[![Image]() Meet Jobicy Copilot — free AI autofill for job applications + remote job alerts ›](#)   [All remote jobs](https://jobicy.com/jobs.md)Open role[![Rithum logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/fe3986d8-221-1.jpeg)](https://jobicy.com/company/rithum.md)Remote opportunity at[Rithum](https://jobicy.com/company/rithum.md)

# Staff Information Security Engineer – AI First

Review the role, location requirements, compensation details, and application process before deciding whether this opportunity fits your next career move.

[Apply for this job](#job-application)[View company](https://jobicy.com/company/rithum.md)Share12 Sep 2026Published62Listing views7Application actions12 Oct 2026Apply before  Opportunity details

## About this role.

AI SummaryThis Staff Information Security Engineer role leads the design and automation of security controls for an AI-first commerce platform and workforce. The position combines cloud, identity, application, and AI/LLM security, with responsibility for policy-as-code, threat modeling, vendor risk, and security-tool integration. The engineer will build preventive controls and AI-assisted security workflows while governing agent identities, model access, prompt injection, and data-handling risks. Success requires autonomous technical judgment, strong collaboration with Platform Engineering and IT, and the ability to translate emerging AI threats into enforceable safeguards. It is a senior hands-on individual-contributor role with broad security architecture and operational influence.

## Role DNA

A quick view of the complexity, pace, ownership and collaboration implied by the job description.

### Job Complexity

5/5EasyHard

### Pace & Pressure

5/5RelaxedFast-paced

### Autonomy Level

5/5GuidedFull ownership

### Communication Load

5/5IndependentCollaborative

AI insightThe role requires deep, cross-functional expertise spanning AI/LLM threat models, cloud security, IAM, application security, automation, and governance frameworks. It also demands independent prioritization and the ability to turn ambiguous AI risks into practical, scalable controls in a fast-moving environment.

## Salary analysis

Estimated compensation compared with the broader US market for similar roles.

Estimated job medianMarket rate$195,000US market range$170k–$230k0$253k

AI insightThe disclosed U.S. annual base-pay range is $170,000 to $220,000, producing a job median of $195,000. A competitive U.S. market base-salary range for a staff-level AI security engineer is estimated at $170,000 to $230,000 annually; the stated offer is well aligned with this market range. The separate 12% discretionary bonus and benefits are not included in the base-salary calculation.

## Core skills

Skills and capabilities most closely associated with this opportunity.

[AI security](https://jobicy.com/jobs?search_keywords=AI%20security.md)[LLM security](https://jobicy.com/jobs?search_keywords=LLM%20security.md)[Cloud security](https://jobicy.com/jobs?search_keywords=Cloud%20security.md)[AWS](https://jobicy.com/jobs?search_keywords=AWS.md)[Identity and access management](https://jobicy.com/jobs?search_keywords=Identity%20and%20access%20management.md)[Infrastructure as code](https://jobicy.com/jobs?search_keywords=Infrastructure%20as%20code.md)[Terraform](https://jobicy.com/jobs?search_keywords=Terraform.md)[Policy as code](https://jobicy.com/jobs?search_keywords=Policy%20as%20code.md)[Threat modeling](https://jobicy.com/jobs?search_keywords=Threat%20modeling.md)[Security automation](https://jobicy.com/jobs?search_keywords=Security%20automation.md)

Sample interview questionsHow would you design controls to reduce prompt-injection risk in an LLM-powered product?I would start with threat modeling the full data and tool flow, separating trusted system instructions from untrusted content. Controls would include strict tool allowlists, least-privilege service identities, input provenance labeling, output validation, retrieval access controls, sandboxed tool execution, and monitoring for suspicious prompts or actions. High-impact actions would require human approval and auditable decision records.

Describe how you would implement security policy-as-code across a multi-account AWS environment.

I would establish organization-level preventive guardrails using AWS Organizations and SCPs, then use Terraform for standardized account and platform configuration. OPA/Rego or equivalent policies would run in pull requests and deployment pipelines to detect noncompliant infrastructure before release. I would also combine preventive checks with CSPM monitoring, exception workflows, ownership, and remediation SLAs.

How would you secure non-human and AI-agent identities?

Each agent should have a unique, purpose-bound identity with short-lived credentials, narrowly scoped permissions, and explicit boundaries on accessible data and tools. I would avoid shared secrets, use a managed secrets solution and workload identity where possible, and require approval gates for sensitive actions. Continuous logging, access reviews, behavioral monitoring, and fast credential revocation are essential to limit blast radius.

What is your approach to integrating SIEM, CSPM, and application-security findings with LLM capabilities?

I would use LLMs to enrich, correlate, summarize, and prioritize findings rather than grant them unrestricted authority to act. The integration should preserve source evidence, apply data-minimization and redaction controls, and route recommended remediation through deterministic workflows or human approval. I would measure quality through false-positive rates, time to triage, remediation outcomes, and security-review feedback.

How do you balance a business team's need to adopt an AI vendor quickly with third-party risk requirements?

I would identify the intended data flows, model usage, retention practices, subprocessors, identity controls, and contractual protections, then assess the vendor against the risk tier. If gaps exist, I would propose compensating controls such as limiting data classes, disabling training on customer data, using SSO and audit logs, or constraining the initial deployment. The goal is to document residual risk clearly and enable a safe, time-bounded path forward rather than simply blocking adoption.

Rithum™ is the world’s most trusted commerce network, accelerating how brands, suppliers, and retailers work together to deliver seamless e-commerce experiences. We provide an unmatched platform for brands and retailers, enabling them to accelerate growth, optimize operations across channels, scale product offerings and enhance margins.

Today, more than 40,000 companies trust Rithum to grow their business across hundreds of channels, representing over $50 billion in annual GMV. Using our commerce, marketing, and delivery solutions, our customers create optimized consumer shopping journeys from beginning to end.

Overview

Rithum expects employees across all roles to leverage AI and technology to improve efficiency, streamline workflows, and create scalable ways of working.

Rithum is embedding AI into every corner of how it operates — and security is no exception.

As a Staff AI-First Information Security Engineer, you own the intersection of AI adoption and information security: designing guardrails for AI-powered products, building automated security tooling, designing security controls and monitoring for an AI-First workforce, helping every team at Rithum move fast without creating risk they cannot see. This is not a typical security role. You spend as much time building and automating as you do reviewing, turning a repeating control into infrastructure-as-code, a manual review into a workflow, and a vague AI risk into a concrete, enforced guardrails. You work autonomously, balancing research with fast-paced delivery, and collaborating closely with Platform Engineering, IT, Security Champions, and external auditors.

Responsibilities

* Act as the bridge between architectural intent and operational reality; mediate conflicts between security requirements and feasible implementation, propose compensating controls where gaps exist and help register, track and remediate residual risks.
* Implement preventive, default-on security controls across cloud and enterprise environments, codified as policy- and infrastructure-as-code so security is enforced by design, including controls that govern how AI tools and models may be used.
* Implement and enforce identity and access controls to an agreed standard, including access boundaries for AI systems and non-human/agent identities by partnering with Platform Engineering and IT to align tooling and policy to the architecture.
* Assist in maintaining the InfoSec risk register; track emerging threats and translate them into actionable guidance for engineering teams.
* Support third-party and vendor risk assessments, with a focus on vendors who process data through AI pipelines.
* Automate repetitive security workflows (evidence collection, access reviews, alert enrichment) and build or operate AI-assisted security agents — with human-in-the-loop approval gates, least-privilege credentials, and explicit attention to each agent’s own blast radius.
* Integrate security tooling (SIEM, CSPM, DAST/SAST, vulnerability scanners) with LLM layers to surface actionable insight and automated responses.
* Define and enforce security requirements for AI-powered features: model access controls, prompt-injection mitigations, output validation, and data-handling boundaries.
* Conduct threat modelling on agentic and LLM-based systems, accounting for novel attack surfaces such as tool misuse, indirect prompt injection, and supply chain risk.

Qualifications

Minimum Qualifications

* 5+ years of security engineering experience with demonstrated AI/ML security depth (prompt injection, model supply chain, adversarial inputs, RAG).
* Experience using AI tools (ChatGPT, Copilot, Claude, etc.) and LLM frameworks and APIs (OpenAI, Anthropic, LangChain, or similar) to accelerate and elevate your work.
* Hands-on identity and access expertise across modern enterprise and cloud identity stacks, including access models for AI systems and non-human identities.
* Infrastructure and policy-as-code (e.g. Terraform, OPA/Rego) and proficiency in a scripting language for automation (Python preferred).
* Cloud security expertise: AWS Solutions Architect / Security Specialty or equivalent demonstrated expertise, including multi-account governance, preventive guardrails, and policy-as-code.
* Application security (OWASP Top 10 and the OWASP LLM/GenAI Top 10, secure SDLC) and threat-modelling methodologies (STRIDE, PASTA, or equivalent). Practical experience building or operating AI agents, and integrating security tooling (SIEM, CSPM, SAST/DAST/SCA) so it surfaces action rather than raw alerts.
* Working knowledge of SOC 2 and/or ISO 27001 control frameworks.

Preferred Qualifications

* Experience building or operating AI agents in a production environment.
* Awareness of privacy regulation (GDPR/CCPA) as it touches AI including privacy-by-design and DPIAs.
* Red teaming or adversarial ML research backgrounds.
* Experience implementing privileged-access, key-management, posture-management, or data-protection programs.
* Experience with EDR, CASB, DLP, Security automation and SAST, DAST, IAST and SCA tools.
* Cloud Architecture or Security certifications (CCSK, TAISE, AWS).

Travel Required
Up to 10%

Other Duties

Please note this job description is not designed to cover or contain a comprehensive listing of activities, duties or responsibilities required of the employee for this job. Duties, responsibilities, and activities may change at any time with or without notice.

What it’s like to work at Rithum

When you join Rithum, you can expect to work with smart risk-takers, courageous collaborators, and curious minds.

As part of the Rithum team, you are valued, supported, and included. Guided by a transparent culture and accessible, approachable leadership, we offer career opportunities aligned to your ambitions and talents. To ensure work and life balance works for you, we also offer an array of resources to support you and your families, including comprehensive benefits and wellness plans.

At Rithum you will:

* Partner with the leading brands and retailers.
* Connect with passionate professionals who will help support your goals.
* Participate in an inclusive, welcoming work atmosphere.
* Achieve work-life balance through remote-first working conditions, generous time off, and wellness days.
* Receive industry-competitive compensation and total rewards benefits.

We believe in transparency and fairness in our compensation practices.

For this position, the expected base pay range is: $170,000-$220,000 per year.

This range represents the base pay for the role across all U.S. locations and is determined based on market data, internal equity, and experience. Final compensation may vary depending on geographic location, skills, and relevant experience.In addition to base pay, we offer a discretionary bonus for non-sales roles, a comprehensive benefits package, and, where applicable, sales incentives.

For this position, the expected discretionary bonus is 12% of the annual base salary.

Benefits

* Medical, dental and vision benefits: Affordable health care plans and company HSA contributions, starting on Day 1
* A 6% 401(k) match
* Competitive time off package with 20 days of Paid Time Off, 9 Company-Paid holidays, 2 paid floating holidays, 7 paid sick days, 2 Wellness days, and 1 Paid Volunteer Day; at 3 years of service PTO increases to 22 days, and at 5 years it increases to 25 days
* 12 weeks primary caregiver leave & 4 weeks secondary caregiver leave
* Accident, critical illness, and hospital indemnity insurance
* Pet insurance
* Legal assistance and identity theft insurance plans
* Life insurance 2x salary
* Access to the Calm app and the Employee Assistance Program
* $65/month Remote work stipend for internet
* Culture and team-building activities
* Tuition assistance
* Career development opportunities
* Charitable contribution match up to $250 per year

Rithum is an equal opportunity employer. We are committed to providing an environment of mutual respect where equal employment opportunities are available to all applicants and teammates without regard to race, religion, color, sex, gender identity, sexual orientation, age, non-disqualifying physical or mental disability, national origin, veteran status or any other protected characteristic. All employment is decided on the basis of qualifications, merit, and business need.

We’re committed to providing reasonable accommodations in accordance with the law for qualified applicants. If you require assistance during the interview process due to a medical condition or need support accessing our website or completing the application process, please reach out to us by completing the [Accommodations Request Form](https://forms.office.com/r/v1qDcUpHLw). Your comfort and accessibility are important to us, and we’re here to ensure a seamless experience as you explore opportunities with our team.

Show more

[Apply now >](https://jobicy.com/jobs/153112-staff-information-security-engineer-ai-first.md)

*

![Upload CV](data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI2NSIgaGVpZ2h0PSI2NSIgZmlsbD0ibm9uZSIgeG1sbnM6dj0iaHR0cHM6Ly92ZWN0YS5pby9uYW5vIj48ZyBjbGlwLXBhdGg9InVybCgjQSkiPjxwYXRoIGQ9Ik0wIDBINjVWNjVIMFYwWiIgZmlsbD0iIzAyOWFlYiIvPjxnIGZpbGw9IiNmZmYiIHN0cm9rZT0iI2ZmZiIgc3Ryb2tlLXdpZHRoPSIyIj48cGF0aCBkPSJNMzMuMDQ5IDE1LjQ1NGExLjQzIDEuNDMgMCAwIDAtMi4wOTcgMGwtNy41NzkgOC4xNDdhMS4zOCAxLjM4IDAgMCAwIC4wOSAxLjk3MyAxLjQ0IDEuNDQgMCAwIDAgMi4wMDgtLjA4OGw1LjEwOS01LjQ5MnYyMC42MWExLjQxIDEuNDEgMCAwIDAgMS40MjEgMS4zOTdjLjc4NSAwIDEuNDIxLS42MjUgMS40MjEtMS4zOTd2LTIwLjYxbDUuMTA5IDUuNDkyYTEuNDQgMS40NCAwIDAgMCAyLjAwOC4wODggMS4zOCAxLjM4IDAgMCAwIC4wOS0xLjk3M2wtNy41NzktOC4xNDZ6TTE2Ljc2OSAzOC40YzAtLjc3My0uNjItMS40LTEuMzg1LTEuNFMxNCAzNy42MjcgMTQgMzguNHYuMTAybC4yMTUgNi4yMjljLjIyMyAxLjY4LjcwMSAzLjA5NSAxLjgxMyA0LjIxOHMyLjUxIDEuNjA3IDQuMTcyIDEuODMzYzEuNi4yMTggMy42MzYuMjE4IDYuMTYuMjE4aDExLjI4bDYuMTYtLjIxOGMxLjY2Mi0uMjI2IDMuMDYxLS43MDkgNC4xNzItMS44MzNzMS41ODktMi41MzggMS44MTMtNC4yMThDNTAgNDMuMTEzIDUwIDQxLjA1NSA1MCAzOC41MDNWMzguNGMwLS43NzMtLjYyLTEuNC0xLjM4NS0xLjRzLTEuMzg1LjYyNy0xLjM4NSAxLjRsLS4xOSA1Ljk1OGMtLjE4MiAxLjM3LS41MTUgMi4wOTUtMS4wMjYgMi42MTJzLTEuMjI4Ljg1My0yLjU4MyAxLjAzOGMtMS4zOTUuMTktMy4yNDMuMTkzLTUuODkzLjE5M0gyNi40NjJjLTIuNjUgMC00LjQ5OC0uMDAzLTUuODkzLS4xOTMtMS4zNTUtLjE4NC0yLjA3Mi0uNTIxLTIuNTgzLTEuMDM4cy0uODQ0LTEuMjQyLTEuMDI2LTIuNjEyYy0uMTg3LTEuNDEtLjE5MS0zLjI3OS0uMTkxLTUuOTU4eiIvPjwvZz48L2c+PGRlZnM+PGNsaXBQYXRoIGlkPSJBIj48cGF0aCBmaWxsPSIjZmZmIiBkPSJNMCAwaDY1djY1SDB6Ii8+PC9jbGlwUGF0aD48L2RlZnM+PC9zdmc+)

### Upload your resume now

To unlock remote work opportunities and be discovered by global employers.

This job listing has been manually reviewed by the Jobicy Trust & Safety Team for compliance with our posting guidelines, including verification of the company's legitimacy, accuracy of job details, clarity of remote work policy, and absence of misleading or fraudulent content.

Next step

## Apply now.

Follow the employer’s application method and review Jobicy’s safety guidance before sharing personal information.

Keep exploring

## Related remote jobs.

Matched by job category10 related opportunities[Cybersecurity](https://jobicy.com/categories/cybersecurity.md) [Browse all jobs](https://jobicy.com/jobs.md)
*
![1Password logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2020/09/WRILS-200909195848-296323.png)
1Password  Sep 12

### [Manager, Security Incident Response](https://jobicy.com/jobs/153123-manager-security-incident-response.md)

1Password is growing. We’ve surpassed $400M in ARR and we’re continuing to accelerate, earning a spot on the Forbes Cloud 100 for four years in a row and teaming up…

*
![Sporty Group logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/8e6c246a-221.png)
Sporty Group  Sep 12

### [Offensive Security Engineer](https://jobicy.com/jobs/149060-offensive-security-engineer.md)

About the roleMission Strengthen Sporty’s offensive security posture by proactively testing and identifying vulnerabilities across our external perimeter, standalone virtual private servers (VPS), physical office infrastructure, and endpoint defenses. The…

*
![Liftoff logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/c47aea9f-221.png)
Liftoff  Sep 12

### [Security Engineer, Detection & Response](https://jobicy.com/jobs/153102-security-engineer-detection-response.md)

Liftoff is a leading AI-powered performance marketing platform for the mobile app economy. Our end-to-end technology stack helps app marketers acquire and retain high-value users, while enabling publishers to maximize…

*
![Stripe logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2020/10/WRILS-201011073943-272457.png)
Stripe  Sep 11

### [Abuse Research Engineer](https://jobicy.com/jobs/153053-abuse-research-engineer.md)

Who we are About Stripe Stripe is a financial infrastructure platform for businesses. Millions of companies—from the world’s largest enterprises to the most ambitious startups—use Stripe to accept payments, grow…

*
![Ping Identity logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/09/63e8d5a6-221.png)
Ping Identity  Sep 11

### [Cyber Security Engineer II](https://jobicy.com/jobs/153056-cyber-security-engineer-ii.md)

About Ping Identity: At Ping Identity, we believe in making digital experiences both secure and seamless for all users, without compromise. We call this digital freedom. And it’s not just…

*
![Luna Physical Therapy logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2026/07/fcb34e841928-221.webp)
Luna Physical Therapy  Sep 11

### [Director , Information Security and IT](https://jobicy.com/jobs/153041-director-information-security-and-it.md)

Luna is seeking a Director of Information Security & IT to lead the strategy, execution, and continuous evolution of the company’s enterprise technology and information security programs. Reporting to the…

*
![CertiK logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2021/03/Jobicy-210308091023-955845.jpg)
CertiK  Sep 10

### [Blockchain Security Expert Intern – AI Track](https://jobicy.com/jobs/152979-blockchain-security-expert-intern-ai-track.md)

About the Company Founded in 2018 by professors of Yale University and Columbia University, CertiK is a pioneer in blockchain security, utilizing best-in-class AI technology to secure and monitor blockchain…

*
![CertiK logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2021/03/Jobicy-210308091023-955845.jpg)
CertiK  Sep 10

### [Blockchain Security Expert – Security Audit Track](https://jobicy.com/jobs/152975-blockchain-security-expert-security-audit-track.md)

About You You’re a self-starter. You believe in tackling the most important problems, even if they are the most difficult problems. You’re comfortable with the unknown and understand that #startuplife…

*
![CertiK logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2021/03/Jobicy-210308091023-955845.jpg)
CertiK  Sep 10

### [Blockchain Security Expert – Chain Security Evaluation Track](https://jobicy.com/jobs/152970-blockchain-security-expert-chain-security-evaluation-track.md)

About You You’re a self-starter who thrives on tackling the toughest and most meaningful problems, even if they are the most difficult problems. You’re comfortable with the unknown and understand…

*
![Synthesia logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2026/06/c69aad11-221.webp)
Synthesia  Sep 10

### [SecOps Security Engineer (Staff-level, L6)](https://jobicy.com/jobs/152968-secops-security-engineer-staff-level-l6.md)

Synthesia is the world’s leading AI video platform for business, used by over 90% of the Fortune 100. Founded in 2017, the company is headquartered in London, with offices and…