About the role
We're looking for an AI Application Security Engineer with a strong Application Security foundation and a hands-on engineering mindset.
You'll work directly with Product and R&D to design secure applications, build security automation, and embed practical security controls into our products and development workflows.
As part of a small security team, you'll take ownership across application security, AI security, cloud infrastructure, and security tooling. This is an opportunity to lead projects independently, make technical decisions, and help shape how security gets done at Artlist.
Responsibilities
Lead threat modeling and secure design reviews from the design stage, working directly with Product and R&D.
Embed security into CI/CD pipelines, products, and technology environments through security testing, tooling, and automated controls.
Define and implement guardrails for access control, data exposure, injection risks, and rate limiting.
Build scripts and automation to improve security workflows and reduce manual work.
Secure cloud infrastructure across AWS, GCP, and Azure.
Own WAF and site protection, including custom rules, rate limiting, bot mitigation, and DDoS protection.
Lead detection, response, and incident handling across endpoint, cloud, and application layers.
Integrate and maintain security tools and controls, including SAST, cloud security platforms, WAF, and EDR, and coordinate penetration testing and remediation.
Support SOC 2 and ISO 27001 requirements.
Requirements
4+ years of experience in Application Security, DevSecOps, or Security Engineering, with ownership of production systems and hands-on Application Security experience.
A track record of embedding security into product design and working directly with developers on secure development and remediation.
Hands-on GCP or AWS security experience.
Practical AI/LLM security knowledge, including model access, data leakage, and prompt injection.
Hands-on WAF and site protection experience.
Scripting and automation skills in Python, Go, or Bash.
Ability to work independently, take ownership, and collaborate across Product, R&D, and infrastructure teams.
Fluent English.
Nice to Have
Experience securing generative AI or ML product features in production.
Familiarity with AI gateways and platforms such as LiteLLM, OpenRouter, and Amazon Bedrock, and with LLM observability tools.
Relevant certifications, such as CISSP or GCP/AWS security certifications.