# Senior Application Security Engineer, AI and Machine Learning

[Lightningai](https://gurify.com/jobs?q=Lightningai) · San Francisco, United States · Posted 5 months ago

Senior

[AI & ML](https://gurify.com/jobs/ai-ml)

[Security](https://gurify.com/jobs/security)

[Apply on the original posting → (opens in a new tab)](https://job-boards.greenhouse.io/lightningai/jobs/7687112003)

## Job description

### Who We Are

Lightning AI is the company behind PyTorch Lightning. Founded in 2019, we build an end-to-end platform for developing, training, and deploying AI systems—designed to take ideas from research to production with less friction.

Through our merger with Voltage Park, a neocloud and AI Factory, Lightning AI combines developer-first software with cost-efficient, large-scale compute. Teams get the tools they need for experimentation, training, and production inference, with security, observability, and control built in.

We serve solo researchers, startups, and large enterprises. Lightning AI operates globally with offices in New York City, San Francisco, Seattle, and London, and is backed by Coatue, Index Ventures, Bain Capital Ventures, and Firstminute.

### The Way We Work

The people who thrive here are builders who move fast, communicate openly, take ownership, and continuously improve themselves, their teams, and our company. Here's what that looks like in practice:

- Move with Urgency: We move quickly, make thoughtful decisions, and keep momentum. We value action over perfection and learn by shipping.

- Take Ownership: We own outcomes, not just our individual work. We make decisions that move the company forward and follow through.

- Communicate Openly: We communicate directly, seek to understand, and create clarity for others. Honest conversations help us move faster together.

- Build Great Teams: We lead by example, empower others, and create healthy teams where people can do their best work.

- Raise the Bar: We're always improving ourselves. We learn from feedback, consistently challenge ourselves to grow, and focus on the work that matters most.

- Think Long-Term: We design for what's next. We create scalable systems, simplify complexity, and use AI and automation to amplify our impact.

### What We're Looking For

We are looking for a Senior Application Security Engineer to help secure our AI, machine learning, and inference platforms. This is a hands on technical role focused on building security into modern AI infrastructure, inference systems, and developer platforms.

You will work closely with platform engineers, ML engineers, and infrastructure teams to identify risks, design secure architectures, and build security tooling that enables engineers to move quickly and safely.

This role is execution focused. You will drive technical implementation, perform deep security reviews, and help build out our application security capabilities alongside the CISO and engineering leadership.

This role is hybrid out of our Seattle or San Francisco offices, with an in-office requirement of at least 2 days per week and occasional team and company offsites. We are not able to provide visa sponsorship for this role at this time.

### What You’ll Do

### Secure AI and Machine Learning Systems

- Perform threat modeling across AI platforms, inference services, and ML pipelines

- Identify risks such as prompt injection, model extraction, adversarial inputs, and data leakage

- Review model serving architectures and inference pipelines

- Partner with ML engineers to secure training, fine tuning, and deployment workflows

- Help design isolation and security controls for multi tenant AI workloads

### Application Security Engineering

- Perform architecture and design security reviews

- Conduct targeted code reviews for high risk components

- Identify security gaps in APIs, micro-services, and distributed systems

- Build secure patterns for authentication, authorization, and service to service communication

- Help engineering teams implement secure defaults and guardrails

### Inference Platform Security

- Secure customer facing inference APIs and services

- Protect against abuse, model extraction, and adversarial behavior

- Design rate limiting, isolation, and workload protection controls

- Build monitoring and detection for anomalous inference behavior

### AI Supply Chain and Model Security

- Evaluate open source models and dependencies

- Secure model artifacts and distribution pipelines

- Implement integrity validation and provenance controls

- Help secure container images and runtime environments

### Security Automation and Tooling

- Build security automation for AI and application pipelines

- Integrate security scanning into CI/CD workflows

- Develop tooling to help engineers detect and fix issues early

- Improve developer experience with security guardrails

### What You'll Need

### Required Experience

- Strong background in application security engineering

- Experience performing threat modeling and architecture reviews

- Experience securing APIs and distributed systems

- Experience working in cloud environments such as AWS, GCP, or Azure

- Experience with containers and Kubernetes

- Strong scripting or programming skills such as Python, Go, or similar

- Experience working closely with engineering teams to implement security improvements

### AI and Machine Learning Experience

- Experience securing ML pipelines, inference systems, or data platforms

- Familiarity with risks such as prompt injection, model extraction, and adversarial inputs

- Experience reviewing model serving architectures

- Understanding of training data security and data leakage risks

### It's a Strong Plus If You Have

- Red team or offensive security experience

- Experience crafting payloads and evaluating CVEs for exploitability in diverse environments

- Experience with GPU infrastructure or high performance computing

- Experience with Hugging Face, PyTorch, TensorFlow, or similar frameworks

- Experience with LLM systems, RAG pipelines, or agent frameworks

- Experience building security automation pipelines

- Experience securing multi tenant infrastructure

##

### What Success Looks Like

- Security is embedded into AI platform architecture early

- Engineering teams ship quickly with secure defaults

- Inference platforms are resilient against abuse and extraction

- Model pipelines are secure and auditable

- Security tooling scales with engineering growth

##

### Why This Role Matters

This role sits at the intersection of application security, AI infrastructure, and developer platforms. You will help define how we secure modern AI systems while enabling engineers to move quickly and safely.

You will work closely with engineering leadership and the CISO to build practical, scalable security capabilities that support rapid innovation in AI and machine learning.

### Compensation

We are committed to offering competitive compensation that reflects the value each team member brings to our mission. Final offers are based on factors such as experience, skills, geographic location, and role expectations. In addition to base salary, our total rewards package for eligible roles includes a discretionary bonus, a meaningful equity component, and comprehensive benefits.

The anticipated annual base salary range for this role is:

$180,000—$220,000 USD

### Benefits and Perks

We offer a comprehensive and competitive benefits package designed to support our employees’ health, well-being, and long-term success:

- Comprehensive Health Coverage: Medical, dental, and vision coverage for employees and eligible dependents.

- Meaningful Equity: RSUs that give employees a stake in the company's long-term success.

- Retirement Savings: 401(k) matching (U.S.) and pension contributions (U.K.).

- Flexible Time Off: Unlimited PTO, company holidays, and floating holidays to support work-life balance.

- Company-Wide Winter Break: Two weeks of company closure each winter to disconnect and recharge.

- Paid Parental & Family Leave: Paid leave to support you and your family through life's important moments.

- Professional Development: Annual learning and development allowance to support your professional growth.

- Wellness Benefits: Wellness and work-from-home stipends to support your physical and mental well-being.

- Sabbatical Program: Four weeks of paid sabbatical leave after four years of service.

- Flexible Work: Flexible schedules and a hybrid work model for our office-based teams.

- In-Office Meals: Complimentary meals at our office hubs.

Benefits may vary by location, team, and role.

At Lightning AI, we are committed to fostering an inclusive and diverse workplace. We believe that diverse teams drive innovation and create better products. We provide equal employment opportunities to all employees and applicants without regard to race, color, religion, gender, sexual orientation, gender identity, national origin, age, disability, veteran status, or any other protected characteristic. We are dedicated to building a culture where everyone can thrive and contribute to their fullest potential.

**Live in Lightningai’s hiring system.** Read from the company's own applicant tracking system, not reposted from a job board — so it's a real, open requisition rather than an ad that outlived the role.

We remove it as soon as it disappears at source.

## More jobs like this

- SP [Staff Machine Learning Engineer - Music Mission](https://gurify.com/job/staff-machine-learning-engineer-music-mission-at-spotify-ea58201fe986) Spotify · New York, NY · 5 weeks ago
- RI [Software Engineer, GPU Kernels](https://gurify.com/job/software-engineer-gpu-kernels-at-riverai-d38198190289) Riverai · Palo Alto, CA · last week
- JA [Machine Learning Engineer :: Jane Street](https://gurify.com/job/machine-learning-engineer-jane-street-at-janestreet-e23d7ec8f3d1) Janestreet · New York, United States · 2 months ago
- AD [Staff AI Security Engineer](https://gurify.com/job/staff-ai-security-engineer-at-addepar1-b9f9ad310cbf) Addepar1 · Remote, United States · 5 weeks ago
- LI [Data Engineer](https://gurify.com/job/data-engineer-at-lightningai-e16de6fd0458) Lightningai · New York, United States · 2 months ago
- SH [Technical Program Manager, Maritime](https://gurify.com/job/technical-program-manager-maritime-at-shieldai-37134bfd018e) Shieldai · Washington, DC · 4 days ago

```json
{"@context":"https://schema.org/","@type":"JobPosting","title":"Senior Application Security Engineer, AI and Machine Learning","description":"\u003Ch3\u003EWho We Are\u003C/h3\u003E\u003Cp\u003ELightning AI is the company behind PyTorch Lightning. Founded in 2019, we build an end-to-end platform for developing, training, and deploying AI systems\u2014designed to take ideas from research to production with less friction.\u003C/p\u003E\u003Cp\u003EThrough our merger with Voltage Park, a neocloud and AI Factory, Lightning AI combines developer-first software with cost-efficient, large-scale compute. Teams get the tools they need for experimentation, training, and production inference, with security, observability, and control built in.\u003C/p\u003E\u003Cp\u003EWe serve solo researchers, startups, and large enterprises. Lightning AI operates globally with offices in New York City, San Francisco, Seattle, and London, and is backed by Coatue, Index Ventures, Bain Capital Ventures, and Firstminute.\u003C/p\u003E\u003Ch3\u003EThe Way We Work\u003C/h3\u003E\u003Cp\u003EThe people who thrive here are builders who move fast, communicate openly, take ownership, and continuously improve themselves, their teams, and our company. Here\u0026#39;s what that looks like in practice:\u003C/p\u003E\u003Cul\u003E\u003Cli\u003EMove with Urgency: We move quickly, make thoughtful decisions, and keep momentum. We value action over perfection and learn by shipping.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ETake Ownership: We own outcomes, not just our individual work. We make decisions that move the company forward and follow through.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ECommunicate Openly: We communicate directly, seek to understand, and create clarity for others. Honest conversations help us move faster together.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EBuild Great Teams: We lead by example, empower others, and create healthy teams where people can do their best work.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ERaise the Bar: We\u0026#39;re always improving ourselves. We learn from feedback, consistently challenge ourselves to grow, and focus on the work that matters most.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EThink Long-Term: We design for what\u0026#39;s next. We create scalable systems, simplify complexity, and use AI and automation to amplify our impact.\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003EWhat We\u0026#39;re Looking For\u003C/h3\u003E\u003Cp\u003EWe are looking for a Senior Application Security Engineer to help secure our AI, machine learning, and inference platforms. This is a hands on technical role focused on building security into modern AI infrastructure, inference systems, and developer platforms.\u003C/p\u003E\u003Cp\u003EYou will work closely with platform engineers, ML engineers, and infrastructure teams to identify risks, design secure architectures, and build security tooling that enables engineers to move quickly and safely.\u003C/p\u003E\u003Cp\u003EThis role is execution focused. You will drive technical implementation, perform deep security reviews, and help build out our application security capabilities alongside the CISO and engineering leadership.\u003C/p\u003E\u003Cp\u003EThis role is hybrid out of our Seattle or San Francisco offices, with an in-office requirement of at least 2 days per week and occasional team and company offsites. We are not able to provide visa sponsorship for this role at this time.\u003C/p\u003E\u003Ch3\u003EWhat You\u2019ll Do\u003C/h3\u003E\u003Ch3\u003ESecure AI and Machine Learning Systems\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EPerform threat modeling across AI platforms, inference services, and ML pipelines\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EIdentify risks such as prompt injection, model extraction, adversarial inputs, and data leakage\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EReview model serving architectures and inference pipelines\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EPartner with ML engineers to secure training, fine tuning, and deployment workflows\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EHelp design isolation and security controls for multi tenant AI workloads\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003EApplication Security Engineering\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EPerform architecture and design security reviews\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EConduct targeted code reviews for high risk components\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EIdentify security gaps in APIs, micro-services, and distributed systems\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EBuild secure patterns for authentication, authorization, and service to service communication\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EHelp engineering teams implement secure defaults and guardrails\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003EInference Platform Security\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003ESecure customer facing inference APIs and services\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EProtect against abuse, model extraction, and adversarial behavior\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EDesign rate limiting, isolation, and workload protection controls\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EBuild monitoring and detection for anomalous inference behavior\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003EAI Supply Chain and Model Security\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EEvaluate open source models and dependencies\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ESecure model artifacts and distribution pipelines\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EImplement integrity validation and provenance controls\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EHelp secure container images and runtime environments\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003ESecurity Automation and Tooling\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EBuild security automation for AI and application pipelines\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EIntegrate security scanning into CI/CD workflows\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EDevelop tooling to help engineers detect and fix issues early\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EImprove developer experience with security guardrails\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003EWhat You\u0026#39;ll Need\u003C/h3\u003E\u003Ch3\u003ERequired Experience\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EStrong background in application security engineering\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExperience performing threat modeling and architecture reviews\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExperience securing APIs and distributed systems\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExperience working in cloud environments such as AWS, GCP, or Azure\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExperience with containers and Kubernetes\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EStrong scripting or programming skills such as Python, Go, or similar\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExperience working closely with engineering teams to implement security improvements\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003EAI and Machine Learning Experience\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EExperience securing ML pipelines, inference systems, or data platforms\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EFamiliarity with risks such as prompt injection, model extraction, and adversarial inputs\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExperience reviewing model serving architectures\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EUnderstanding of training data security and data leakage risks\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003EIt\u0026#39;s a Strong Plus If You Have\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003ERed team or offensive security experience\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExperience crafting payloads and evaluating CVEs for exploitability in diverse environments\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExperience with GPU infrastructure or high performance computing\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExperience with Hugging Face, PyTorch, TensorFlow, or similar frameworks\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExperience with LLM systems, RAG pipelines, or agent frameworks\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExperience building security automation pipelines\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExperience securing multi tenant infrastructure\u003C/li\u003E\u003C/ul\u003E\u003Cp\u003E##\u003C/p\u003E\u003Ch3\u003EWhat Success Looks Like\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003ESecurity is embedded into AI platform architecture early\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EEngineering teams ship quickly with secure defaults\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EInference platforms are resilient against abuse and extraction\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EModel pipelines are secure and auditable\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ESecurity tooling scales with engineering growth\u003C/li\u003E\u003C/ul\u003E\u003Cp\u003E##\u003C/p\u003E\u003Ch3\u003EWhy This Role Matters\u003C/h3\u003E\u003Cp\u003EThis role sits at the intersection of application security, AI infrastructure, and developer platforms. You will help define how we secure modern AI systems while enabling engineers to move quickly and safely.\u003C/p\u003E\u003Cp\u003EYou will work closely with engineering leadership and the CISO to build practical, scalable security capabilities that support rapid innovation in AI and machine learning.\u003C/p\u003E\u003Ch3\u003ECompensation\u003C/h3\u003E\u003Cp\u003EWe are committed to offering competitive compensation that reflects the value each team member brings to our mission. Final offers are based on factors such as experience, skills, geographic location, and role expectations. In addition to base salary, our total rewards package for eligible roles includes a discretionary bonus, a meaningful equity component, and comprehensive benefits.\u003C/p\u003E\u003Cp\u003EThe anticipated annual base salary range for this role is:\u003C/p\u003E\u003Cp\u003E$180,000\u2014$220,000 USD\u003C/p\u003E\u003Ch3\u003EBenefits and Perks\u003C/h3\u003E\u003Cp\u003EWe offer a comprehensive and competitive benefits package designed to support our employees\u2019 health, well-being, and long-term success:\u003C/p\u003E\u003Cul\u003E\u003Cli\u003EComprehensive Health Coverage: Medical, dental, and vision coverage for employees and eligible dependents.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EMeaningful Equity: RSUs that give employees a stake in the company\u0026#39;s long-term success.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ERetirement Savings: 401(k) matching (U.S.) and pension contributions (U.K.).\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EFlexible Time Off: Unlimited PTO, company holidays, and floating holidays to support work-life balance.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ECompany-Wide Winter Break: Two weeks of company closure each winter to disconnect and recharge.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EPaid Parental \u0026amp; Family Leave: Paid leave to support you and your family through life\u0026#39;s important moments.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EProfessional Development: Annual learning and development allowance to support your professional growth.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EWellness Benefits: Wellness and work-from-home stipends to support your physical and mental well-being.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ESabbatical Program: Four weeks of paid sabbatical leave after four years of service.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EFlexible Work: Flexible schedules and a hybrid work model for our office-based teams.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EIn-Office Meals: Complimentary meals at our office hubs.\u003C/li\u003E\u003C/ul\u003E\u003Cp\u003EBenefits may vary by location, team, and role.\u003C/p\u003E\u003Cp\u003EAt Lightning AI, we are committed to fostering an inclusive and diverse workplace. We believe that diverse teams drive innovation and create better products. We provide equal employment opportunities to all employees and applicants without regard to race, color, religion, gender, sexual orientation, gender identity, national origin, age, disability, veteran status, or any other protected characteristic. We are dedicated to building a culture where everyone can thrive and contribute to their fullest potential.\u003C/p\u003E","identifier":{"@type":"PropertyValue","name":"Gurify","value":"senior-application-security-engineer-ai-and-machine-learning-at-ecbd393f1d2c"},"url":"https://gurify.com/job/senior-application-security-engineer-ai-and-machine-learning-at-ecbd393f1d2c","datePosted":"2026-04-01","validThrough":"2026-11-04T23:59:59Z","hiringOrganization":{"@type":"Organization","name":"Lightningai","sameAs":"https://job-boards.greenhouse.io/lightningai"},"directApply":false,"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressCountry":"US","addressLocality":"San Francisco"}}}
```

```json
{"@context":"https://schema.org/","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Jobs","item":"https://gurify.com/jobs"},{"@type":"ListItem","position":2,"name":"United States","item":"https://gurify.com/jobs/united-states"},{"@type":"ListItem","position":3,"name":"Senior Application Security Engineer, AI and Machine Learning","item":"https://gurify.com/job/senior-application-security-engineer-ai-and-machine-learning-at-ecbd393f1d2c"}]}
```
