Metaforms · Posted today
AI Security & Platform Engineer
The posting
key requirement, as the employer wrote it
ABOUT METAFORMS Metaforms builds AI infrastructure for research delivery teams.
Our agents help market research agencies and sample providers execute complex workflows with greater speed, consistency, and scale.
As these agents interact with customer data, files, APIs, integrations, and other tools, security must be built into every layer of the platform.
We are looking for an engineer who is excited about understanding how AI systems can fail—and building the controls that make them safe, reliable, and secure by default.
ABOUT THE ROLE We’re looking for an AI Security & Platform Engineer to help secure the AI agents and infrastructure behind Metaforms.
You will test our AI systems adversarially, identify vulnerabilities across prompts, context, data, tools, integrations, and execution environments, and work with engineers to fix them properly.
You will also build platform-level controls, automated evaluations, monitoring, and secure infrastructure that prevent similar vulnerabilities from recurring.
This is a hands-on engineering role, not a policy or compliance position.
You will write code, inspect production systems, reproduce vulnerabilities, build security tooling, and contribute directly to product and infrastructure improvements.
You will work closely with engineering leadership and gradually take ownership of larger AI security and platform initiatives.
WHAT YOU’LL WORK ON AI AND AGENT SECURITY - Adversarially test AI agents for prompt injection, context poisoning, unsafe tool use, data leakage, memory manipulation, and unintended behavior. - Identify security risks introduced through customer prompts, uploaded files, retrieved content, external links, integrations, and model-generated outputs. - Test whether agents can access unauthorized tools, records, tenants, credentials, or internal services. - Threat-model new AI features, agent workflows, model integrations, and tool-calling capabilities before they reach production. - Evaluate risks in RAG pipelines, context assembly, agent memory, system prompts, MCP servers, model providers, and third-party AI frameworks. - Build repeatable adversarial evaluations and regression tests for discovered vulnerabilities. - Design controls for least-privilege tool access, scoped credentials, sandboxing, runtime policy enforcement, and human approval. - Ensure model output is validated before it reaches databases, APIs, executable systems, or customer-visible workflows. - Improve auditability across model calls, retrieved context, tool invocations, agent decisions, and resulting actions. - Monitor emerging AI attack techniques and translate relevant risks into practical product controls.
PRODUCT SECURITY - Review customer-facing applications and APIs for authentication, authorization, tenant-isolation, injection, and business-logic vulnerabilities. - Secure customer-controlled payloads, file uploads, webhooks, exports, and third-party integrations. - Reproduce security reports, determine credible impact, and distinguish exploitable vulnerabilities from theoretical findings. - Work directly with engineers to implement production-ready fixes and regression tests. - Help build secure, reusable patterns for input handling, authorization, secrets, data access, and external integrations. - Perform focused code reviews, penetration tests, and architecture assessments for security-sensitive changes.
PLATFORM AND INFRASTRUCTURE - Build and improve the secure, reliable infrastructure behind model calls and agent workflows. - Harden cloud permissions, service identities, secrets, storage, networking, deployment pipelines, and production access. - Build guardrails into CI/CD and infrastructure-as-code so common security problems are caught before deployment. - Improve model-provider routing, retries, timeouts, fallbacks, quotas, rate limits, and cost controls. - Add observability for unusual model behavior, tool usage, data access, errors, latency, and token consumption. - Build containment mechanisms and kill switches for unsafe or misbehaving agents. - Support production debugging and the investigation of application, infrastructure, and AI-security incidents.
WHAT WE’RE LOOKING FOR - 2–3 years of hands-on experience across AI engineering, backend/platform engineering, application security, infrastructure security, DevSecOps, or a related engineering role. - Experience building, operating, or securing production AI systems using LLM APIs, agents, tool calling, RAG, model gateways, or similar technologies. - Strong programming ability in Python, TypeScript, Go, or another relevant language. - Understanding of common web and API security risks, including authentication, authorization, injection, tenant isolation, secrets, and unsafe data handling. - Practical experience with cloud infrastructure, CI/CD, containers, monitoring, or infrastructure-as-code. - Ability to investigate a suspected vulnerability, reproduce it, assess its real-world impact, and contribute an effective fix. - Ability to reason about trust boundaries between users, models, customer data, application code, tools, and third-party services. - Comfort debugging systems through source code, logs, traces, metrics, and database queries. - Strong written communication and the ability to explain security risks clearly without unnecessary alarm. - A builder’s mindset: you enjoy implementing durable controls, not only identifying problems.
We care more about strong fundamentals, practical work, and learning velocity than matching every item in the description.
GOOD TO HAVE - Hands-on experience with AI red teaming or adversarial model testing. - Familiarity with prompt injection, insecure output handling, tool-use vulnerabilities, agent sandboxing, or context leakage. - Experience securing multi-tenant B2B SaaS products. - Experience with OAuth, webhooks, file processing, MCP, and third-party integrations. - Experience building security test harnesses, fuzzers, automated evaluations, or inter
Metaforms
- Open roles in India
- 6
- Hiring in
- Bengaluru
- Applications through
- Ashby
Counted from the roles we read off Metaforms's own hiring page today.
No open company record matched this employer by name with certainty, so none is shown — a wrong company's facts would be worse than none.