BrainCo
AI Application Security Engineer
About this role
Brain Co. seeks an AI Application Security Engineer to secure its AI products operating in regulated industries. You'll own application-layer security for agentic AI systems, build secure development practices, and use AI tooling to scale security reviews across a fast-moving engineering organization.
What you'll do
- Design and enforce secure development practices including authentication, authorization, secrets management, and secure-by-default standards
- Own security model for agentic products: agent scoping, authorization boundaries, and trust boundaries with external systems
- Define secure patterns for third-party API integrations, credential handling, and response validation
- Build automated security tooling and integrate security checks into CI/CD pipelines and code review processes
- Conduct threat modeling for product features and translate risks into concrete controls
- Define data protection standards for sensitive data (PHI, PII) flowing through AI pipelines
What they're looking for
- Application security and secure development practices
- Authentication/authorization (AuthN/AuthZ) design
- Threat modeling and risk assessment
- AI/ML security and agent security patterns
- Secure code review and SAST/security tooling
- Third-party API and integration security
- Data protection and privacy (regulated data handling)
- CI/CD and DevSecOps practices
Opens the application — the Jobs AI extension fills it for you. Set up autofill
Opens the official application on the employer’s site. No login required.
BrainCo
BrainCo builds and deploys cutting-edge AI and language model solutions for governments, healthcare systems, and critical infrastructure organizations. The company is hiring AI/ML engineers, backend platform engineers, AI platform engineers, and sales engineers to develop scalable infrastructure, production AI systems, and secure government contracts.
View all jobs at BrainCoLikely interview questions
- Walk us through how you'd approach securing an AI agent that has the ability to call external APIs and take actions on behalf of users — what are the key trust boundaries and authorization controls you'd implement at the application layer?
- Describe your experience building or integrating automated security tooling into CI/CD pipelines. How have you used automation or AI to scale security review across a codebase?