Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Security Engineer II, AI/ML Security image - Rise Careers
Job details

Security Engineer II, AI/ML Security

Who We Are

Founded in 2012 by 3 expert hackers with no investment capital, Trail of Bits is the premier place for security experts to boldly advance security and address technology’s newest and most challenging risks. It has helped secure some of the world's most targeted organizations and devices. Our combination of novel research with practical solutions reduces the security risks that our clients face from emerging technologies. Our work helps drive the security industry and the public understanding of the technology underlying our world.

Cybersecurity preparedness is a moving target. Companies like ours are the tip of the spear in the fight against attackers. Our research-based and custom-engineering approach ensures that our client’s capabilities are at the forefront of what’s available. For companies and technologies that live and die by their security, a proactive, tailored approach is required to keep one step ahead of attackers.

Democratizing security information is essential. As part of our business, we provide ongoing informational support through blogs, whitepapers, newsletters, meetups, and open-source tools. The more the community understands security, the more they’ll understand why a company like ours is so unique and valuable.

Role

Trail of Bits seeks a Security Engineer II, AI/ML Security within our growing Software Assurance team. You will conduct comprehensive security assessments of machine learning and large language model systems, examining everything from examining software across the AI/ML supply chain and stack such as LLM web applications, training data pipelines, neural network architectures, AI/ML frameworks, and CUDA-based libraries. You will identify and analyze novel attack vectors and vulnerabilities specific to MLops environments, focusing on potential failure modes, vectors for model performance degradation, and unauthorized access to sensitive data and model parameters.

In addition to performing technical assessments, you will contribute to threat modeling, evaluating AI adoption risk frameworks, and delivering specialized training to clients on AI security concepts, including AI/ML-specific attacks, AI safety, and pipeline threats.

What You’ll Achieve

  • AI/ML Security Assessment: Conduct comprehensive security assessments of AI/ML pipelines, tools, and frameworks. Examine vulnerabilities in model architectures, training processes, and deployment infrastructure while developing mitigation strategies.
  • AI/ML Security Controls: Design and develop security frameworks and tools specifically for AI/ML systems, including model robustness testing, data poisoning detection, and protection against adversarial attacks.
  • Application Security Assessment: Conduct security assessments of client code bases using a combination of static analysis, dynamic testing, and manual code review, identifying vulnerabilities and developing mitigation strategies, with a focus on findings at the intersection of application security and AI/ML security.
  • AI/ML Threat Modeling: Conduct threat modeling and risk assessments to proactively identify potential risks for clients and develop mitigation strategies for future prevention.
  • Client Engagement: Work with leading industry teams to review system code and architecture, and help assure their products through system analysis  and modeling.
  • AI Policy & Compliance Initiatives: Develop and contribute to AI/ML regulatory frameworks, establishing assurance methods and auditing processes for mission-critical AI applications while ensuring alignment with emerging industry standards and safety requirements.


What You’ll Bring

  • AI/ML Security Expertise: Extensive experience in AI/ML security, with demonstrated ability to identify and mitigate ML-specific vulnerabilities across complex systems.
  • Technical AI/ML Knowledge: Deep understanding of AI/ML architectures, frameworks (PyTorch, Jax, LangChain, RAG systems, etc.), and MLOps practices, combined with robust security engineering expertise.
  • Assessment Experience: Have conducted technical security assessments of AI/ML systems and implemented effective security measures.
  • Tool Proficiency: Strong background in AI/ML development languages (Python, C, C++, Typescript, JacaScript, Rust) and security testing frameworks, with experience in developing and applying ML-specific security tools.
  • Communication Skills: Ability to effectively communicate complex AI/ML security concepts to diverse stakeholders and deliver clear, actionable recommendations.

The base salary for this full-time position ranges from $165,000 to $195,000, excluding benefits and potential bonuses. Various factors influence our salary ranges, including the specific role, level of seniority, geographic location, and the nature of the employment contract. An individual's specific work location, unique skills, experience, and relevant educational background will determine the final offer within this range. The presented salary range encompasses the starting salaries for all U.S. locations. For a precise salary estimate tailored to your preferred location, please discuss it with your recruiter during the hiring process.

Trail of Bits, Inc. participates in E-Verify, the US federal electronic employment eligibility verification program. Learn more.

Benefits, Perks & Wellness

Trail of Bits is our people, not a place. With over 100+ employees working from every time zone across the globe, our remote-first culture is built on autonomy and trust (and backed by smile-worthy benefits) for full-time employees:

Empowered Living:

  • Competitive salary complemented by performance-based bonuses.
  • Fully company-paid insurance packages, including health, dental, vision, disability, and life.
  • A solid 401(k) plan with a 5% match of your base salary.
  • 20 days of paid vacation with flexibility for more, adhering to jurisdictional regulations.

Nurturing New Beginnings:

  • 4 months of parental leave to cherish the arrival of new family members.
  • Our team is global and remote-first. However, if you are interested in moving to NYC, we offer $5,000 in relocation assistance to support your transition.

Work & Life Enrichment:

  • $1,000 Working-from-Home stipend to create a comfortable and productive home office.
  • Annual $750 Learning & Development stipend for continuous personal and professional growth.
  • Company-sponsored all-team celebrations, including travel and accommodation, to foster community and recognize achievements.

Community Impact:

  • Philanthropic contribution matching up to $2,000 annually.

Dedication to Diversity, Equity, Inclusion & Belonging (DEIB)

Trail of Bits is a community of innovators, risk-takers, and trailblazers who celebrate individual differences and recognize that unique perspectives make us stronger, smarter, and more successful. We actively seeks applicants who can bring a variety of experiences, perspectives, and backgrounds to the team. We provide equal employment opportunities to all employees and applicants for employment without regard to race, color, ancestry, national origin, gender, sex, pregnancy, pregnancy-related condition, sexual orientation, marital status, religion, age, disability, qualified handicap, gender identity, results of genetic testing, military status, veteran status, or any other characteristic protected by applicable law. Our team values diversity in experience and backgrounds—we do our best work when we create space for different voices and perspectives. Whatever unique experiences or skill sets you bring, we look forward to learning from each other.

Trail of Bits Glassdoor Company Review
5.0 Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon
Trail of Bits DE&I Review
5.0 Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon
CEO of Trail of Bits
Trail of Bits CEO photo
Dan Guido
Approve of CEO

Average salary estimate

$180000 / YEARLY (est.)
min
max
$165000K
$195000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Security Engineer II, AI/ML Security, Trail of Bits

At Trail of Bits, we’re on the lookout for a dynamic Security Engineer II specialized in AI/ML Security to join our innovative Software Assurance team. Since 2012, we’ve been tackling some of the most challenging security risks faced by organizations worldwide, offering a unique blend of cutting-edge research and practical solutions. In this role, you’ll dive deep into the realms of machine learning and large language models, conducting comprehensive security assessments that scrutinize software across the full AI/ML supply chain. You’ll identify and analyze novel attack vectors specific to MLops environments, playing a crucial role in ensuring the security and integrity of our clients’ systems. Your efforts won’t just stop at vulnerability detection—as a Security Engineer II at Trail of Bits, you will also contribute to threat modeling, risk assessment, and client engagement, delivering valuable insights and training on AI security concepts. If you're passionate about advancing security and addressing emerging technologies' challenges, and if you have experience in AI/ML architectures and robust security engineering, you’ll fit right in with our team that thrives on making a significant impact in the cybersecurity world. With a remote-first culture and a broad range of benefits that support your professional growth and well-being, Trail of Bits offers a vibrant work environment where innovation and collaboration are at the forefront. We’d love for you to be part of our mission to empower organizations with proactive, tailored security measures, keeping them one step ahead of cyber threats. Ready to take on the challenge?

Frequently Asked Questions (FAQs) for Security Engineer II, AI/ML Security Role at Trail of Bits
What are the responsibilities of a Security Engineer II at Trail of Bits?

As a Security Engineer II specializing in AI/ML Security at Trail of Bits, you'll conduct comprehensive security assessments of AI/ML systems, design and develop security frameworks, engage with clients, and contribute to threat modeling and risk assessments to safeguard against emerging vulnerabilities.

Join Rise to see the full answer
What qualifications are needed for the Security Engineer II position at Trail of Bits?

To qualify for the Security Engineer II, AI/ML Security role at Trail of Bits, candidates should have extensive experience in AI/ML security, a strong technical knowledge of AI/ML frameworks, experience conducting security assessments, and proficiency in programming languages such as Python, C++, or JavaScript.

Join Rise to see the full answer
How does Trail of Bits approach AI/ML security assessments?

Trail of Bits employs a thorough approach towards AI/ML security assessments, focusing on examining vulnerabilities within model architectures and training processes, while also delivering mitigation strategies tailored to client needs to ensure robust security in their AI implementations.

Join Rise to see the full answer
What tools and frameworks do Security Engineers at Trail of Bits work with?

Security Engineers II at Trail of Bits work with advanced security testing frameworks and AI/ML development languages like Python, as well as platforms such as PyTorch and Jax, enhancing their assessments and security measures through cutting-edge tools.

Join Rise to see the full answer
What is the salary range for the Security Engineer II role at Trail of Bits?

The base salary for the Security Engineer II, AI/ML Security position at Trail of Bits ranges from $165,000 to $195,000, depending on factors like experience level, skills, and the nature of the employment contract.

Join Rise to see the full answer
Common Interview Questions for Security Engineer II, AI/ML Security
Can you describe your experience with AI/ML security frameworks?

When answering this question, detail specific frameworks you've worked with, such as PyTorch or TensorFlow, and explain how you used them to enhance security measures or conduct assessments, highlighting any innovative strategies you implemented.

Join Rise to see the full answer
What vulnerabilities do you think are most common in AI/ML systems?

Discuss prevalent vulnerabilities like data poisoning or adversarial attacks, and provide examples of how you have identified or mitigated such vulnerabilities in previous roles to demonstrate both your knowledge and hands-on experience.

Join Rise to see the full answer
How do you approach threat modeling for AI applications?

Convey your methodical approach to threat modeling, including the tools and processes you use, such as STRIDE or PASTA, and how these techniques have helped you anticipate risks and devise mitigation strategies specific to AI applications.

Join Rise to see the full answer
What strategies would you use to secure a machine learning pipeline?

Outline a multi-layered security strategy, discussing areas such as access control, data integrity, and monitoring real-time threats to ensure that each aspect of the pipeline is protected against potential attacks.

Join Rise to see the full answer
How do you stay updated on the latest AI/ML security trends?

Mention your practices for staying informed, such as following industry publications, attending conferences, participating in relevant online forums, or contributing to open-source projects related to AI security.

Join Rise to see the full answer
Can you provide an example of a significant security incident you managed?

Detail a specific incident, your role in managing it, the steps you took to resolve the issue, and the lessons learned that would apply to the Security Engineer II position at Trail of Bits.

Join Rise to see the full answer
What role do you think communication plays in security engineering?

Emphasize the importance of clear communication, especially in conveying complex security concepts to non-technical stakeholders and fostering collaboration among team members to develop effective security solutions.

Join Rise to see the full answer
Describe your experience conducting penetration testing on AI systems.

Discuss your methodologies for penetration testing AI systems, any specific tools used, and insights gained from performing such tests that could be applicable to improving the security of AI systems at Trail of Bits.

Join Rise to see the full answer
In your opinion, what is the future of AI/ML security?

Provide a thoughtful perspective on emerging threats and technologies within AI/ML security, backed by current trends or case studies that illustrate your expertise and vision for the future.

Join Rise to see the full answer
How would you prioritize vulnerabilities in an AI system?

Share your approach to vulnerability prioritization, including factors such as the potential impact on organizational security and the likelihood of exploitation, highlighting how this aligns with best practices in risk management.

Join Rise to see the full answer
Similar Jobs

As a cybersecurity research and consulting firm, we serve clients in the defense, tech, finance, and blockchain industries. Our teams help with their most difficult security challenges by designing and building new technology, researching new tech...

6 jobs
MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, remote
DATE POSTED
December 10, 2024

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!