Senior AI Platform Engineer - Security
Location: Flexible - remote, hybrid, or based at an Esko location.
Worldwide locations considered.
Function: Software Engineering
Reports to: Team Leader, Esko AI
Esko's products handle sensitive customer content and support business-critical workflows. AI-powered and agentic systems introduce additional security challenges because they combine access to sensitive data, specialized tools, and potentially consequential actions within those workflows.
We are building shared security foundations for Esko's AI Platform so product teams can develop AI capabilities without implementing critical controls independently. As part of the platform team, you will help shape and build these foundations, taking end-to-end ownership of substantial security areas.
You will collaborate closely with Esko's cloud platform teams, security engineers, compliance specialists, and product engineering teams to develop controls that are secure, practical, and reusable across products. This is a hands-on engineering role, not a compliance or review position.
This is a hands-on engineering role. It is not a compliance or review position.
Design and build identity, authorization, delegated-access, and policy-enforcement controls for AI systems, including tenant-, user-, document-, and tool-level permissions.
Secure retrieval, tool use, and execution against prompt injection, unauthorized actions, data leakage, and other AI-specific threats.
Design controls proportionate to the risk of an action, including approval gates, isolation, execution limits, and recovery mechanisms.
Work with cloud platform teams, security engineers, compliance specialists, and product engineering teams to integrate controls that satisfy Esko's security obligations while remaining practical to adopt and operate.
Strong software engineering experience designing, building, and operating secure production systems in Python, TypeScript, or a similar language.
At least 5 years’ experience in a software engineering role with experience securing cloud, distributed, or platform services, including authentication, authorization, policy enforcement, and multi-tenant isolation.
Experience designing or building systems using LLMs, retrieval-augmented generation, or agents, with an understanding of their distinctive security failure modes.
Sound judgement in balancing security, usability, and operational complexity, including recognizing when stronger isolation or human approval is required.
Ability to communicate security decisions and tradeoffs clearly across engineering, security, compliance, and product stakeholders.
At Veralto, we value diversity and the existence of similarities and differences, both visible and not, found in our workforce, workplace and throughout the markets we serve. Our associates, customers and shareholders contribute unique and different perspectives as a result of these diverse attributes.
Unsolicited Assistance
We do not accept unsolicited assistance from any headhunters or recruitment firms for any of our job openings. All resumes or profiles submitted by search firms to any employee at any of the Veralto companies, in any form without a valid, signed search agreement in place for the specific position, approved by Talent Acquisition, will be deemed the sole property of Veralto and its companies. No fee will be paid in the event the candidate is hired by Veralto and its companies because of the unsolicited referral.