# AI Security Engineer

[Crossriver](https://gurify.com/jobs?q=Crossriver) · Jerusalem, Israel · Posted last week

[AI & ML](https://gurify.com/jobs/ai-ml)

[Security](https://gurify.com/jobs/security)

[Apply on the original posting → (opens in a new tab)](https://www.comeet.com/jobs/crossriver/C7.00F/ai-security-engineer/53.E6A)

## Job description

### We are

At Cross River, we're building the financial infrastructure that powers global innovation. With our cutting-edge suite of embedded payments, cards, and lending solutions, we enable millions of businesses and consumers to transact seamlessly and securely.

With 900+ employees worldwide and an R&D center of over 160 employees in Jerusalem - we’re reshaping how financial technology is developed and delivered. .

### The Role

As AI capabilities accelerate across the bank, we need an engineer to design and enforce safe AI usage—protecting customer data, preserving model integrity, and meeting our regulatory obligations. You'll be the architect of guardrails, tooling, and policies that make AI both secure and useful for product and internal teams. This isn't about slowing things down; it's about building the trust layer that lets innovation move fast without breaking things.

### Who You Are

You're a security engineer who's excited about the AI wave—someone who sees LLMs and Agentic AI as fascinating puzzles to secure, not just threats to mitigate. You've spent 5+ years in Security Engineering, AppSec, or Cloud Security, and at least 1–2 of those years have been spent getting your hands dirty with LLMs, AI Agents and MCPs.

You understand how agentic frameworks (LangGraph, CrewAI, AutoGen, and similar) orchestrate multi-step tool use—and where trust boundaries break down. You've assessed or secured AI-powered coding agents (Claude Code, GitHub Copilot, Cursor) and understand the unique risks of AI with filesystem, terminal, and API access in developer environments.

You're equally comfortable dissecting a prompt injection attack as you are writing a Terraform module or shipping a Python library. You know your way around AWS and/or Azure, modern app stacks (Python/TypeScript, REST/gRPC, containers/Kubernetes), and can translate security requirements into developer-friendly tooling—not just PDF policies that gather dust.

You communicate clearly in English and Hebrew, thrive in regulated environments, and understand that security in financial services means mapping controls to frameworks like FFIEC, SOC 2, and PCI DSS—and actually having the evidence to prove it.

### What You’ll Actually Be Doing

- Design enterprise AI guardrails across Azure and AWS (e.g., Azure AI Studio/Azure OpenAI, Amazon Bedrock/SageMaker): content filtering, PII redaction, prompt/response validation, and policy enforcement services.

- Assess and define secure usage patterns and data governance controls for agentic frameworks and coding agents: permission scoping, tool-call authorization, least‐privileged retrieval, session isolation, and MCP server governance.

- Threat model AI systems (apps, agents, MCPs, RAG, fine-tuning pipelines) using frameworks like STRIDE and the OWASP Top 10 for LLM Apps; define misuse scenarios (prompt injection/context poisoning/jailbreaks/data exfiltration) and build mitigations.

- Build monitoring and telemetry: privacy-preserving prompt/response logging, sensitive-data detection, safety/eval dashboards, drift/abuse signals, and incident hooks into our SIEM.

- Integrate AI security into the SDLC: reusable libraries, pre-commit checks, CI/CD gates, policy-as-code, and secure-by-default reference architectures for product teams.

- Evaluate third‑party AI vendors and internal apps: security reviews, data residency and retention requirements, SSO/SCIM integrations, DPA/TPRM inputs, and continuous control testing.

- Partner across Security, Data, Privacy, and Engineering to map AI controls to FFIEC, SOC 2, and PCI DSS; document control evidence for audits.

- Lead/participate in AI red‑teaming: automated jailbreak/prompt‑injection tests, safety benchmarks, purple‑team exercises, and response playbooks for AI incidents.

- Enable the org with concise guidelines, examples, and training on safe AI development and usage.

### Requirements

### What You Bring to the Table

- 5+ years in Security Engineering/AppSec/Cloud Security (or similar), including 1–2+ years securing AI/ML or data‑intensive systems (GenAI preferred).

- Hands‑on experience with AWS and/or Azure and modern app stacks (Python/TypeScript, REST/gRPC, containers/Kubernetes, IaC such as Terraform).

- Practical understanding of LLM attack surfaces (prompt injection, context and goal poisoning, data leakage via tools, training/fine‑tune poisoning, model supply chain) and mitigation patterns.

- Experience assessing agentic architectures (LangGraph, CrewAI, or similar) and AI coding assistants (Claude Code, GitHub Copilot) for secure enterprise deployment.

- Familiarity with identity and access for AI workloads (OAuth2/OIDC, service principals, role tokens, PIM), and secure secret management/KMS.

- Experience implementing observability/telemetry and routing findings to SIEM; comfort balancing privacy with traceability.

- Ability to translate controls into developer-friendly libraries, docs, and CI/CD checks.

- Comfort working in a regulated environment and mapping controls to frameworks (FFIEC, SOC 2, PCI DSS).

- Strong written communication in English and Hebrew.

##

### Nice to have

- Financial services background or other high‑assurance domains.

- Exposure to Duende IdentityServer, SSO/SCIM, and enterprise authorization patterns.

- Familiarity with guardrail tooling (e.g., Azure AI Safety features, Amazon Bedrock Guardrails) and policy engines (OPA/Rego).

- Prior work in AI red‑teaming or safety evaluation harnesses; contributions to OSS or published talks.

### Why You’ll Love Working Here

- Flexible hybrid work model: three days a week at our Jerusalem office

- Monthly wellness reimbursement – from therapy to gel manicure, it's up to you

- Full Keren Hishtalmut, private health and dental insurance

- Volunteer days, donation matching, Yoga and Pilates

- A supportive, collaborative culture that puts our people first

### Next Step

Hit Apply!

**Live in Crossriver’s hiring system.** Read from the company's own applicant tracking system, not reposted from a job board — so it's a real, open requisition rather than an ad that outlived the role.

We remove it as soon as it disappears at source.

## More jobs like this

- ZE [AI Agent Security | Product Security Engineer](https://gurify.com/job/ai-agent-security-product-security-engineer-at-zenity-f5b9cf85b08a) Zenity · Tel Aviv-Jaffa, Israel · last week
- SA [Machine Learning Engineer](https://gurify.com/job/machine-learning-engineer-at-samsung-d5388bead839) Samsung · Tel Aviv-Yafo, Israel · last week
- SO [AI Backend Engineer](https://gurify.com/job/ai-backend-engineer-at-somekhchaikin-0dc34950d02b) Somekhchaikin · Tel Aviv-Yafo, Israel · last week
- ZE [AI Agent Security | Senior Product Manager](https://gurify.com/job/ai-agent-security-senior-product-manager-at-zenity-8cc8d512e1f0) Zenity · Tel Aviv-Jaffa, Israel · last week
- VA [Senior DevOps Engineer](https://gurify.com/job/senior-devops-engineer-at-viz-ai-3ab32c1a2128) Viz AI · Tel Aviv, Israel · 4 days ago
- SE [Senior Python AI Engineer (LLM & Multi-Agent Systems)](https://gurify.com/job/senior-python-ai-engineer-llm-multi-agent-systems-at-seekingalpha-7bcf0e57d982) Seekingalpha · Ra'anana, Israel · 3 weeks ago

```json
{"@context":"https://schema.org/","@type":"JobPosting","title":"AI Security Engineer","description":"\u003Ch3\u003EWe are\u003C/h3\u003E\u003Cp\u003EAt Cross River, we\u0026#39;re building the financial infrastructure that powers global innovation. With our cutting-edge suite of embedded payments, cards, and lending solutions, we enable millions of businesses and consumers to transact seamlessly and securely.\u003C/p\u003E\u003Cp\u003EWith 900\u002B employees worldwide and an R\u0026amp;D center of over 160 employees in Jerusalem - we\u2019re reshaping how financial technology is developed and delivered. .\u003C/p\u003E\u003Ch3\u003EThe Role\u003C/h3\u003E\u003Cp\u003EAs AI capabilities accelerate across the bank, we need an engineer to design and enforce safe AI usage\u2014protecting customer data, preserving model integrity, and meeting our regulatory obligations. You\u0026#39;ll be the architect of guardrails, tooling, and policies that make AI both secure and useful for product and internal teams. This isn\u0026#39;t about slowing things down; it\u0026#39;s about building the trust layer that lets innovation move fast without breaking things.\u003C/p\u003E\u003Ch3\u003EWho You Are\u003C/h3\u003E\u003Cp\u003EYou\u0026#39;re a security engineer who\u0026#39;s excited about the AI wave\u2014someone who sees LLMs and Agentic AI as fascinating puzzles to secure, not just threats to mitigate. You\u0026#39;ve spent 5\u002B years in Security Engineering, AppSec, or Cloud Security, and at least 1\u20132 of those years have been spent getting your hands dirty with LLMs, AI Agents and MCPs.\u003C/p\u003E\u003Cp\u003EYou understand how agentic frameworks (LangGraph, CrewAI, AutoGen, and similar) orchestrate multi-step tool use\u2014and where trust boundaries break down. You\u0026#39;ve assessed or secured AI-powered coding agents (Claude Code, GitHub Copilot, Cursor) and understand the unique risks of AI with filesystem, terminal, and API access in developer environments.\u003C/p\u003E\u003Cp\u003EYou\u0026#39;re equally comfortable dissecting a prompt injection attack as you are writing a Terraform module or shipping a Python library. You know your way around AWS and/or Azure, modern app stacks (Python/TypeScript, REST/gRPC, containers/Kubernetes), and can translate security requirements into developer-friendly tooling\u2014not just PDF policies that gather dust.\u003C/p\u003E\u003Cp\u003EYou communicate clearly in English and Hebrew, thrive in regulated environments, and understand that security in financial services means mapping controls to frameworks like FFIEC, SOC 2, and PCI DSS\u2014and actually having the evidence to prove it.\u003C/p\u003E\u003Ch3\u003EWhat You\u2019ll Actually Be Doing\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EDesign enterprise AI guardrails across Azure and AWS (e.g., Azure AI Studio/Azure OpenAI, Amazon Bedrock/SageMaker): content filtering, PII redaction, prompt/response validation, and policy enforcement services.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EAssess and define secure usage patterns and data governance controls for agentic frameworks and coding agents: permission scoping, tool-call authorization, least\u2010privileged retrieval, session isolation, and MCP server governance.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EThreat model AI systems (apps, agents, MCPs, RAG, fine-tuning pipelines) using frameworks like STRIDE and the OWASP Top 10 for LLM Apps; define misuse scenarios (prompt injection/context poisoning/jailbreaks/data exfiltration) and build mitigations.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EBuild monitoring and telemetry: privacy-preserving prompt/response logging, sensitive-data detection, safety/eval dashboards, drift/abuse signals, and incident hooks into our SIEM.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EIntegrate AI security into the SDLC: reusable libraries, pre-commit checks, CI/CD gates, policy-as-code, and secure-by-default reference architectures for product teams.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EEvaluate third\u2011party AI vendors and internal apps: security reviews, data residency and retention requirements, SSO/SCIM integrations, DPA/TPRM inputs, and continuous control testing.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EPartner across Security, Data, Privacy, and Engineering to map AI controls to FFIEC, SOC 2, and PCI DSS; document control evidence for audits.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ELead/participate in AI red\u2011teaming: automated jailbreak/prompt\u2011injection tests, safety benchmarks, purple\u2011team exercises, and response playbooks for AI incidents.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EEnable the org with concise guidelines, examples, and training on safe AI development and usage.\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003ERequirements\u003C/h3\u003E\u003Ch3\u003EWhat You Bring to the Table\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003E5\u002B years in Security Engineering/AppSec/Cloud Security (or similar), including 1\u20132\u002B years securing AI/ML or data\u2011intensive systems (GenAI preferred).\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EHands\u2011on experience with AWS and/or Azure and modern app stacks (Python/TypeScript, REST/gRPC, containers/Kubernetes, IaC such as Terraform).\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EPractical understanding of LLM attack surfaces (prompt injection, context and goal poisoning, data leakage via tools, training/fine\u2011tune poisoning, model supply chain) and mitigation patterns.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExperience assessing agentic architectures (LangGraph, CrewAI, or similar) and AI coding assistants (Claude Code, GitHub Copilot) for secure enterprise deployment.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EFamiliarity with identity and access for AI workloads (OAuth2/OIDC, service principals, role tokens, PIM), and secure secret management/KMS.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExperience implementing observability/telemetry and routing findings to SIEM; comfort balancing privacy with traceability.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EAbility to translate controls into developer-friendly libraries, docs, and CI/CD checks.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EComfort working in a regulated environment and mapping controls to frameworks (FFIEC, SOC 2, PCI DSS).\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EStrong written communication in English and Hebrew.\u003C/li\u003E\u003C/ul\u003E\u003Cp\u003E##\u003C/p\u003E\u003Ch3\u003ENice to have\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EFinancial services background or other high\u2011assurance domains.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExposure to Duende IdentityServer, SSO/SCIM, and enterprise authorization patterns.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EFamiliarity with guardrail tooling (e.g., Azure AI Safety features, Amazon Bedrock Guardrails) and policy engines (OPA/Rego).\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EPrior work in AI red\u2011teaming or safety evaluation harnesses; contributions to OSS or published talks.\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003EWhy You\u2019ll Love Working Here\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EFlexible hybrid work model: three days a week at our Jerusalem office\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EMonthly wellness reimbursement \u2013 from therapy to gel manicure, it\u0026#39;s up to you\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EFull Keren Hishtalmut, private health and dental insurance\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EVolunteer days, donation matching, Yoga and Pilates\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EA supportive, collaborative culture that puts our people first\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003ENext Step\u003C/h3\u003E\u003Cp\u003EHit Apply!\u003C/p\u003E","identifier":{"@type":"PropertyValue","name":"Gurify","value":"ai-security-engineer-at-crossriver-14ec056f6cbd"},"url":"https://gurify.com/job/ai-security-engineer-at-crossriver-14ec056f6cbd","datePosted":"2026-07-29","validThrough":"2026-09-24T23:59:59Z","hiringOrganization":{"@type":"Organization","name":"Crossriver","sameAs":"https://www.comeet.com/jobs/crossriver"},"directApply":false,"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressCountry":"IL","addressLocality":"Jerusalem"}}}
```

```json
{"@context":"https://schema.org/","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Jobs","item":"https://gurify.com/jobs"},{"@type":"ListItem","position":2,"name":"Israel","item":"https://gurify.com/jobs/israel"},{"@type":"ListItem","position":3,"name":"AI Security Engineer","item":"https://gurify.com/job/ai-security-engineer-at-crossriver-14ec056f6cbd"}]}
```
