The Role
As a Security Engineer at Aily, you are a software engineer with deep security expertise. We are not looking for people who configure existing tools; we need engineers who write productionquality code to solve hard security problems in an AI-first company.
You will face problems of the AI age: securing complex data flows across distributed systems, protecting AI models and training pipelines, building detection logic against real threats, and designing products that handle highly regulated data safely. You will own projects from design through deployment and work closely with Engineering, Data Science, Platform, and Product teams.
Where You’ll Specialize
Our Security Engineering team operates across four tracks. You’ll share your preference during the process; we’ll confirm fit and align on where you’ll have the most impact
Platform Security
Build the security infrastructure that protects Aily’s cloud platform, AI pipelines, and data ecosystem.
- Design and build security automation systems and platforms — from control monitoring to advanced threat detection capabilities or agentic red teaming
- Secure complex data flows, data lakes, and AI training pipelines; implement DLP strategies at scale
- Protect AI models from adversarial attacks, data poisoning, and unauthorized access
- Implement cloud security controls for AWS environments and codify security policies through Infrastructure as Code
Embed security into our AI-powered products from the start, working closely with Product andR&D teams.
- Design security architectures for AI/ML systems handling regulated data
- Conduct threat models and security architecture reviews across all engineering teams
- Design authentication and authorization architectures (SSO, OAuth/OIDC, RBAC/ABAC) and review third-party integrations
- Ensure GDPR/CCPA/EU AI Act compliance and integrate SAST/DAST into CI/CD pipelines
Write production-quality code to build the detection logic and agentic observability platform that keeps Aily ahead of threats.
- Design detection strategies against real attacker TTPs — from signal engineering to response workflows
- Build and operate an AI-native, agentic Security & Governance Observability Platform with autonomous agents that ingest telemetry, correlate signals, and execute responses
- Build data pipelines for security telemetry at scale and design intelligent automation that eliminates repetitive work
- Design incident response playbooks and automated remediation workflows across endpoint, cloud, and identity domains
Protect corporate infrastructure, ensure secure and well-architected business systems, and govern company-wide AI usage and agentic tooling.
- Design and implement security controls for corporate infrastructure — MDM, identity management, endpoint security, and access control architectures
- Build security automation and tooling for compliance and policy enforcement across corporate systems
- Define and enforce policies for company-wide AI usage and agentic tooling — ensuring safe adoption, data boundaries, and governance guardrails
- Review and validate architectural decisions for business systems (HRIS, CRM, Finance, Legal, BI) from Security and Data Architecture perspectives
- Provide Enterprise Architecture governance — ensuring business systems meet security and architectural standards through review, patterns, and guidance
