AI Security Engineer
SeniorHybrid
Description
We are
At Cross River, we're building the financial infrastructure that powers global innovation. With our cutting-edge suite of embedded payments, cards, and lending solutions, we enable millions of businesses and consumers to transact seamlessly and securely.
With 900+ employees worldwide and an R&D center of over 160 employees in Jerusalem - we’re reshaping how financial technology is developed and delivered. .
What You Bring to the Table
- 5+ years in Security Engineering/AppSec/Cloud Security (or similar), including 1–2+ years securing AI/ML or data‑intensive systems (GenAI preferred).
- Hands‑on experience with AWS and/or Azure and modern app stacks (Python/TypeScript, REST/gRPC, containers/Kubernetes, IaC such as Terraform).
- Practical understanding of LLM attack surfaces (prompt injection, context and goal poisoning, data leakage via tools, training/fine‑tune poisoning, model supply chain) and mitigation patterns.
- Experience assessing agentic architectures (LangGraph, CrewAI, or similar) and AI coding assistants (Claude Code, GitHub Copilot) for secure enterprise deployment.
- Familiarity with identity and access for AI workloads (OAuth2/OIDC, service principals, role tokens, PIM), and secure secret management/KMS.
- Experience implementing observability/telemetry and routing findings to SIEM; comfort balancing privacy with traceability.
- Ability to translate controls into developer-friendly libraries, docs, and CI/CD checks.
- Comfort working in a regulated environment and mapping controls to frameworks (FFIEC, SOC 2, PCI DSS).
- Strong written communication in English and Hebrew.
##
Nice to have
- Financial services background or other high‑assurance domains.
- Exposure to Duende IdentityServer, SSO/SCIM, and enterprise authorization patterns.
- Familiarity with guardrail tooling (e.g., Azure AI Safety features, Amazon Bedrock Guardrails) and policy engines (OPA/Rego).
- Prior work in AI red‑teaming or safety evaluation harnesses; contributions to OSS or published talks.