Forward Deployed Engineer, AI Security
Indexed description
The Forward Deployed Engineer, AI Security serves as a hands-on technical engineer embedded onsite with one of A10's largest financial services customers in Sunrise, Florida. You will sit directly with the customer's AI platform, model risk, and security engineering teams to operate and scale two critical disciplines: runtime AI firewall enforcement and adversarial model testing.
On the runtime side, you will deploy and operate inline inspection of AI traffic — prompts, responses, retrieval context, tool/MCP calls, and agent-to-agent exchanges — managing policies that determine what gets blocked, redacted, rewritten, or logged. On the testing side, you will build and run adversarial evaluation workflows that probe models, RAG pipelines, and agents before and after they reach production.
This role suits an intermediate-level engineer who bridges backend systems development, cloud infrastructure, and practical AI security.
Responsibilities
• AI Firewall and Runtime Enforcement
- Deploy, configure, and maintain inline AI traffic inspection across inference paths (self-hosted models, commercial APIs, RAG, and agents)
- Manage proxy topologies, TLS termination/SSLi, streaming/SSE response handling, and proxy routing across modern network stacks using tools like Envoy, NGINX, or HAProxy
- Implement and tune guardrail policies: prompt injection/jailbreak detection, PII/PCI/MNPI data leakage, grounding controls, and token rate limiting
- Enforce authorization, tool-use policies, and identity attribution across REST and gRPC endpoints to ensure every agentic action maps to a verified principal
- Monitor baseline false positive/negative rates, shadow-test policy updates, and manage inspection latency to meet production SLA budgets
• Adversarial Model Testing and Red Teaming
- Execute automated red team campaigns against models, vector databases (e.g., PostgreSQL with pgvector), and RAG pipelines covering injection, data extraction, poisoning, and cost-exhaustion risks
- Maintain versioned test suites and automated evaluation harnesses using Python and Go
- Integrate security testing gates directly into the customer’s MLOps, CI/CD, and dev pipelines
- Produce structured finding reports with clear reproduction steps, severity assessments, and concrete remediation steps (policy changes, system prompt updates, or infrastructure controls)
• Customer Collaboration & Product Feedback
- Collaborate daily with the customer's platform architects, model risk teams, and security leads on control selection and threat modeling.
- Map control coverage to common industry frameworks (OWASP Top 10 for LLMs, MITRE ATLAS, NIST AI RMF).
- Feed operational feedback, detection gaps, and bug reports back to A10 Product and Engineering teams to continuously improve the core product.
Required Qualifications
- Experience: 5–7 years of professional experience in software engineering, security engineering, cloud platform engineering, and technical solution delivery
- Programming Languages: Proficiency in Python and Go for building production-grade integrations, microservices, micro-benchmarks, and test automation harnesses
- Data & Middleware: Strong working knowledge of PostgreSQL (schema design, query optimization, indexing) and API architectures using REST and gRPC
- Cloud & DevOps: Hands-on experience deploying and managing workloads in at least one major cloud provider (AWS, GCP, or Azure), alongside containerization (Docker, Kubernetes) and CI/CD pipelines
- Networking & Traffic Management: Solid understanding of core networking concepts, L4/L7 traffic management, reverse proxies (e.g., Envoy, NGINX, HAProxy), TLS decryption/inspection, and networking diagnostics (e.g., tcpdump, wireshark, curl, dig)
- AI & Security Foundations: Practical understanding of LLM application stacks (RAG, vector databases, embeddings, tool-calling) and basic exposure to AI/LLM security risks (prompt injection, jailbreaking, data leakage)
- Delivery: Strong written and verbal communication skills with a track record of implementing technical solutions directly within enterprise environments
- Location: Ability to work onsite in Sunrise, FL on a regular, customer-embedded schedule.
- Education: Bachelor's degree in Computer Science, Software Engineering, Information Security, or equivalent practical experience
Preferred Qualifications
- Experience working within financial services or highly regulated environments (understanding of PCI DSS, GLBA, SOX, or model risk frameworks like SR 11-7)
- Prior experience in customer-embedded engineering, professional services, or technical field roles at an enterprise security software company
- Exposure to vector extensions in relational databases (e.g., pgvector in PostgreSQL) or specialized vector stores
- Hands-on experience with LLM guardrail frameworks, AI gateways, or red-teaming toolkits (e.g., Garak, PyRIT)
- Familiarity with A10 product suites, web application firewalls (WAAP), or ADC/SSLi technologies
- Industry certifications such as AWS/GCP/Azure Security or Developer Solutions Architect, Certified Kubernetes Administrator (CKA), or security certifications (e.g., Security+, OSCP)."
A10 Networks is an equal opportunity employer and a VEVRAA federal subcontractor. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability status, protected veteran status, or any other characteristic protected by law. A10 also complies with all applicable state and local laws governing nondiscrimination in employment.
#LI-AN1
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search