Senior AI Security Enginee
About BJAK: Pioneering the Future of Finance
At BJAK, we're on a mission to empower millions across Southeast Asia with smarter ways to manage their money. Since our inception in 2019, we've transformed the financial landscape, launching the region's first mobile-first insurance platform and becoming its undisputed leader. Now, we're aggressively expanding our ecosystem to encompass spending, saving, investing, exchanging, travel, and beyond, all driven by a singular purpose: to help people get more from their money every single day.
We are a vibrant, global team representing over 20 nationalities, united by a passion for innovation and a commitment to building next-generation products that redefine financial accessibility for everyone. We seek driven individuals who are excited by challenging the status quo, who thrive on passion, and who dream of making a tangible impact on millions of lives. If you're ready to build something truly revolutionary, you belong with us.
The Role: Forge the Future of Secure AI
As a Senior AI Security Engineer at BJAK, you will be at the forefront of securing our innovative, AI-enabled products and agent workflows that leverage cutting-edge third-party models. Your expertise will be critical in safeguarding customer data, managing agent permissions, ensuring robust user data isolation, and fortifying against sophisticated prompt injection attacks originating from uploaded documents and other untrusted content. This is a unique opportunity to define and implement security best practices in a rapidly evolving FinTech AI environment.
What You Will Build & Secure
Architect and implement robust controls for customer data shared with third-party AI model vendors, focusing on data minimization, vendor controls, retention policies, comprehensive logging, and approved use cases.
Design and enforce stringent controls to limit AI agent permissions, tools, actions, and system access, leveraging least privilege principles and explicit authorization.
Develop, implement, and rigorously test tenant and user data isolation mechanisms across prompts, conversation history, retrieval-augmented generation (RAG), memory, and all AI-connected services.
Lead threat modeling exercises and conduct comprehensive penetration testing against prompt injection and indirect injection vectors, including uploaded documents, retrieved content, links, and other untrusted inputs.
Collaborate closely with Product and Engineering teams to ensure secure document ingestion, content handling, output validation, and approval workflows for sensitive AI-driven actions.
Provide expert support for SC TRM and BNM RMiT compliance regarding AI technology risks, encompassing comprehensive assessments, third-party oversight, control evidence generation, and remediation planning.
Develop and implement advanced security tests, monitoring solutions, and incident response procedures specifically tailored for AI misuse, data exposure, unauthorized actions by AI, and vendor-related security incidents.
What We Look Fo
Bachelor's degree in Computer Science, Cybersecurity, Artificial Intelligence, or a related technical field, or equivalent practical experience.
Minimum of 3+ years of hands-on experience in application security, product security, security engineering, or specialized AI system security.
Proven experience in implementing, owning, or providing evidence for SC TRM and BNM RMiT controls, technology risk management, or other relevant regulatory compliance.
Deep understanding of third-party Large Language Model (LLM) integrations, model APIs, AI agent tooling, Retrieval-Augmented Generation (RAG) systems, and modern AI application architectures.
Expertise in identifying and mitigating critical AI security risks, including prompt injection, indirect injection, cross-user data leakage, excessive agent permissions, and vendor data disclosure vulnerabilities.
Strong programming or scripting skills (preferably Python and TypeScript/Node.js) coupled with experience in API security and cloud platforms such as AWS or GCP.
Exceptional ability to collaborate cross-functionally with Product, Legal, Compliance, Data, and Engineering teams to implement practical security controls and effectively communicate risks.
Language
English is our global team's primary working language. Strong English communication skills are essential for this role.
Ready to secure the future of AI-driven finance? Apply now and help us build a safer, smarter financial world.