Cloud Engineer - Security
ARCHIVED
We can't find an active application page for this role right now. It may reopen or be listed elsewhere. Use Next Steps to search for an active apply link and similar live jobs.
**************************** CANNOT SPONSOR VISA ************************************************** US Citizen, Green Card applicant only ********************************************** Law firm experience is desirable *******************Company DescriptionBrxio Software is a software development company dedicated to creating powerful and simple solutions. This position is for our client - a leading financial and professional services company, with footprint in multiple US cities.Role DescriptionWe are seeking a highly skilled Senior Multi-Cloud Security Engineer to anchor the security architecture of our multi-cloud infrastructure, with a dedicated focus on supporting and safeguarding our newly formed AI Department.Operating within the legal sector demands an uncompromising approach to data integrity. This role sits at the critical intersection of cutting-edge AI engineering (including LLMs, vector databases, and agentic workflows) and strict legal compliance. The ideal candidate will ensure our cloud footprints and AI initiatives are innovative, highly secure, and fully compliant with the stringent privacy mandates governing attorney-client privilege.Key Responsibilities1. AI & Machine Learning Security GovernanceSecure the AI Pipeline: Design and implement robust security guardrails for data ingestion, model training, and inference phases across multi-cloud environments.Mitigate AI-Specific Threats: Proactively defend against emerging vectors such as prompt injection, training data poisoning, model inversion, and supply-chain vulnerabilities in open-source models, utilizing frameworks like the OWASP Top 10 for LLMs.Data Privacy in AI: Ensure sensitive client data, internal legal work product, and proprietary algorithms are strictly segregated and anonymized before interfacing with third-party or self-hosted foundational models.2. Multi-Cloud Security Engineering & ArchitectureInfrastructure as Code (IaC) Security: Embed security into CI/CD pipelines (Terraform, CloudFormation) to enforce continuous compliance across AWS, Azure, and GCP.Identity & Access Management (IAM): Architect and maintain zero-trust IAM policies, ensuring strict least-privilege access for both human operators and autonomous AI agents.Data Protection & Encryption: Oversee advanced encryption mechanism standards for data at rest, in transit, and in use (homomorphic encryption/confidential computing where applicable) across multi-cloud databases and vector stores.3. Legal Regulatory Compliance & Risk ManagementFramework Alignment: Ensure all cloud and AI infrastructure continuously aligns with SOC 2 Type II, ISO 27001, and HIPAA standards.Audit Readiness: Partner with internal legal counsel and external auditors to conduct comprehensive risk assessments, vulnerability scans, and penetration testing on AI-driven legal operations tools.Vendor Assessments: Evaluate the security posture of third-party cloud applications and legal technology vendors integrated into the ecosystem.Required Qualifications & ExperienceExperience: Minimum of 5–7 years in cloud security engineering, with at least 1–2 years of hands-on experience securing AI/ML infrastructure or data pipelines.Cloud Expertise: Deep knowledge of native security tools across multiple providers (e.g., AWS GuardDuty/IAM, Azure Security Center, GCP Security Command Center).AI/ML Technical Literacy: Familiarity with the security nuances of vector databases (e.g., Pinecone, Milvus), model orchestration tools (e.g., LangChain, LlamaIndex), and API security.The Legal Edge: Prior experience working within a major law firm, corporate legal department, or specialized legal technology provider is highly preferred. Understanding the weight of attorney-client privilege in a digital context is crucial.Certifications (Desirable): CCSP, CISSP, AWS Certified Security – Specialty, or Microsoft Certified: Azure Security Engineer Associate.