Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
JobTailor Logo

See all jobs on JobTailor

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Casper Studios

AI Security, DevOps Engineer

Casper Studios

AI Security & DevOps Engineer securing AI systems from prototype to production for Casper Studios, an AI services firm. Owning security standards, platform controls, and enterprise client approvals.

Posted 9/10/2026full-timeRemote • 🇺🇸 United StatesMid-LevelSenior💰 $150,000 - $180,000 per yearWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates deep hands-on application and product security expertise, including threat modeling, vulnerability assessment, and secure SDLC practices. Proficient in DevOps methodologies, cloud security, and identity management, with a strong ability to engage with enterprise security teams and translate complex risks for stakeholders.

Highest-signal resume keywords
Application And Product SecurityDevOps And Platform ExperienceIdentity And Authentication ExpertiseSecure SDLC ExperienceClient-Facing Credibility

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Threat ModelingVulnerability AssessmentCI/CDInfrastructure-As-CodeSecrets ManagementSAST/DAST/SCAOAuth/OIDCRBACAI Supply Chain RiskAdversarial Testing
Soft Skills
Strong WritingHigh Agency
Tools & Technologies
Microsoft EntraAzureAWSGCPModern AI Tooling
Certifications & Qualifications
SOC 2ISO 27001NIST AI RMFISO 42001
Industry Keywords
Regulated IndustriesOWASP Top 10MITRE ATLASClient Security EngagementsEngineering Security Standards

Tech Stack

Tools & technologies
AWSAzureCloudGoogle Cloud PlatformSDLC

About the role

Key responsibilities & impact
  • Own Casper's dev-to-production security standard
  • Define and run security gates including threat models, design reviews, and release decisions
  • Harden identity and authentication, secrets management, data protection, egress controls, and agent security
  • Own security-dependent platform work including CI/CD, automated repository scanning and review, infrastructure-as-code, environment and access management, logging, and telemetry
  • Audit internal repositories and systems and remediate findings
  • Lead client security engagements, gather requirements, map approved and unapproved vendors, and produce threat models and evidence packs
  • Establish preferred vendors for authentication, secrets, telemetry, and scanning
  • Incorporate security validation timelines into project scoping and production roadmaps
  • Raise engineering security standards through reviews, pairing, and written guidance
  • Work across client engagements, primarily with regulated enterprises using Microsoft stacks

Requirements

What you’ll need
  • Deep hands-on application and product security experience, including threat modeling, finding vulnerabilities, and writing fixes
  • DevOps and platform experience with CI/CD, infrastructure-as-code, cloud (especially Azure, plus AWS/GCP), secrets management, and observability
  • Identity and authentication expertise: OAuth/OIDC, SSO/SCIM, RBAC, conditional access, and Microsoft Entra
  • LLM and agent security expertise: prompt injection, excessive agency, tool and connector permissioning, insecure output handling, retrieval abuse, and AI supply chain risk
  • Secure SDLC experience with SAST/DAST/SCA, dependency and supply chain controls, and automated review
  • Judgment to right-size controls to the stage and stakes
  • Client-facing credibility with enterprise security teams and ability to translate risk for executives
  • Daily use of modern AI tooling with customized workflows
  • Strong writing and high agency
  • Experience in regulated industries, consulting/agency/forward-deployed environments, OWASP Top 10 for LLM Applications, MITRE ATLAS, NIST AI RMF, ISO 42001, SOC 2 or ISO 27001, AI red teaming, adversarial testing, or abuse-case analysis are nice to have
  • Must be based in the US or Canada
  • Must provide a GitHub profile with private contributions enabled

Benefits

Comp & perks
  • Medical, Dental, and Vision Coverage
  • Flexible PTO
  • Health FSA/HSA
  • Life Insurance
  • Fully remote work
  • Occasional client travel