETLMLOps+6Technology - PA
AI Lead / AI Architect(Healthcare | AWS Bedrock | Agentic AI)- Remote - 6 Months
NewPalni Inc
United States🇺🇸RemoteYesterdaySQLAWSDatabricks+3Technology - ST
AI Engineer / Staff Software Engineer - W2 Position
NewSaim Technologies
United States🇺🇸HybridYesterdayExpressMaterial UIMicroservices+14Technology - SS
GEN AI Architect with AWS architecture
NewSun-IT Solutions
Boston, MA🇺🇸HybridYesterdayDynamoDBSpringAPI Gateway+12Technology - AI
AI Engineer with Java
NewAmerican IT Systems
Atlanta, GA🇺🇸HybridYesterdayMicroservicesSQLSpring+5Technology - CL
AI Engineer
NewClevanoo LLC
Coppell, TX🇺🇸HybridYesterdaySOAPAWSAzure+2Technology