Sobre este puesto de AI Security Engineer en Bjak
About BJAK
The original mission of BJAK is we believe people deserve smarter ways to plan, save and grow their money. This is the origin of our name.
Started in 2019, we built the first mobile-first, insurance platform, enabling insurance to be accessible online by millions in the region. Today, its the leading insurance platform in Southeast Asia.
Today, we are expanding ways to help people in the region — this includes spending, saving, investing, exchanging, travelling, and more. Our mission is help people get more from their money every day.
We have teams working around the world, with over 20 nationalities from our offices and remotely, who truly enjoys their work. We are looking for the most talented and driven people we can find. We are looking for people who work for their passion, not counting hours. Who loves building great next-generation products, not status quo. Who cares about redefining how everyone around us can get the best financial applications, not for an exclusive few.
If you're this person, we'd love to talk to you.
The Role
Secure BJAK's AI-enabled products and agent workflows using third-party models. Focus on customer data shared with model providers, agent permissions, user data isolation, and prompt injection through uploaded documents and other untrusted content.
What You Will Build
Assess customer data sent to third-party model vendors, including minimization, vendor controls, retention, logging, and approved use.
Design controls limiting AI agent permissions, tools, actions, and system access using least privilege and explicit authorization.
Implement and test tenant and user data isolation across prompts, conversation history, retrieval, memory, and AI-connected services.
Threat model and test prompt injection and indirect injection through uploaded documents, retrieved content, links, and other untrusted inputs.
Partner with Product and Engineering on safe document ingestion, content handling, output validation, and approval for sensitive actions.
Support SC TRM and BNM RMiT for AI technology risks, including assessments, third-party oversight, control evidence, and remediation.
Build security tests, monitoring, and response procedures for AI misuse, data exposure, unauthorized actions, and vendor incidents.
What We Look For
Degree in Computer Science, Cybersecurity, AI, or related field, or equivalent experience.
3+ years in application security, product security, security engineering, or AI system security.
Experience implementing or owning SC TRM and BNM RMiT controls, technology risk, or regulatory control evidence.
Understanding of third-party LLM integrations, model APIs, agent tools, RAG, and AI application architectures.
Knowledge of prompt injection, indirect injection, cross-user data leakage, excessive agent permissions, and vendor data disclosure risks.
Programming or scripting skills, preferably Python and TypeScript/Node.js, plus APIs and AWS or GCP.
Able to collaborate with Product, Legal, Compliance, Data, and Engineering on practical controls and risk communication.
Language
English is our main working language across global teams. Strong English communication is required.