Senior Infrastructure Security Engineer

Dropbox Dropbox · Enterprise · Canada +1 · Security (Sub Team)

Senior Infrastructure Security Engineer responsible for designing, deploying, and operating security controls for Dropbox's AI and agentic infrastructure, including model gateways, inference services, vector stores, and retrieval systems. The role involves implementing least-privilege and secure-execution patterns for AI agents, leading security implementation for AI tool and agent connectivity, and automating security controls. Requires experience securing LLM, RAG, or agentic AI systems in production and designing identity and authorization for non-human workloads.

What you'd actually do

  1. Design, deploy, and operate security controls for Dropbox’s AI and agentic infrastructure, including model gateways, inference services, vector stores, retrieval systems, and supporting cloud and Kubernetes platforms.
  2. Implement least-privilege and secure-execution patterns for AI agents, including per-tool authorization, sandboxing, human-in-the-loop approvals for high-impact actions, and separation of policy validation from execution.
  3. Lead security implementation for AI tool and agent connectivity layers, including MCP gateway deployments, with controls for OAuth-based authorization, scope minimization, token audience validation, origin validation, replay protection, and secure isolation between trusted and untrusted tool domains.
  4. Deploy, build, and/or operate security infrastructure solutions to help scale and raise the security bar for Dropbox’s on-prem and cloud infrastructure.
  5. Automate security controls using scripting to eliminate redundant work and minimize need for human involvement.

Skills

Required

  • Security experience
  • Coding proficiency
  • Experience securing LLM, RAG, or agentic AI systems in production
  • Hands-on implementation of controls for prompt injection, sensitive-data disclosure, excessive agency, data or model poisoning, and AI supply-chain risk
  • Experience designing identity and authorization for non-human workloads and agents
  • Integrate adversarial testing and release gates for AI systems into CI/CD
  • Solid knowledge of Linux fundamentals
  • Proficiency using one or more scripting or high-level languages to automate tasks, manipulate data, or build small systems e.g. Bash, Python, Go, Rust, Ruby, NodeJS, C/C++, Java

Nice to have

  • Experience securing MCP-based systems or similar AI agent and tool protocols
  • Experience with multi-agent security controls
  • Familiarity with NIST AI RMF, NIST SP 800-218A, MITRE ATLAS, CSA AICM, and OWASP LLM and agentic security guidance
  • Experience with security tools such as Teleport, CrowdStrike, Proofpoint, IPS/IDS, SIEM or SOAR
  • Certifications such as CISSP, CISM, or equivalent

What the JD emphasized

  • Experience securing LLM, RAG, or agentic AI systems in production
  • Experience designing identity and authorization for non-human workloads and agents
  • Integrate adversarial testing and release gates for AI systems into CI/CD

Other signals

  • AI infrastructure security
  • Agentic AI security
  • LLM security controls
  • Security for RAG systems
  • Identity and authorization for non-human workloads