Secure BJAK's AI-enabled products and agent workflows using third-party models, focusing on customer data shared with model providers, agent permissions, user data isolation and prompt injection through untrusted content.
Responsibilities
- ▹Assess customer data sent to third-party model vendors, including minimization, vendor controls, retention, logging and approved use
- ▹Design controls limiting AI agent permissions, tools, actions and system access using least privilege and explicit authorization
- ▹Implement and test tenant and user data isolation across prompts, conversation history, retrieval, memory and AI-connected services
- ▹Threat model and test prompt injection and indirect injection through uploaded documents, retrieved content, links and other untrusted inputs
- ▹Partner with Product and Engineering on safe document ingestion, content handling, output validation and approval for sensitive actions
- ▹Support SC TRM and BNM RMiT for AI technology risks, including assessments, third-party oversight, control evidence and remediation
- ▹Build security tests, monitoring and response procedures for AI misuse, data exposure, unauthorized actions and vendor incidents
Requirements
- ▹Degree in Computer Science, Cybersecurity, AI or a related field, or equivalent experience
- ▹3+ years in application security, product security, security engineering or AI system security
- ▹Experience implementing or owning SC TRM and BNM RMiT controls, technology risk or regulatory control evidence
- ▹Understanding of third-party LLM integrations, model APIs, agent tools, RAG and AI application architectures
- ▹Knowledge of prompt injection, indirect injection, cross-user data leakage, excessive agent permissions and vendor data disclosure risks
- ▹Programming or scripting skills, preferably Python and TypeScript/Node.js, plus APIs and AWS or GCP
Soft skills
Collaboration with Product, Legal, Compliance, Data and Engineering; practical risk communication
About the company
BJAK started in 2019 and is the leading online insurance platform in Southeast Asia, now expanding into other areas of personal finance such as saving, investing and travel. The team spans over 20 nationalities, working from offices and remotely.
Languages: Angol: erős kommunikációs készség (a fő munkanyelv)
Education: Informatikai, kiberbiztonsági, mesterséges intelligencia vagy kapcsolódó diploma, vagy azzal egyenértékű tapasztalat
Similar jobs

Job
Application Security Engineer (AppSec)
Bjakcareer
+4
💰 Salary: not specified
🌍 Remote
🗣️ EN

Job
Security Operations Engineer
CircleCI
AI/ML
+4
💰 Salary: not specified
🌍 Remote
Anywhere in the World
🗣️ EN
Job
Application Security Engineer II
Abnormal
AI/MLLlm
+3
$130,100–$187,000/yr
gross
🌍 Remote
Anywhere in the World
🗣️ EN

Job
Security Engineer, Institutional Trading
Blockchain.com
Llm
+2
💰 Salary: not specified
🏢 On-site
Paris
🗣️ EN

Job
Cybersecurity Engineer
10a Labs
+5
$135,000–$160,000/yr
gross
🌍 Remote
🗣️ EN

Job
Security Engineer, Public Sector
Scale AI
+2
$218,400–$342,000/yr
gross
🏢 On-site
St. Louis
🗣️ EN