application security engineer
генерация резюме под вакансию
сопроводительное письмо
описание
Capital.com is a financial services company advancing the digital assets movement through a rapidly expanding platform.
задачи
- Design and implement security controls for AI/ML systems across development, training, and production;
- Secure LLM integrations, RAG pipelines, and AI APIs;
- Conduct threat modeling for AI systems and data pipelines;
- Define secure-by-design patterns for AI-powered features;
- Identify and mitigate AI-specific threats, including prompt injection, jailbreak techniques, model poisoning, data contamination, adversarial attacks, training data leakage, insecure model serialization, and excessive permissions in AI agents;
- Develop guardrails, content filters, and output validation mechanisms;
- Implement monitoring for anomalous AI behavior;
- Integrate AI security checks into CI/CD pipelines;
- Perform security reviews of ML code and AI-related infrastructure;
- Secure model registries and artifact storage;
- Collaborate with engineers and platform teams to enforce security standards;
- Ensure AI systems comply with GDPR, data privacy regulations, and financial industry regulatory requirements;
- Implement controls for sensitive data used in training and inference;
- Perform AI risk assessments aligned with internal risk methodology;
- Contribute to AI security standards and internal policies;
- Define AI risk classification and control frameworks;
- Support security reviews for new AI initiatives and tools.
требования
- 3–5+ Years of experience in software engineering, ML engineering, or application security;
- Hands-on experience with AI/ML systems, including LLMs or NLP models;
- Python proficiency for automation and scripting;
- Experience working with Claude Code;
- Strong understanding of AWS, Azure, or GCP;
- Experience with API security, Docker, and Kubernetes;
- Knowledge of AI-specific security risks and mitigations;
- Experience conducting threat modeling and risk assessments;
- Strong analytical and problem-solving skills;
- Ability to translate technical risk into business impact;
- Ability to explain AI security risks and mitigations to non-security teams;
- Experience collaborating cross-functionally with ML, data, and product teams;
- Clear documentation and communication skills;
- Nice to have: familiarity with RAG architectures, vector databases, and ML pipelines such as MLflow, Kubeflow, and SageMaker; experience in fintech or regulated environments; knowledge of AI governance frameworks including EU AI Act, NIST AI RMF, and ISO/IEC 42001; experience with AI red teaming; cybersecurity or application security background including OWASP and Secure SDLC.
условия
- Competitive salary;
- Annual leave;
- Employee referral program;
- Medical insurance and pension plans;
- Location-specific benefits and perks;
- 30 Extra days to work remotely from anywhere in the world, with some restrictions;
- Two additional paid volunteer days each year;
- No conditions specified.
навыки
Если просят войти через iCloud, отправить коды из SMS, запустить код, что-то установить, перевести деньги или сделать что угодно, связанное с деньгами, не соглашайтесь: это признаки мошенничества.