{"id":1720229,"url":"https://alion.io/job/metaforms-ai-security-platform-engineer","title":"AI Security & Platform Engineer","company":{"id":680192,"name":"Metaforms","domain":"metaforms.ai","url":"https://alion.io/company/metaforms","size_band":"51-200","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Ashby","truth_index":null},"role":"DevOps","role_family":"DevOps","seniority":"junior","employment_type":"full_time","work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Bengaluru, India"],"countries":["IN"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":null,"experience_years_min":2,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"AI Agents","optional":false},{"name":"CI/CD","optional":false},{"name":"Function Calling","optional":false},{"name":"Go","optional":false},{"name":"Least Privilege","optional":false},{"name":"LLM","optional":false},{"name":"LLM Guardrails","optional":false},{"name":"Model Context Protocol","optional":false},{"name":"Platform Engineering","optional":false},{"name":"Python","optional":false},{"name":"RAG","optional":false},{"name":"Tool Use","optional":false},{"name":"TypeScript","optional":false},{"name":"ISO 27001","optional":true},{"name":"Red Teaming","optional":true},{"name":"SOC 2","optional":true}],"status":"live","first_seen_at":"2026-10-02T06:28:13Z","employer_posted_date":"2026-10-02","last_verified_at":"2026-10-05T02:36:51Z","board_verified":true,"closed_at":null,"days_open":2,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":2},"description":"About Metaforms\nMetaforms builds AI infrastructure for research delivery teams. Our agents help market research agencies and sample providers execute complex workflows with greater speed, consistency, and scale.\nAs these agents interact with customer data, files, APIs, integrations, and other tools, security must be built into every layer of the platform. We are looking for an engineer who is excited about understanding how AI systems can fail-and building the controls that make them safe, reliable, and secure by default.\nAbout the role\nWe’re looking for an AI Security & Platform Engineer to help secure the AI agents and infrastructure behind Metaforms.\nYou will test our AI systems adversarially, identify vulnerabilities across prompts, context, data, tools, integrations, and execution environments, and work with engineers to fix them properly. You will also build platform-level controls, automated evaluations, monitoring, and secure infrastructure that prevent similar vulnerabilities from recurring.\nThis is a hands-on engineering role, not a policy or compliance position. You will write code, inspect production systems, reproduce vulnerabilities, build security tooling, and contribute directly to product and infrastructure improvements.\nYou will work closely with engineering leadership and gradually take ownership of larger AI security and platform initiatives.\nWhat you’ll work on\nAI and agent security\nAdversarially test AI agents for prompt injection, context poisoning, unsafe tool use, data leakage, memory manipulation, and unintended behavior.\n\nIdentify security risks introduced through customer prompts, uploaded files, retrieved content, external links, integrations, and model-generated outputs.\n\nTest whether agents can access unauthorized tools, records, tenants, credentials, or internal services.\n\nThreat-model new AI features, agent workflows, model integrations, and tool-calling capabilities before they reach production.\n\nEvaluate risks in RAG pipelines, context assembly, agent memory, system prompts, MCP servers, model providers, and third-party AI frameworks.\n\nBuild repeatable adversarial evaluations and regression tests for discovered vulnerabilities.\n\nDesign controls for least-privilege tool access, scoped credentials, sandboxing, runtime policy enforcement, and human approval.\n\nEnsure model output is validated before it reaches databases, APIs, executable systems, or customer-visible workflows.\n\nImprove auditability across model calls, retrieved context, tool invocations, agent decisions, and resulting actions.\n\nMonitor emerging AI attack techniques and translate relevant risks into practical product controls.\n\nProduct security\nReview customer-facing applications and APIs for authentication, authorization, tenant-isolation, injection, and business-logic vulnerabilities.\n\nSecure customer-controlled payloads, file uploads, webhooks, exports, and third-party integrations.\n\nReproduce security reports, determine credible impact, and distinguish exploitable vulnerabilities from theoretical findings.\n\nWork directly with engineers to implement production-ready fixes and regression tests.\n\nHelp build secure, reusable patterns for input handling, authorization, secrets, data access, and external integrations.\n\nPerform focused code reviews, penetration tests, and architecture assessments for security-sensitive changes.\n\nPlatform and infrastructure\nBuild and improve the secure, reliable infrastructure behind model calls and agent workflows.\n\nHarden cloud permissions, service identities, secrets, storage, networking, deployment pipelines, and production access.\n\nBuild guardrails into CI/CD and infrastructure-as-code so common security problems are caught before deployment.\n\nImprove model-provider routing, retries, timeouts, fallbacks, quotas, rate limits, and cost controls.\n\nAdd observability for unusual model behavior, tool usage, data access, errors, latency, and token consumption.\n\nBuild containment mechanisms and kill switches for unsafe or misbehaving agents.\n\nSupport production debugging and the investigation of application, infrastructure, and AI-security incidents.\n\nWhat we’re looking for\n2-3 years of hands-on experience across AI engineering, backend/platform engineering, application security, infrastructure security, DevSecOps, or a related engineering role.\n\nExperience building, operating, or securing production AI systems using LLM APIs, agents, tool calling, RAG, model gateways, or similar technologies.\n\nStrong programming ability in Python, TypeScript, Go, or another relevant language.\n\nUnderstanding of common web and API security risks, including authentication, authorization, injection, tenant isolation, secrets, and unsafe data handling.\n\nPractical experience with cloud infrastructure, CI/CD, containers, monitoring, or infrastructure-as-code.\n\nAbility to investigate a suspected vulnerability, reproduce it, assess its real-world impact, and contribute an effective fix.\n\nAbility to reason about trust boundaries between users, models, customer data, application code, tools, and third-party services.\n\nComfort debugging systems through source code, logs, traces, metrics, and database queries.\n\nStrong written communication and the ability to explain security risks clearly without unnecessary alarm.\n\nA builder’s mindset: you enjoy implementing durable controls, not only identifying problems.\n\nWe care more about strong fundamentals, practical work, and learning velocity than matching every item in the description.\nGood to have\nHands-on experience with AI red teaming or adversarial model testing.\n\nFamiliarity with prompt injection, insecure output handling, tool-use vulnerabilities, agent sandboxing, or context leakage.\n\nExperience securing multi-tenant B2B SaaS products.\n\nExperience with OAuth, webhooks, file processing, MCP, and third-party integrations.\n\nExperience building security test harnesses, fuzzers, automated evaluations, or internal security tools.\n\nFamiliarity with SAST, DAST, dependency scanning, secret scanning, or infrastructure scanning.\n\nExperience with model gateways, multi-provider routing, AI observability, or LLM evaluations.\n\nParticipation in bug bounties, CTFs, security research, or relevant open-source projects.\n\nFamiliarity with SOC 2 or ISO 27001 from an engineering implementation perspective.\n\nExample projects\nYou might work on projects such as:\nBuild a test harness that injects malicious instructions through prompts, uploaded files, and retrieved documents.\n\nFind and eliminate a path through which one tenant’s information could enter another tenant’s model context.\n\nIntroduce capability-scoped credentials so agents receive access only to the data and tools required for a specific task.\n\nAdd security regression evaluations for previously discovered AI vulnerabilities.\n\nBuild validation and containment around model-generated JSON, XML, queries, scripts, or API payloads.\n\nPrevent untrusted content from triggering sensitive tool calls without deterministic authorization.\n\nBuild traceability from user input through model context, output, tool execution, and final side effects.\n\nDetects unusual tool-call sequences, data-access patterns, agent loops, or token consumption.\n\nThreat-model a new agent capability and implement the required controls before launch.\n\nTurn a recurring vulnerability class into a reusable platform guardrail.\n\nWhat success looks like\nIn your first three months, you will:\nUnderstand the major trust boundaries across Metaforms’ AI agents, customer data, tools, and infrastructure.\n\nBuild an initial threat model and prioritized AI-security testing plan.\n\nReproduce and help remediate high-priority product or AI vulnerabilities.\n\nAdd high-signal security tests for important agent and application boundaries.\n\nImprove visibility into model calls, tool usage, and security-relevant agent behavior.\n\nOver time, you will:\nBuild continuous adversarial testing into how Metaforms develops AI features.\n\nReduce recurring vulnerability classes through reusable controls and secure defaults.\n\nHelp engineers ship AI capabilities quickly without weakening customer-data boundaries.\n\nDevelop into a technical owner for AI security across the platform.\n\nMake Metaforms’ agents more secure, observable, reliable, and resilient as their capabilities grow.\n\nWhy join Metaforms?\nWork on practical AI-security problems in production agent systems.\n\nOperate across offensive testing, application security, and platform engineering.\n\nShip fixes and controls directly rather than producing reports that sit in a queue.\n\nWork closely with engineering leadership and influence platform design early.\n\nTake meaningful ownership while growing into an emerging technical specialization.\n\nOur hiring process\nThe process will focus on practical engineering judgment rather than security trivia:\nIntroductory conversation.\n\nTechnical discussion covering AI systems, security fundamentals, and past projects.\n\nPractical exercise involving a simplified agent workflow, its trust boundaries, likely attack paths, and one proposed or implemented control.\n\nFinal conversation with engineering leadership.\n\nBreak AI systems like an attacker. Fix them like a platform engineer.","description_format":"text","description_chars":9235,"description_truncated":false,"requirements":{"experience_years_min":2,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[]},"benefits":[],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["Market Research","AI Agents"],"lifecycle":[{"event":"open","at":"2026-10-02T20:19:55Z"}],"visa":[],"liveness":{"score":86,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.86,"p_room":1,"age_days":1,"expected_fill_days":19,"reasons":["conf:0","win:early","comp:junior"],"computed_at":"2026-10-04T05:45:00Z"},"pay":null,"html_url":"https://alion.io/job/metaforms-ai-security-platform-engineer","json_url":"https://alion.io/job/metaforms-ai-security-platform-engineer.json","meta":{"generated_at":"2026-10-05T03:21:43Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":4503,"day_limit":5000,"remaining_today":497,"minute_limit":60,"resets_at":"2026-10-06T00:00:00Z"}}}