安全工程师-平台安全
Security Engineer - Platform Security
我们相信,人们与财务的互动方式将在未来几年大幅改善。我们致力于通过构建工具和体验来推动这一变革,成千上万的开发者使用这些工具来创建他们自己的产品。Plaid 为数以百万计的人们依赖的工具提供支持,帮助他们过上更健康的财务生活。我们与 Venmo、SoFi、多家财富 500 强公司以及许多大型银行合作,让人们能够轻松地将他们的财务账户连接到他们想要使用的应用和服务中。Plaid 的网络覆盖美国、加拿大、英国和欧洲的 12,000 家金融机构。公司成立于 2013 年,总部位于旧金山,纽约、西雅图、华盛顿特区、罗利、伦敦和阿姆斯特丹设有办事处。
平台安全团队(PlatSec)负责防御 Plaid 面临的攻击。我们负责笔记本电脑安全、云安全、AI 安全、检测与响应以及红队工作。目前我们正处于增长阶段。AI 扩展了 Plaid 的攻击面,快于大多数安全团队的适应速度,我们正在构建防护措施、身份控制和检测系统,以跟上节奏而不会影响业务进展。如果你喜欢解决尚未有人解决的问题,这就是你的团队。
职位简介
你将成为 Plaid 在 AI 安全方面的第一道防线。你会审查新的 AI 技术,在它们上线前发现安全风险,然后设计并实施关闭这些风险的控制措施。你将构建防护措施、身份管理及检测系统,使 Plaid 能够大胆使用 AI 而不被其伤害。
职责
- 在部署前后审查 AI 系统和集成的安全风险。
- 设计并部署防护措施、沙盒和其他控制措施,以限制 AI 代理的行为。
- 构建或实施系统来跟踪和管理 AI 身份,以便我们知道每个 AI 被授予了哪些访问权限,并能在风险与敏捷性之间取得平衡。
- 检测并缓解 Plaid AI 表面区域中的提示注入问题。
- 开展针对 AI 的安全审查,并设定其他团队需要遵循的标准。
- 你的影响:减少 AI 相关事件,加快 AI 上线速度,以及可扩展的控制措施。Plaid 希望在 AI 领域成为领导者,无论是在内部还是外部,而没有你,我们无法安全地做到这一点。
任职要求
必备条件:有实际经验保护 AI 技术,包括至少以下之一:
- 部署防护措施或沙盒,
- 管理 AI 身份,
- 检测或缓解
查看英文原文
We believe that the way people interact with their finances will drastically improve in the next few years. We’re dedicated to empowering this transformation by building the tools and experiences that thousands of developers use to create their own products. Plaid powers the tools millions of people rely on to live a healthier financial life. We work with thousands of companies like Venmo, SoFi, several of the Fortune 500, and many of the largest banks to make it easy for people to connect their financial accounts to the apps and services they want to use. Plaid’s network covers 12,000 financial institutions across the US, Canada, UK and Europe. Founded in 2013, the company is headquartered in San Francisco with offices in New York, Seattle, Washington D.C., Raleigh, London, and Amsterdam.
The Platform Security team (PlatSec) defends Plaid against attackers. We own laptop security, cloud security, AI security, detection and response, and red teaming. Right now we're in growth mode. AI has expanded Plaid's attack surface faster than most security teams can adapt, and we're building the guardrails, identity controls, and detection systems to keep pace without slowing the business down. If you like solving problems nobody's solved yet, this is that team.
About the role
You'll be Plaid's first line of defense on AI security. You'll review new AI technologies to find security risks before they ship, then design and implement the controls that close them. You'll build the guardrails, identity management, and detection systems that let Plaid use AI aggressively without getting burned.
Responsibilities
- Review AI systems and integrations for security risk before and after deployment.
- Design and deploy guardrails, sandboxes, and other controls that contain what AI agents can do.
- Build or implement systems to track and manage AI identities, so we know what access every AI has been granted and can balance risk with agility.
- Detect and mitigate prompt injection across Plaid's AI surface area.
- Run AI-focused security reviews and set the bar other teams build to.
- Your impact: fewer AI-related incidents, faster AI shipping, and controls that scale. Plaid wants to be a leader in AI, internally and externally, and we can’t do that safely without you.
Qualifications
Must-have: hands-on experience securing AI technologies, including at least one of:
- deploying guardrails or sandboxes,
- managing AI identities,
- detecting or mitigating prompt injection,
- running AI security reviews, or
- implementing AI security tooling (built or bought).
- Nice-to-haves:
- Experience at a frontier AI lab or on a security team defending production AI systems at scale.
- Experience on a Infrastructure Security, Cloud Security, Platform Security, Corporate Security, Security Operations (SecOps), and/or Detection & Response team
- Software security review, SDLC, vulnerability discovery, and/or offensive security experience
Our mission at Plaid is to unlock financial freedom for everyone. To support that mission, we seek to build a diverse team of driven individuals who care deeply about making the financial ecosystem more equitable. We recognize that strong qualifications can come from both prior work experiences and lived experiences. We encourage you to apply to a role even if your experience doesn't fully match the job description. We are always looking for team members that will bring something unique to Plaid!
Plaid is proud to be an equal opportunity employer and values diversity at our company. We do not discriminate based on race, color, national origin, ethnicity, religion or religious belief, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender, gender identity, gender expression, transgender status, sexual stereotypes, age, military or veteran status, disability, or other applicable legally protected characteristics. We also consider qualified applicants with criminal histories, consistent with applicable federal, state, and local laws. Plaid is committed to providing reasonable accommodations for candidates with disabilities in our recruiting process. If you need any assistance with your application or interviews due to a disability, please let us know at accommodations@plaid.com.
Please review our Candidate Privacy Notice here https://plaid.com/legal/#candidate-privacy-notice.
Additional compensation in the form(s) of equity and/or commission are dependent on the position offered. Plaid provides a comprehensive benefit plan, including medical, dental, vision, and 401(k). Pay is based on factors such as (but not limited to) scope and responsibilities of the position, candidate's work experience and skillset, and location. Pay and benefits are subject to change at any time, consistent with the terms of any applicable compensation or benefit plans.