Your brand on every pageBecome a sponsor →

AI Security Jobs

AI security roles protect models, training data, and AI infrastructure from attack - securing training pipelines and inference endpoints, and defending against prompt injection, data poisoning, and model theft. It sits alongside traditional security engineering but focuses specifically on AI-system risk.

35 live AI Security roles across the AI employers we track - updated hourly, apply directly.

2new AI Security roles posted this week

AI Security roles are rare: 35 live right now. Get the new ones every Monday.

Get new AI Security jobs in your inbox

Join 100+ AI professionals · Weekly, free, unsubscribe anytime

Latest AI Security roles

Securing AI systems, end to end

AI security means securing AI systems. The asset boundary is specific: model weights and checkpoints, training data and its provenance, the fine-tuning and evaluation pipelines, the serving path and its endpoints, the retrieval corpus a model reads at runtime, and the credentials and tool permissions an AI system can act with. A conventional security program does not cover any of that by default, which is why these roles are scoped and staffed separately.

Prompt injection is the defining unsolved problem, and it is unsolved in a strong sense. SQL injection was fixed structurally by parameterized queries, which separate code from data so that a hostile string can never become an instruction. Language models have no such separation: instructions and data arrive through the same channel, so any text a model reads, whether a web page, a document, an email, or a tool result, can attempt to redirect it. Defenses are layered mitigations rather than a fix, and treating model output as untrusted input remains the sound design assumption.

Agents turn manipulation into action, which changes the severity calculation. A chat model talked into saying something wrong produces bad text. An agent with browser access, code execution, or write access to real systems can be talked into taking an action with consequences. That pushes the practical work toward permission scoping, sandboxing, human confirmation on irreversible steps, and audit trails that record what an AI system did rather than only what it said.

Explore related searches

Frequently asked questions

Is there much AI Security hiring happening currently?
We are tracking 35 live AI Security roles across the AI companies we monitor, updated hourly. Each listing links straight to the employer's own application page.
What does AI security protect that application security does not?
Model weights and checkpoints, training and fine-tuning data and its provenance, evaluation and training pipelines, inference endpoints, retrieval corpora that models read at runtime, and the credentials and tool permissions available to an AI system. Conventional application and infrastructure security is still required underneath, but it does not address these assets or their failure modes.
Why can prompt injection not be fixed the way SQL injection was?
Parameterized queries fixed SQL injection by separating code from data at the interface, so input can never be parsed as instructions. Language models take instructions and data through the same channel and have no equivalent separation, so any content a model reads can attempt to steer it. Current practice layers mitigations, including filtering, permission limits, isolation, and human confirmation, without eliminating the class of attack.
How do AI agents change the security model?
An agent acts, so a successful manipulation causes an action rather than an unwanted sentence. Tool access, browsing, code execution, and persistent memory expand what an attacker can reach through content the agent merely reads. Controls shift toward least-privilege tool scoping, sandboxed execution, confirmation gates on irreversible operations, and logging detailed enough to reconstruct what the agent did.

Related AI job searches