Lead MLSecOps Security Engineer

Advanced Tech Placement

  • Roseland, NJ
  • 4 days ago

    Highlights

    Evaluate AI Security Posture Management (AI-SPM) capabilities and establish processes for identifying, categorizing, prioritizing, and remediating risks associated with AI assets, agents, prompts, datasets, and AI-enabled applications. Stay current on top vulnerabilities affecting Machine Learning Models, Large Language Models (LLMs), and AI agents, such as prompt injection, data poisoning, model theft, and adversarial attacks.

    Numbers & Facts

    LocationRoseland, NJ

    Description

    We are seeking a Lead MLSecOps Security Engineer. 

    What You’ll Do:

    • Design, implement, and maintain secure ML pipelines for AI/ML model evaluation, validation, deployment, and inference.
    • Assess and mitigate security risks throughout the ML lifecycle, including data ingestion, model storage, and deployment.
    • Evaluate, secure, and govern AI coding agents, autonomous agents, and agentic workflows used throughout the software development lifecycle.
    • Define and implement security guardrails for AI-assisted software development platforms, agent orchestration frameworks, and autonomous development pipelines.
    • Develop and operationalize an Agentic Development Lifecycle (ADLC) framework that incorporates security requirements, threat modeling, testing, deployment governance, and continuous security monitoring.
    • Evaluate AI Security Posture Management (AI-SPM) capabilities and establish processes for identifying, categorizing, prioritizing, and remediating risks associated with AI assets, agents, prompts, datasets, and AI-enabled applications.
    • Assess emerging threats against frontier AI models and agentic systems and recommend preventative and detective security controls to reduce enterprise risk.
    • Develop and maintain code for AI/ML pipelines using Python and CICD, ensuring robust security controls and compliance with best practices.
    • Institutionalize security scanning of AI/ML models in line with shift left strategy; interpret results and remediate identified issues.
    • Evaluate and optimize model inference deployment strategies, balancing security, performance, and resource utilization.
    • Stay current on top vulnerabilities affecting Machine Learning Models, Large Language Models (LLMs), and AI agents, such as prompt injection, data poisoning, model theft, and adversarial attacks.
    • Collaborate with data scientists, ML engineers, and security teams to drive adoption of secure ML practices.
    • Establish strong partnership with key stakeholders in technology and product organizations.
    • Perform other duties as required.

    Experience You'll Need:

    • Hands-on experience with MLOps pipelines and model deployment tools (e.g., Kubeflow, MLflow, SageMaker).
    • Strong programming skills in Python and CICD for automation and pipeline development.
    • Hands-on experience with major AI coding assistants and coding agents such as GitHub Copilot, Microsoft Copilot, Cursor, Claude Code, Windsurf, or similar AI-assisted development platforms.
    • Experience using AI-driven development techniques across multiple programming languages including Python, Java, JavaScript, C#, .NET, Go, or similar technologies.
    • Strong understanding of agentic architectures, AI agents, autonomous workflows, Retrieval-Augmented Generation (RAG), and associated security considerations.
    • Experience assessing Agent Sandboxes, agent runtime environments, agent-to-tool communications, and agent execution workflows.
    • Understanding of security limitations and control mechanisms governing agent behavior, including permissions, approval workflows, runtime controls, and data protection guardrails.
    • Ability to identify, categorize, prioritize, and operationalize risks associated with AI assets, models, prompts, datasets, agents, and AI-enabled applications.
    • Deep understanding of Agentic Development Lifecycle (ADLC) principles and integration of security controls throughout planning, development, testing, deployment, and operations.
    • Knowledge of frontier AI model cybersecurity programs and the ability to reason about layered controls that mitigate AI-driven cyber attacks, adversarial ML threats, model and agent abuse.
    • Familiarity with structured (SQL, data warehouses) and unstructured (object storage, NoSQL) data systems.
    • Familiarity with Databricks
    • Experience with ML security tools for model scanning and vulnerability assessment.
    • Knowledge of top OWASP AI/ML vulnerabilities, including:

    - Prompt injection
    - Data and model poisoning
    - Model extraction and inversion
    - Adversarial example attacks
    - Supply chain risks in ML components

    • Strong communication skills and ability to document and explain Cybersecurity and AI/ML security controls to technical and non-technical stakeholders.
    • Understanding of AL/ML model formats such as pickle, tensorflow, safetensors
    • Experience in rolling out model scanning solution as part of model development.
    • Understanding CI/CD pipelines covering source control, integration, and deployment (ex: Bitbucket, Jenkins, JIRA, Artifactory, Nexus, SonarQube, git, Snyk scanner).
    • Previous software engineering/architecture experience (Java, C#, .Net, JavaScript, Python) preferred.
    • Strong analytical/problem solving skills and cross functional knowledge across multiple development and security disciplines.
    • Experience with development of RESTful web services preferred.
    • Understanding of advanced iterative Agile, Cloud and Container Security, GenAI Security
    • Exceptional problem-solving skill
    • Excellent communication and presentation skills
    • Ability to be a good team player as part of remote teams
    • Self-motivated with positive attitude
    • Should be able to work independently.


    Qualifications:

    • Bachelor's degree in computer science, Information / Cyber Security, Computer Systems Engineering, Computer Information Systems or equivalent education and experience required
    • Eight years or more experience in various IT or cybersecurity roles, with five or more years of experience specifically in software engineering roles.
    • Deep knowledge and understanding of AI/ML and Agentic Security and related risks
    • Candidate should be very thorough in internet technologies and highly versed with web development best practices.
    • Strong analytical/problem solving skills and cross functional knowledge across multiple development and security disciplines.
    • Ability to communicate security-related concepts to a broad range of technical and non-technical stakeholders.
    • Understanding of advanced iterative Agile and container & cloud security
    • Familiarity with micro-services architecture and Design Patterns
    • Excellent analytic skills, including qualitative and quantitative data analysis to support and defend data-driven decision-making regarding system threats, vulnerabilities, and risk
    • Any of the following are a plus but not necessary: CEH, CISSP, CSSLP, GCIA, GPEN, GWAPT

    Similar Jobs