{"id":1889742,"url":"https://alion.io/job/bjak-ai-security-engineer","title":"AI Security Engineer","company":{"id":12599,"name":"Bjak","domain":"bjak.my","url":"https://alion.io/company/bjak","size_band":"5000+","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Ashby","truth_index":{"grade":"A","score":100,"open_postings":80,"ghost_share":0,"stale_share":0.05,"repost_share":0,"time_to_fill_p50_days":8,"computed_at":"2026-10-06T05:45:30Z"}},"role":"AI/ML","role_family":"AI/ML","seniority":"middle","employment_type":"full_time","work_mode":"remote","remote_scope":"worldwide","remote_scope_basis":"board_field","remote_working_hours":null,"hiring_geo_confidence":"inferred","locations":[],"countries":[],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":88000,"max_usd":218000,"period":"year","method":"global_role_seniority_cell","sample_n":654},"experience_years_min":3,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"AI Agents","optional":false},{"name":"AWS","optional":false},{"name":"GCP","optional":false},{"name":"Least Privilege","optional":false},{"name":"LLM","optional":false},{"name":"Node JS","optional":false},{"name":"Python","optional":false},{"name":"RAG","optional":false},{"name":"TypeScript","optional":false},{"name":"JavaScript","optional":true}],"status":"live","first_seen_at":"2026-09-29T08:40:45Z","employer_posted_date":"2026-09-29","last_verified_at":"2026-10-06T19:08:13Z","board_verified":true,"closed_at":null,"days_open":7,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":7},"description":"About BJAK\nThe original mission of BJAK is we believe people deserve smarter ways to plan, save and grow their money. This is the origin of our name.\nStarted in 2019, we built the first mobile-first, insurance platform, enabling insurance to be accessible online by millions in the region. Today, its the leading insurance platform in Southeast Asia.\nToday, we are expanding ways to help people in the region - this includes spending, saving, investing, exchanging, travelling, and more. Our mission is help people get more from their money every day.\nWe have teams working around the world, with over 20 nationalities from our offices and remotely, who truly enjoys their work. We are looking for the most talented and driven people we can find. We are looking for people who work for their passion, not counting hours. Who loves building great next-generation products, not status quo. Who cares about redefining how everyone around us can get the best financial applications, not for an exclusive few.\nIf you're this person, we'd love to talk to you.\nThe Role\nSecure BJAK's AI-enabled products and agent workflows using third-party models. Focus on customer data shared with model providers, agent permissions, user data isolation, and prompt injection through uploaded documents and other untrusted content.\nWhat You Will Build\nAssess customer data sent to third-party model vendors, including minimization, vendor controls, retention, logging, and approved use.\n\nDesign controls limiting AI agent permissions, tools, actions, and system access using least privilege and explicit authorization.\n\nImplement and test tenant and user data isolation across prompts, conversation history, retrieval, memory, and AI-connected services.\n\nThreat model and test prompt injection and indirect injection through uploaded documents, retrieved content, links, and other untrusted inputs.\n\nPartner with Product and Engineering on safe document ingestion, content handling, output validation, and approval for sensitive actions.\n\nSupport SC TRM and BNM RMiT for AI technology risks, including assessments, third-party oversight, control evidence, and remediation.\n\nBuild security tests, monitoring, and response procedures for AI misuse, data exposure, unauthorized actions, and vendor incidents.\n\nWhat We Look For\nDegree in Computer Science, Cybersecurity, AI, or related field, or equivalent experience.\n\n3+ years in application security, product security, security engineering, or AI system security.\n\nExperience implementing or owning SC TRM and BNM RMiT controls, technology risk, or regulatory control evidence.\n\nUnderstanding of third-party LLM integrations, model APIs, agent tools, RAG, and AI application architectures.\n\nKnowledge of prompt injection, indirect injection, cross-user data leakage, excessive agent permissions, and vendor data disclosure risks.\n\nProgramming or scripting skills, preferably Python and TypeScript/Node.js, plus APIs and AWS or GCP.\n\nAble to collaborate with Product, Legal, Compliance, Data, and Engineering on practical controls and risk communication.\n\nLanguage\nEnglish is our main working language across global teams. Strong English communication is required.","description_format":"text","description_chars":3192,"description_truncated":false,"requirements":{"experience_years_min":3,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":{"level":"bachelor","optional":false},"security_clearance":false,"languages":[{"language":"English","level":"Upper-Intermediate (B2)","optional":false}]},"benefits":[],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["InsurTech","Financial Comparison & Loan Marketplaces"],"lifecycle":[{"event":"open","at":"2026-10-05T04:20:01Z"}],"visa":[],"liveness":{"score":54,"band":"ok","label":"Likely open","p_open":1,"p_active":0.725,"p_room":0.75,"age_days":6,"expected_fill_days":8,"reasons":["conf:0","velocity","win:late","comp:remote,brand"],"computed_at":"2026-10-06T05:45:30Z"},"pay":null,"html_url":"https://alion.io/job/bjak-ai-security-engineer","json_url":"https://alion.io/job/bjak-ai-security-engineer.json","meta":{"generated_at":"2026-10-06T21:26:14Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","about":"Alion is a live layer of people, companies and AI agents: who they are, whether they are real and active right now, what they do and how to work with them, readable by people and by agents and paid per call.","catalog":"https://alion.io/catalog.json","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":957,"day_limit":5000,"remaining_today":4043,"minute_limit":60,"resets_at":"2026-10-07T00:00:00Z"}},"offers":[{"id":"company.slices","title":"One company in depth, by slice","status":"live","price":{"credits":0.02,"usd":0.002,"plus_per_slice":{"credits":0.05,"usd":0.005}},"unit":"per company, plus each slice with data","note":"the employer in depth","call":{"mcp_tool":"get_company","arguments":{"id":12599},"rest":"https://alion.io/mcp/rest/get_company?id=12599"},"human":"https://alion.io/catalog?offer=company.slices&for=job%2Fbjak-ai-security-engineer"},{"id":"market.stats","title":"A market slice: pay, demand and time to fill","status":"live","price":{"credits":1,"usd":0.1},"unit":"per slice","note":"pay, demand and time to fill for this role and place","call":{"mcp_tool":"market_stats"},"human":"https://alion.io/catalog?offer=market.stats&for=job%2Fbjak-ai-security-engineer"},{"id":"job.search","title":"Open jobs by role, technology, place, pay and visa","status":"live","price":{"credits":0.02,"usd":0.002},"unit":"per posting in a list","note":"similar open postings","call":{"mcp_tool":"search_jobs"},"human":"https://alion.io/catalog?offer=job.search&for=job%2Fbjak-ai-security-engineer"},{"id":"company.verify","title":"Is this company real and active right now","status":"pilot","price":null,"unit":"per company","request":{"url":"https://alion.io/catalog/request","method":"POST","body":"{\"offer\": \"company.verify\", \"for\": \"job/bjak-ai-security-engineer\", \"note\": \"what you need it for\"}"},"human":"https://alion.io/catalog?offer=company.verify&for=job%2Fbjak-ai-security-engineer"}]}