Overview
Metaforms is looking for an AI Security & Platform Engineer to secure AI agents and the infrastructure behind them. This hands-on engineering role involves adversarial testing, vulnerability remediation, platform controls, automated evaluations, monitoring, and secure infrastructure improvements.
What you'll do
- Adversarially test AI agents for prompt injection, context poisoning, unsafe tool use, data leakage, memory manipulation, and unintended behavior.
- Identify security risks from customer prompts, uploaded files, retrieved content, external links, integrations, and model-generated outputs.
- Test whether agents can access unauthorized tools, records, tenants, credentials, or internal services.
- Threat-model AI features, agent workflows, model integrations, and tool-calling capabilities before production.
- Evaluate risks in RAG pipelines, context assembly, agent memory, system prompts, MCP servers, model providers, and third-party AI frameworks.
- Build adversarial evaluations, regression tests, security test harnesses, and reusable platform guardrails.
- Design controls for least-privilege tool access, scoped credentials, sandboxing, runtime policy enforcement, human approval, output validation, auditability, containment, and kill switches.
- Review customer-facing applications and APIs for authentication, authorization, tenant-isolation, injection, and business-logic vulnerabilities.
- Secure customer-controlled payloads, file uploads, webhooks, exports, and third-party integrations.
- Reproduce security reports, assess credible impact, distinguish exploitable vulnerabilities from theoretical findings, and implement production-ready fixes and regression tests.
- Perform focused code reviews, penetration tests, and architecture assessments for security-sensitive changes.
- Harden cloud permissions, service identities, secrets, storage, networking, deployment pipelines, and production access.
- Build security guardrails into CI/CD and infrastructure-as-code.
- Improve model-provider routing, retries, timeouts, fallbacks, quotas, rate limits, and cost controls.
- Add observability for model behavior, tool usage, data access, errors, latency, and token consumption.
- Support production debugging and investigate application, infrastructure, and AI-security incidents.
- Build trust-boundary models, prioritized testing plans, security tests, and visibility into model calls, tool usage, and agent behavior.
- Develop into a technical owner for AI security across the platform.
What you'll need
- 2–3 years of hands-on experience across AI engineering, backend/platform engineering, application security, infrastructure security, DevSecOps, or a related engineering role.
- Experience building, operating, or securing production AI systems using LLM APIs, agents, tool calling, RAG, model gateways, or similar technologies.
- Strong programming ability in Python, TypeScript, Go, or another relevant language.
- Understanding of common web and API security risks, including authentication, authorization, injection, tenant isolation, secrets, and unsafe data handling.
- Practical experience with cloud infrastructure, CI/CD, containers, monitoring, or infrastructure-as-code.
- Ability to investigate a suspected vulnerability, reproduce it, assess its real-world impact, and contribute an effective fix.
- Ability to reason about trust boundaries between users, models, customer data, application code, tools, and third-party services.
- Comfort debugging systems through source code, logs, traces, metrics, and database queries.
- Strong written communication and the ability to explain security risks clearly without unnecessary alarm.
- A builder’s mindset focused on implementing durable controls, not only identifying problems.
Nice to have
- Hands-on experience with AI red teaming or adversarial model testing.
- Familiarity with prompt injection, insecure output handling, tool-use vulnerabilities, agent sandboxing, or context leakage.
- Experience securing multi-tenant B2B SaaS products.
- Experience with OAuth, webhooks, file processing, MCP, and third-party integrations.
- Experience building security test harnesses, fuzzers, automated evaluations, or internal security tools.
- Familiarity with SAST, DAST, dependency scanning, secret scanning, or infrastructure scanning.
- Experience with model gateways, multi-provider routing, AI observability, or LLM evaluations.
- Participation in bug bounties, CTFs, security research, or relevant open-source projects.
- Familiarity with SOC 2 or ISO 27001 from an engineering implementation perspective.
Details
- Location: Bengaluru.
- The role works closely with engineering leadership on AI security and platform initiatives.
- The hiring process includes an introductory conversation, a technical discussion, a practical exercise involving an agent workflow and its trust boundaries, and a final conversation with engineering leadership.
Read the full description and apply on the company’s own careers page.