Senior AI Security Engineer
Firmus · Sydney, Australia
Skills in this posting
The posting
Firmus Technologies
Firmus Technologies is a global leader pioneering the development and operation of efficient AI infrastructure across Asia Pacific.
Founded in Australia in 2019, our mission is to create the most efficient AI infrastructure by combining cutting-edge technology with a steadfast commitment to sustainability.
At Firmus, we are unique in our approach. We design, build, and operate a new class of digital infrastructure – the AI Factory. Through our model-to-grid technology approach, we have pushed the boundaries of multi-generational liquid cooling systems, energy management, AI software orchestration, and construction. For our customers, this approach allows us to make every watt count and deliver low-cost AI tokens globally.
Firmus AI Cloud
Our large-scale GPU cloud platform, Firmus AI Cloud, is purpose-built to deliver energy-efficient AI compute at scale to customers.
It empowers developers, enterprises, educational institutions, and government users to train and deploy AI models with unmatched efficiency and cost savings. With an ever-growing suite of services and applications, we are committed to delivering a cloud experience that is market-leading, proprietary, and built to scale.
Why Firmus?
As an NVIDIA Cloud and Engineering partner in Asia Pacific, you will gain skills, experience, and exposure across the AI industry and be part of shaping what this industry looks like for decades to come.
We are founder-led, not a big corporate. Decisions happen fast, our leaders are accessible, and there's minimum bureaucracy between you and the work. Ownership comes early. Whatever your role, you will have a direct line to outcomes, helping shape how the business grows as we scale nationally across a long-term, large-scale roadmap.
Work alongside founders and experts in AI infrastructure, energy systems and next-generation compute.
What we build here has impact beyond the business. Our AI Factories are designed to operate as assets to the energy grid to actively strengthen the communities and regions they operate in rather than drawing from them.
Considering applying? You don't need a perfect background to join our team. If you're driven and curious, there's a path for you. We back our people to grow into new domains and take on challenges beyond their previous experience.
ROLE SUMMARY
The Senior AI Security Engineer - AI Products & Applications will be embedded within the AI & Applications team to enable the secure design, development, release, and operation of AI products and applications.
The role works directly with AI engineers, application engineers, product managers, inference engineers, DevOps, and platform teams to build practical security controls into agentic workflows, retrieval-augmented generation (RAG), model-serving APIs, enterprise-data integrations, and user-facing AI experiences.
This is a product- and application-oriented security role. The engineer will help teams deliver trusted AI features without unnecessarily slowing innovation, while ensuring that AI products protect customer, enterprise, and operational data.
The role reports operationally to the Head of AI & Applications, with a dotted-line reporting relationship to the Head of Cybersecurity to maintain alignment with enterprise security strategy, risk management, compliance requirements, and incident-response processes.
KEY RESPONSIBILITIES
Partner with AI product, application, and engineering teams from discovery through production to define secure-by-design architectures for AI-powered products and services.
Threat-model LLM-enabled and agentic workflows, including direct and indirect prompt injection, data exfiltration, unsafe tool use, excessive agent permissions, cross-tenant access, model abuse, and unintended autonomous actions.
Design secure patterns for agent identity, delegated authorization, scoped credentials, tool allowlists, approval gates, action validation, execution sandboxing, rollback, and auditability.
Secure RAG and enterprise-knowledge workflows, including document ingestion, indexing, retrieval permissions, metadata filtering, source attribution, tenant isolation, sensitive-data classification, and data-retention controls.
Define security controls for user-facing AI products, including authentication, authorization, consent, rate limiting, abuse detection, content and output controls, conversation-data handling, and customer-facing audit trails.
Secure model-serving and inference APIs through workload identity, API authentication, tenant-aware access controls, quotas, request validation, model access policies, usage monitoring, and logging controls.
Build reusable AI security guardrails, libraries, reference architectures, templates, policy-as-code, and developer tooling that make secure implementation the default path for product teams.
Work with DevOps and Platform teams to ensure Kubernetes, custom job-scheduler integrations, CI/CD pipelines, secrets management, containers, and runtime environments provide the required security posture for AI applications.
Lead vulnerability management for AI application dependencies, model-serving runtimes, agent frameworks, SDKs, APIs, containers, CUDA and GPU software components, and related infrastructure.
Embed security requirements into application design reviews, pull-request and CI/CD controls, release processes, operational runbooks, and incident-response procedures.
Develop security telemetry and detections for anomalous agent actions, unsafe tool calls, unusual data retrieval, credential misuse, inference API abuse, suspicious workload behavior, and policy violations.
Act as the principal security liaison between AI & Applications and the Cybersecurity function, coordinating architecture reviews, security exceptions, risk acceptance, compliance evidence, incident response, and remediation tracking.
SKILLS AND EXPERIENCE
5+ years of experience in security engineering, application security, cloud security, platform security, or a related field.
Demonstrated experience embedding security practices into software engineering or product-development teams and supporting secure delivery from design through production.
Strong understanding of application security, API security, secure software development lifecycle practices, threat modeling, vulnerability management, and security automation.
Practical understanding of AI and LLM application security risks, including prompt injection, indirect prompt injection, jailbreaks, insecure tool use, excessive agency, model abuse, sensitive-data exposure, cross-tenant data leakage, and supply-chain risks.
Experience securing agentic applications, RAG systems, enterprise search, vector databases, model-serving APIs, enterprise-data connectors, or comparable AI-enabled systems.
Experience designing identity and access controls using OIDC, OAuth 2.0, SSO, RBAC, ABAC, workload identity, service accounts, secrets management, and least-privilege principles.
Strong knowledge of Kubernetes and container security, including admission controls, network policies, RBAC, runtime protection, image scanning, software supply-chain security, and policy engines.
The PivotHop read
- What a security engineer actually earnsmedian, seniority, by country
- Alternative careers for a security engineerevery measured route out
- All open security engineer rolesthe full board
Where these skills also reach
- 41 open penetration tester roles71% readiness from security engineer
- 154 open network engineer roles69% readiness from security engineer
- 600 open systems administrator roles47% readiness from security engineer
- 600 open solutions architect roles43% readiness from security engineer
More security engineer roles
EverCommerce - Security Engineer at EverCommerceUnited States · Remote$130k–$150kTodayApply- Cybersecurity Engineer at CelcuityUnited States · Remote$120k–$130kTodayApply
- Sr Infrastructure Cloud Security Engineer - AWS - Remote at SAMC SitusAMC Holdings CorpUnited States · Remote$135k–$180kTodayApply
- Security Engineer at ConductLondon, UK1d agoApply
- Senior Security Engineer, Platform Engineering at FirmusSydney, Australia1d agoApply
Backfilled listing, refreshed with the nightly scrape; the employer has not claimed it yet. Are you the employer? Claim this listing and it can be featured to the candidates whose skills already reach it, first month free.