AI Systems Security Engineer (agent Systems), Sear

Apple Apple · Big Tech · Cupertino, CA +1 · Software and Services

Seeking an AI Systems Security Engineer to design, build, and deploy security foundations for agentic and tool-using AI systems. This role involves developing architectural controls for agent access to tools, services, and data, ensuring effectiveness against adversarial inputs. The engineer will translate ML security research into robust platform capabilities and production protections, working closely with ML security researchers, AI/ML platform teams, and product security teams. Success is measured by enforceable, testable, and observable security properties in shipping systems.

What you'd actually do

  1. Design security architectures for AI agents that interact with tools, APIs, applications, memory, external content, and sensitive user data.
  2. Build runtime controls for capability authorization, action mediation, least-privilege access, context isolation, data-flow enforcement, and secure tool execution.
  3. Establish clear trust boundaries between models, orchestration components, tools, third-party content, local applications, cloud services, and user data.
  4. Translate ML security research—including findings related to indirect prompt injection, goal hijacking, tool misuse, privilege escalation, persistence, confused-deputy behavior, and cross-context data leakage—into production-ready defenses.
  5. Develop reusable security frameworks and platform primitives that product teams can adopt without implementing bespoke controls for each AI experience.

Skills

Required

  • Bachelor’s degree in computer science, computer engineering, security, or a related field, or equivalent practical experience.
  • Significant experience designing and shipping security-critical systems, platform security mechanisms, or large-scale systems software.
  • Strong understanding of security architecture, trust boundaries, least privilege, authorization, isolation, secure execution, and defense-in-depth.
  • Demonstrated ability to convert threat models and security requirements into reliable production implementations.
  • Strong software engineering skills in one or more systems or platform languages, with experience building maintainable, testable, and performance-sensitive software.
  • Experience working across organizational boundaries to influence architecture and deliver security improvements in complex production systems.

Nice to have

  • Experience securing LLM-based, agentic, tool-using, or other probabilistic AI systems.
  • Experience with capability systems, sandboxing, policy engines, information-flow controls, provenance systems, secure IPC/RPC, or workload isolation.
  • Familiarity with attacks against agent systems, including prompt injection, unauthorized tool use, privilege escalation, data exfiltration, memory poisoning, and multi-stage attacks.
  • Experience building security evaluation infrastructure, fuzzing systems, adversarial test frameworks.

What the JD emphasized

  • security-critical systems
  • architectural controls
  • runtime controls
  • trust boundaries
  • production-ready defenses
  • reusable security frameworks
  • security invariants
  • adversarial testing and validation infrastructure
  • security-focused launch gates
  • security improvements

Other signals

  • designing and shipping security-critical systems
  • architectural controls for agents
  • runtime controls for capability authorization
  • adversarial testing and validation infrastructure