首席工程师,AI/ML安全
Principal Engineer, AI/ML Security
在DigitalOcean开启职业生涯中最出色的工作。与一支由顶尖人才组成的强大社区并肩前行,他们不断追求打造最简单、可扩展的云服务。如果你有成长型思维,自然喜欢大胆思考,并且被真正行业颠覆者的快节奏环境所激励,你将在这里找到属于自己的位置。我们重视共同成功——在学习中、在乐趣中,为世界上的梦想家和建设者带来深远的影响。
### **我们正在寻找一位高级工程师,专注于AI/ML安全领域,对保护AI系统和在云规模上实现ML驱动的安全性充满热情。**
在这个职位中,你将向VP、副首席信息安全官汇报,并与安全数据科学和安全领导团队紧密合作。你将主导DigitalOcean与外部AI安全社区的互动,并作为我们内部专家和所有AI相关安全风险的升级处理点。
### **你将负责:**
- 与产品安全和工程领导合作,定义AI安全控制如何集成到DigitalOcean的面向客户的产品中。
- 与安全数据科学和安全工程团队合作,构建、部署并维护内部AI/ML模型、防护机制、工具和自动化流程。参与已部署模型的持续监控,检测偏差,评估性能,并与模型相关方一起规划和实施改进。
- 主导对抗测试和AI红队工作,包括越狱测试、提示注入、规避和中毒测试。
- 主导主要AI产品计划的安全评审,从设计到发布阶段,提供架构批准和对高风险决策的升级指导。
- 跨AI生命周期进行威胁建模:数据摄入、训练/微调、评估、模型服务、RAG、代理框架以及部署后监控。
- 主导并推动DigitalOcean的AI安全策略和多年路线图,明确我们的投资方向、优先考虑的风险以及随着威胁环境和产品组合的变化,AI安全如何演进。
- 架构并领导AI风险与治理框架:建立政策、标准和控制措施,以负责任的方式开发、部署和监控DigitalOcean和Cloudways的AI/ML系统。
- 在高管和董事会层面代表AI安全;向CISO和高级管理层清晰地传达风险状况、项目进展和战略决策。
查看英文原文
Dive in and do the best work of your career at DigitalOcean. Journey alongside a strong community of top talent who are relentless in their drive to build the simplest scalable cloud. If you have a growth mindset, naturally like to think big and bold, and are energized by the fast-paced environment of a true industry disruptor, you’ll find your place here. We value winning together—while learning, having fun, and making a profound difference for the dreamers and builders in the world.
### **We are looking for a Principal Engineer, AI/ML Security who is passionate about securing AI systems and operationalizing ML-powered security at cloud scale.**
In this role, you will report to the VP, Deputy CISO and partner closely with Security Data Science and Security leadership teams. You will lead DigitalOcean’s engagement with the external AI security community and serve as our internal expert and escalation point for all AI-related security risk.
### **What You’ll Do:**
- Partner with Product Security and Engineering leadership to define how AI security controls are integrated into DigitalOcean’s customer-facing products.
- Partner with Security Data Science and Security Engineering to build, deploy, and serve in-house AI/ML models, guardrails, tooling, and automations. Participate in ongoing monitoring of deployed models to detect drift, evaluate performance, and plan and implement improvements alongside model stakeholders.
- Lead adversarial testing and AI red teaming, including jailbreaking, prompt-injection, evasion, and poisoning testing.
- Lead security reviews of major AI product initiatives from design through launch, providing architectural sign-off and escalation guidance for high-risk decisions.
- Threat modeling across the AI lifecycle: data ingestion, training/fine-tuning, evaluation, model serving, RAG, agent frameworks, and post-deployment monitoring
- Own and drive DigitalOcean’s AI Security strategy and multi-year roadmap, defining where we invest, what risks we prioritize, and how AI security evolves as the threat landscape and product portfolio change.
- Architect and lead the AI Risk & Governance framework: establishing policies, standards, and controls for the responsible development, deployment, and monitoring of AI/ML systems across DigitalOcean and Cloudways.
- Represent AI security at executive and board-level briefings; communicate risk posture, program progress, and strategic decisions to the CISO and senior leadership in clear, business-contextualised terms.
- Define DigitalOcean’s position on emerging AI security topics including agentic AI, model supply chain risk, synthetic data integrity, and AI-enabled social engineering.
### **What You’ll Add to DigitalOcean:**
- 10+ years of experience in cybersecurity, with at least 4–5 years focused on AI/ML security, adversarial machine learning, or security data science in a production cloud or technology environment.
- Demonstrated track record of defining and driving AI or security programs at an organizational level — not just executing within them. You have owned a strategy, not just implemented one.
- Deep, practitioner-level knowledge of adversarial ML attack and defence: evasion, poisoning, model extraction, membership inference, and prompt injection at both conceptual and implementation depth.
- Ability to read, evaluate, and synthesise academic AI security research and translate it into concrete engineering guidance and organizational policy.
- Experience engaging executive and senior leadership audiences on technical risk: you can translate complex AI threat scenarios into business-level impact and justify investment decisions accordingly.
- Strong programming skills in Python and Go with a track record of building security tooling and automation, not just reviewing others' code. You can stand up adversarial testing, detection, and guardrail capabilities yourself.
- Proficiency reviewing and critiquing AI/ML system architecture (data ingestion, feature engineering, training pipelines, model serving, continuous monitoring) made by ML engineers and data scientists.
- Hands-on experience with AI red-team and defensive tooling and with model supply-chain frameworks.
- Bachelor’s or Master’s degree in Computer Science, Information Security, Mathematics, or a related field — or equivalent depth of practical experience.
- Fluency in OWASP LLM Top 10, MITRE ATLAS, NIST AI RMF, ISO/IEC 42001, and the EU AI Act.
- Prior experience in a cloud provider, security product company, or large-scale internet platform where AI/ML systems operate at significant customer-facing scale.
- Familiarity with LLM security in production: securing RAG pipelines, agentic frameworks, and model APIs against prompt injection, jailbreaking, and data exfiltration.
### **Compensation Range:**
- $230,400 - $288,000
*This is a remote role
JR: 2026-7824
_#LI-Remote_
### **Why You’ll Like Working for DigitalOcean**
- **We innovate with purpose.** You’ll be a part of a cutting-edge technology company with an upward trajectory, who are proud to simplify cloud and AI so builders can spend more time creating software that changes the world. As a member of the team, you will be a Shark who thinks big, bold, and scrappy, like an owner with a bias for action and a powerful sense of responsibility for customers, products, employees, and decisions.
- **We prioritize career development.** At DO, you’ll do the best work of your career. You will work with some of the smartest and most interesting people in the industry. We are a high-performance organization that will always challenge you to think big. Our organizational development team will provide you with resources to ensure you keep growing. We provide employees with reimbursement for relevant conferences, training, and education. All employees have access to LinkedIn Learning's 10,000+ courses to support their continued growth and development.
- **We care about your well-being.** Regardless of your location, we will provide you with a competitive array of benefits to support you from our Employee Assistance Program to Local Employee Meetups to flexible time off policy, to name a few. While the philosophy around our benefits is the same worldwide, specific benefits may vary based on local regulations and preferences.
- **We reward our employees.** The salary range for this position is based on market data, relevant years of experience, and skills. You may qualify for a bonus in addition to base salary; bonus amounts are determined based on company and individual performance. We also provide equity compensation to eligible employees, including equity grants upon hire and the option to participate in our Employee Stock Purchase Program.
- **DigitalOcean is an equal-opportunity employer.** We do not discriminate on the basis of race, religion, color, ancestry, national origin, caste, sex, sexual orientation, gender, gender identity or expression, age, disability, medical condition, pregnancy, genetic makeup, marital status, or military service.
**Application Limit:** You may apply to a maximum of 3 positions within any 180-day period. This policy promotes better role-candidate matching and encourages thoughtful applications where your qualifications align most strongly.