Secure BJAK's AI-enabled products and agent workflows using third-party models, focusing on customer data shared with model providers, agent permissions, user data isolation and prompt injection through untrusted content.
Responsibilities
- ▹Assess customer data sent to third-party model vendors, including minimization, vendor controls, retention, logging and approved use
- ▹Design controls limiting AI agent permissions, tools, actions and system access using least privilege and explicit authorization
- ▹Implement and test tenant and user data isolation across prompts, conversation history, retrieval, memory and AI-connected services
- ▹Threat model and test prompt injection and indirect injection through uploaded documents, retrieved content, links and other untrusted inputs
- ▹Partner with Product and Engineering on safe document ingestion, content handling, output validation and approval for sensitive actions
- ▹Support SC TRM and BNM RMiT for AI technology risks, including assessments, third-party oversight, control evidence and remediation
- ▹Build security tests, monitoring and response procedures for AI misuse, data exposure, unauthorized actions and vendor incidents
Requirements
- ▹Degree in Computer Science, Cybersecurity, AI or a related field, or equivalent experience
- ▹3+ years in application security, product security, security engineering or AI system security
- ▹Experience implementing or owning SC TRM and BNM RMiT controls, technology risk or regulatory control evidence
- ▹Understanding of third-party LLM integrations, model APIs, agent tools, RAG and AI application architectures
- ▹Knowledge of prompt injection, indirect injection, cross-user data leakage, excessive agent permissions and vendor data disclosure risks
- ▹Programming or scripting skills, preferably Python and TypeScript/Node.js, plus APIs and AWS or GCP
Soft skills
Collaboration with Product, Legal, Compliance, Data and Engineering; practical risk communication
About the company
BJAK started in 2019 and is the leading online insurance platform in Southeast Asia, now expanding into other areas of personal finance such as saving, investing and travel. The team spans over 20 nationalities, working from offices and remotely.
Languages: Angol: erős kommunikációs készség (a fő munkanyelv)
Education: Informatikai, kiberbiztonsági, mesterséges intelligencia vagy kapcsolódó diploma, vagy azzal egyenértékű tapasztalat
Ähnliche Stellen

Stelle
Application Security Engineer (AppSec)
Bjakcareer
+4
💰 Gehalt: keine Angabe
🌍 Remote
🗣️ EN

Stelle
Security Operations Engineer
CircleCI
AI/ML
+4
💰 Gehalt: keine Angabe
🌍 Remote
Anywhere in the World
🗣️ EN
Stelle
Application Security Engineer II
Abnormal
AI/MLLlm
+3
114 638–164 775 €/Jahr
brutto
🌍 Remote
Anywhere in the World
🗣️ EN

Stelle
Security Engineer, Institutional Trading
Blockchain.com
Llm
+2
💰 Gehalt: keine Angabe
🏢 Vor Ort
Paris
🗣️ EN

Stelle
Cybersecurity Engineer
10a Labs
+5
118 955–140 984 €/Jahr
brutto
🌍 Remote
🗣️ EN

Stelle
Security Engineer, Public Sector
Scale AI
+2
192 443–301 353 €/Jahr
brutto
🏢 Vor Ort
St. Louis
🗣️ EN