Описание
Ki is an algorithmic insurance carrier that uses algorithms, machine learning, and large language models to provide insurance brokers with quotes in seconds. Working with Google and UCL, the company digitally transforms the global insurance market.
Задачи
- Provide implementation advice on securing AI-powered applications using frameworks such as OWASP ASVS and the OWASP Top 10 for LLM Applications;
- Lead threat modelling sessions for AI and agentic systems during technical design using STRIDE and AI-specific frameworks;
- Establish secure guardrails, allowlists, telemetry, and safe-by-default configurations for developer AI tooling;
- Manage security testing workflows in the SDLC, including scanners for standard and AI-specific risks such as prompt injection and data leakage;
- Coordinate penetration tests, vulnerability triage, and cloud security posture management across GCP and Azure;
- Automate security tasks by contributing code to infrastructure and security tooling around cloud platforms;
- Facilitate the Security Champions network, organize security discussions, and deliver AI tooling safety training;
- Share expertise, document processes, and mentor team members to build security capability across engineering;
- Provide feedback on Ki's architecture and lead technical security discussions.
Требования
- Strong ability to write and review code, preferably in Python, TypeScript, Kotlin, and Terraform, with a background in software development, SRE, DevOps, or practical security engineering;
- In-depth understanding of securing AI/LLM applications, agentic tooling, and developer AI tools, including prompt injection mitigation, model integration risks, guardrails, telemetry, and frontier models via APIs or locally;
- Practical experience with agentic development using coding harnesses;
- Solid knowledge of major public cloud providers and network infrastructure;
- Solid understanding of Kubernetes, Docker, and container security;
- Experience implementing and managing SCA, SAST, and DAST security testing programs in pipelines such as GitHub Actions, including release packaging and artifact management;
- Ability to develop secure, automated infrastructure using Terraform;
- Interest in both offensive and defensive security;
- Ability to work collaboratively in enterprise-wide agile development environments;
- Outstanding written and verbal communication skills, including explaining complex vulnerabilities to technical teams and business stakeholders, sharing knowledge, and mentoring colleagues;
- Nice to have: Google Cloud Platform, Azure or AWS.
Условия
- Highly competitive remuneration and benefits package;
- Teams and individuals are acknowledged and rewarded for extraordinary effort.
#J-18808-Ljbffr
application security engineer in insurance employer: Enfint
As a leading innovator in AI products for major publishers, our company offers an inspiring work environment where creativity and technology intersect. We prioritise employee growth through continuous learning opportunities and foster a collaborative culture that values diverse perspectives. Located in a vibrant city, we provide competitive salaries, relocation support, and the chance to make a real impact in the media landscape.