About this role
Sr. Engineer, AI Cyber Security
Apply
remote type
Off Campus
locations
Remote, USA
time type
Full time
posted on
Posted Today
job requisition id
REQ24327
About This Role
As Biogen's AI Security Engineer, you are a hands-on technical specialist responsible for securing the organization's rapidly expanding use of artificial intelligence, machine learning, and generative AI technologies. This role operates at the intersection of cybersecurity engineering and AI/ML systems — ensuring that AI deployments across Biogen are resilient against adversarial threats, data poisoning, model manipulation, prompt injection, and unauthorized data exposure.
The AI Security Engineer will design, implement, and operate security controls purpose-built for AI workloads — spanning model development pipelines, inference endpoints, training data protection, and AI-assisted automation platforms. This role is responsible for translating emerging AI threat frameworks (MITRE ATLAS, OWASP AI Top 10, NIST AI RMF) into actionable engineering controls that protect Biogen's AI investments without impeding innovation velocity.
This position requires a rare combination of software engineering depth, AI/ML systems knowledge, and cybersecurity expertise. The scope demands:
Deep technical proficiency across AI/ML security, cloud security, and application security — with the ability to build production-grade security tooling, not just assess or advise
Autonomous execution — independently identifying AI security gaps, designing solutions, and implementing them end-to-end without requiring constant direction
Adversarial mindset — thinking like an attacker to identify how AI systems can be subverted, manipulated, or exploited before threat actors do
Cross-domain fluency — bridging the gap between data science teams building AI and security teams protecting the enterprise, translating between both worlds.
What You’ll Do
-
AI Threat Detection & Response Engineering
-
Design, build, and operate detection capabilities for AI-specific threats including prompt injection, model extraction, training data poisoning, and adversarial input attacks
-
Develop and maintain AI security monitoring pipelines that correlate signals across LLM interactions, API gateways, and model inference endpoints
-
Engineer automated response playbooks for AI security incidents — including model quarantine, token revocation, and session termination
-
Continuously research emerging AI attack vectors and translate findings into detection signatures and prevention controls
-
Operate and tune CrowdStrike AI Runtime Defense (AIRD) and Microsoft Purview AI governance controls across the environment
-
AI Platform Security Engineering
-
Implement security controls across AI development and deployment platforms (AWS SageMaker, Azure OpenAI, Databricks, internal ML pipelines)
-
Secure model training environments — including data access controls, compute isolation, artifact signing, and pipeline integrity verification
-
Engineer guardrails for generative AI usage — content filtering, DLP integration, output validation, and session-level access controls
-
Design and enforce AI model governance controls including model registry security, version control integrity, and deployment approval gates
-
Perform security architecture reviews of new AI services and integrations before production deployment
-
AI Risk Assessment & Framework Implementation
-
Conduct technical risk assessments of AI systems using MITRE ATLAS, OWASP AI Top 10, and NIST AI RMF frameworks
-
Perform adversarial testing (red teaming) of AI models and AI-integrated applications to identify vulnerabilities before production deployment
-
Develop and maintain AI security standards, reference architectures, and secure development guidelines for AI/ML teams
-
Evaluate third-party AI services and vendor AI integrations for security posture, data handling practices, and supply chain integrity
-
Security Automation & AI-Augmented Defense
-
Build and maintain AI-powered security tools that augment the cybersecurity team's detection and response capabilities
-
Develop integrations between security platforms (CrowdStrike, Microsoft Defender, Okta, Zscaler) and AI/ML systems for intelligent threat correlation
-
Engineer automated security workflows using LLMs and agentic AI for threat hunting, alert triage, and incident investigation acceleration
-
Contribute to the security team's internal AI capabilities — including MCP server development, agent frameworks, and security data pipelines
-
Build and maintain security scoring engines and risk quantification models that drive prioritization decisions
-
Required Skills
-
5+ years of combined experience in cybersecurity engineering, software engineering, and/or AI/ML systems
-
Demonstrated expertise in at least three of the following domains:
-
AI/ML Security: LLM security, prompt injection mitigation, model robustness testing, adversarial ML, AI supply chain integrity
-
Cloud Security Engineering: AWS, Azure, or GCP security architecture and controls implementation at scale
-
Application Security: Secure SDLC, API security, code review, penetration testing, threat modeling
-
Security Operations: Detection engineering, SIEM/SOAR development, incident response, threat hunting
-
Hands-on proficiency with Python and demonstrable experience building production security tooling and automation
-
Experience with AI/ML frameworks (PyTorch, TensorFlow, Hugging Face, LangChain) and AI cloud services (SageMaker, Azure OpenAI, Bedrock, Databricks)
-
Working knowledge of AI security frameworks: MITRE ATLAS, OWASP AI Top 10, NIST AI RMF
-
Experience with enterprise security platforms (CrowdStrike, Microsoft Defender, Okta, Zscaler, CyberArk, or equivalent)
-
Strong understanding of LLM architectures, retrieval-augmented generation (RAG), fine-tuning security implications, and agentic AI patterns
-
Bachelor's Degree in Computer Science, Cybersecurity, Data Science, or related technical field required
-
Job Level: Management
-
Additional Information
-
The base compensation range for this role is: $140,000.00-$187,250.00
-
Base salary offered is determined through an analytical approach utilizing a combination of factors including, but not limited to, relevant skills & experience, job location, and internal equity.
-
Regular employees are eligible to receive both short term and long-term incentives, including cash bonus and equity incentive opportunities, designed to reward recent achievements and recognize your future potential based on individual, business unit and com