
Backblaze is the object storage leader in the open cloud movement, fueling customer success with cloud storage built purposefully to unlock budgets, unburden administrators, and unleash innovators. Today, Backblaze generates over $100m in revenue and manages over three billion gigabytes of data storage for 500K+ customers in 175+ countries.
We are seeking a Sr. AI Security Engineer to join our team!
About The Role
Backblaze is seeking a Senior AI Security Engineer to design and implement safeguards for internal AI usage, with a focus on agentic systems, developer protection, and runtime security.
This is a hands-on role for a practitioner who has built and deployed security controls, not just defined policy. You will enable teams to safely use AI by creating enforcement layers, identity controls, and detection capabilities that constrain and monitor AI-driven activity.
What Youβll Do
Agentic AI Safeguards
- Architect and implement guardrails for tool-using AI systems, including:
- Tool access controls and allowlists
- Context and memory isolation
- Step-level validation of agent actions
- Apply mitigations aligned to the OWASP Agentic AI Top 10 (e.g., prompt injection, unsafe tool use, data leakage, excessive autonomy)
Runtime Security Controls
- Build enforcement mechanisms that govern AI behavior at execution time:
- Interceptors, proxies, or middleware for tool/API calls
- Policy decision and enforcement layers
- Rate limits, execution bounds, and kill-switches
- Prevent unsafe or unauthorized actions initiated by AI systems
Non-Human Identity (NHI)
- Design and implement identity and access controls for agents and automation, including:
- Short-lived credentials and scoped permissions
- Clear separation between human and non-human access
- Strong binding of identity to task context and execution
- Ensure all AI actions are attributable and auditable
Observability & Detection
- Implement logging and tracing for AI activity (prompts, tool usage, and decision flows)
- Build detection capabilities using behavioral baselining and anomaly detection techniques
- Identify and alert on abnormal tool usage, suspicious prompt patterns, and unexpected data access
Threat Modeling (MAESTRO)
- Perform agentic system threat modeling using MAESTRO:
- Mapping agent capabilities, trust boundaries, and attack paths
- Modeling misuse and adversarial scenarios
- Translate findings into practical safeguards and detection logic
Developer Safeguards
- Protect developers using AI tools by preventing sensitive data exposure, validating AI-generated code/actions, and constraining unsafe automation
- Enable safe usage of AI-assisted development tools (e.g., Claude Code, Codex, Cursor)
The Right Fit
- 7+ years in security engineering or backend systems
- Proven experience designing and deploying security controls (runtime enforcement layers, identity/access systems)
- Strong programming skills (Python preferred; Go, Java, or TypeScript a plus)
- Experience using AI-assisted development tools in real workflows
- Experience with logging, monitoring, detection systems, and API/service security
- Practical familiarity with agentic AI systems and OWASP guidance for AI/agent risks
Practitioner Knowledge
- Experience applying OWASP Agentic AI / LLM risk guidance, NIST AI RMF, and CSA guidance
- Strong understanding of Zero Trust for non-human identities, secrets management, and observability tooling (e.g., OpenTelemetry, ELK)
Timezone overlap
UTC-6β-3
Open to
LATAM
Sign in to track applications and earn points.