Skip to content

Open nowPosted 17 hours ago

AI Security & Platform Engineer

Metaforms6 open roles

Where
Bengaluru
Work mode
On site
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowAI Security & Platform EngineerMetaforms · Bengaluru
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Metaforms's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.8% of postings close within 7 days. Measured by our own scanner across the market. Metaforms postings stay open a median of 18 days.

Share of postings closed within
  1. 1.6%1 day
  2. 3.4%3 days
  3. 7.8%7 days
  4. 14.3%14 days
  5. 33.7%30 days
This job: posted 17 hours ago

Metaforms median: 18 days open

The posting

ABOUT METAFORMS

Metaforms builds AI infrastructure for research delivery teams. Our agents help market research agencies and sample providers execute complex workflows with greater speed, consistency, and scale.

As these agents interact with customer data, files, APIs, integrations, and other tools, security must be built into every layer of the platform. We are looking for an engineer who is excited about understanding how AI systems can fail—and building the controls that make them safe, reliable, and secure by default.

ABOUT THE ROLE

We’re looking for an AI Security & Platform Engineer to help secure the AI agents and infrastructure behind Metaforms.

You will test our AI systems adversarially, identify vulnerabilities across prompts, context, data, tools, integrations, and execution environments, and work with engineers to fix them properly. You will also build platform-level controls, automated evaluations, monitoring, and secure infrastructure that prevent similar vulnerabilities from recurring.

This is a hands-on engineering role, not a policy or compliance position. You will write code, inspect production systems, reproduce vulnerabilities, build security tooling, and contribute directly to product and infrastructure improvements.

You will work closely with engineering leadership and gradually take ownership of larger AI security and platform initiatives.

WHAT YOU’LL WORK ON

AI AND AGENT SECURITY

- Adversarially test AI agents for prompt injection, context poisoning, unsafe tool use, data leakage, memory manipulation, and unintended behavior.

- Identify security risks introduced through customer prompts, uploaded files, retrieved content, external links, integrations, and model-generated outputs.

- Test whether agents can access unauthorized tools, records, tenants, credentials, or internal services.

- Threat-model new AI features, agent workflows, model integrations, and tool-calling capabilities before they reach production.

- Evaluate risks in RAG pipelines, context assembly, agent memory, system prompts, MCP servers, model providers, and third-party AI frameworks.

- Build repeatable adversarial evaluations and regression tests for discovered vulnerabilities.

- Design controls for least-privilege tool access, scoped credentials, sandboxing, runtime policy enforcement, and human approval.

- Ensure model output is validated before it reaches databases, APIs, executable systems, or customer-visible workflows.

- Improve auditability across model calls, retrieved context, tool invocations, agent decisions, and resulting actions.

- Monitor emerging AI attack techniques and translate relevant risks into practical product controls.

PRODUCT SECURITY

- Review customer-facing applications and APIs for authentication, authorization, tenant-isolation, injection, and business-logic vulnerabilities.

- Secure customer-controlled payloads, file uploads, webhooks, exports, and third-party integrations.

- Reproduce security reports, determine credible impact, and distinguish exploitable vulnerabilities from theoretical findings.

- Work directly with engineers to implement production-ready fixes and regression tests.

- Help build secure, reusable patterns for input handling, authorization, secrets, data access, and external integrations.

- Perform focused code reviews, penetration tests, and architecture assessments for security-sensitive changes.

PLATFORM AND INFRASTRUCTURE

- Build and improve the secure, reliable infrastructure behind model calls and agent workflows.

- Harden cloud permissions, service identities, secrets, storage, networking, deployment pipelines, and production access.

- Build guardrails into CI/CD and infrastructure-as-code so common security problems are caught before deployment.

- Improve model-provider routing, retries, timeouts, fallbacks, quotas, rate limits, and cost controls.

- Add observability for unusual model behavior, tool usage, data access, errors, latency, and token consumption.

- Build containment mechanisms and kill switches for unsafe or misbehaving agents.

- Support production debugging and the investigation of application, infrastructure, and AI-security incidents.

WHAT WE’RE LOOKING FOR

- 2–3 years of hands-on experience across AI engineering, backend/platform engineering, application security, infrastructure security, DevSecOps, or a related engineering role.

- Experience building, operating, or securing production AI systems using LLM APIs, agents, tool calling, RAG, model gateways, or similar technologies.

- Strong programming ability in Python, TypeScript, Go, or another relevant language.

- Understanding of common web and API security risks, including authentication, authorization, injection, tenant isolation, secrets, and unsafe data handling.

- Practical experience with cloud infrastructure, CI/CD, containers, monitoring, or infrastructure-as-code.

- Ability to investigate a suspected vulnerability, reproduce it, assess its real-world impact, and contribute an effective fix.

- Ability to reason about trust boundaries between users, models, customer data, application code, tools, and third-party services.

- Comfort debugging systems through source code, logs, traces, metrics, and database queries.

- Strong written communication and the ability to explain security risks clearly without unnecessary alarm.

- A builder’s mindset: you enjoy implementing durable controls, not only identifying problems.

We care more about strong fundamentals, practical work, and learning velocity than matching every item in the description.

GOOD TO HAVE

- Hands-on experience with AI red teaming or adversarial model testing.

- Familiarity with prompt injection, insecure output handling, tool-use vulnerabilities, agent sandboxing, or context leakage.

- Experience securing multi-tenant B2B SaaS products.

- Experience with OAuth, webhooks, file processing, MCP, and third-party integrations.

- Experience building security test harnesses, fuzzers, automated evaluations, or internal security tools.

- Familiarity with SAST, DAST, dependency scanning, secret scanning, or infrastructure scanning.

- Experience with model gateways, multi-provider routing, AI observability, or LLM evaluations.

- Participation in bug bounties, CTFs, security research, or relevant open-source projects.

- Familiarity with SOC 2 or ISO 27001 from an engineering implementation perspective.

EXAMPLE PROJECTS

You might work on projects such as:

- Build a test harness that injects malicious instructions through prompts, uploaded files, and retrieved documents.

- Find and eliminate a path through which one tenant’s information could enter another tenant’s model context.

- Introduce capability-scoped credentials so agents receive access only to the data and tools required for a specific task.

- Add security regression evaluations for previously discovered AI vulnerabilities.

- Build validation and containment around model-generated JSON, XML, queries, scripts, or API payloads.

- Prevent untrusted content from triggering sensitive tool calls without deterministic authorization.

- Build traceability from user input through model context, output, tool execution, and final side effects.

- Detects unusual tool-call sequences, data-access patterns, agent loops, or token consumption.

- Threat-model a new agent capability and implement the required controls before launch.

- Turn a recurring vulnerability class into a reusable platform guardrail.

WHAT SUCCESS LOOKS LIKE

In your first three months, you will:

- Understand the major trust boundaries across Metaforms’ AI agents, customer data, tools, and infrastructure.

- Build an initial threat model and prioritized AI-security testing plan.

- Reproduce and help remediate high-priority product or AI vulnerabilities.

- Add high-signal security tests for important agent and application boundaries.

- Improve visibility into model calls, tool usage, and security-relevant agent behavior.

Over time, you will:

- Build continuous adversarial testing into how Metaforms develops AI features.

- Reduce recurring vulnerability classes through reusable controls and secure defaults.

- Help engineers ship AI capabilities quickly without weakening customer-data boundaries.

- Develop into a technical owner for AI security across the platform.

- Make Metaforms’ agents more secure, observable, reliable, and resilient as their capabilities grow.

WHY JOIN METAFORMS?

- Work on practical AI-security problems in production agent systems.

- Operate across offensive testing, application security, and platform engineering.

- Ship fixes and controls directly rather than producing reports that sit in a queue.

- Work closely with engineering leadership and influence platform design early.

- Take meaningful ownership while growing into an emerging technical specialization.

OUR HIRING PROCESS

The process will focus on practical engineering judgment rather than security trivia:

1. Introductory conversation.

2. Technical discussion covering AI systems, security fundamentals, and past projects.

3. Practical exercise involving a simplified agent workflow, its trust boundaries, likely attack paths, and one proposed or implemented control.

4. Final conversation with engineering leadership.

Break AI systems like an attacker. Fix them like a platform engineer.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Metaforms's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Metaforms's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Metaforms's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.