{"schemaVersion":"jobsearcher.job.v1","id":"5b20ca226c16a7db94dcdff1","url":"https://jobsearcher.com/jobs/5b20ca226c16a7db94dcdff1","canonicalUrl":"https://jobsearcher.com/jobs/5b20ca226c16a7db94dcdff1","title":"AI Security & DevOps Engineer","description":"About Casper Studios\n\nWe’re an AI services firm that helps companies figure out where and how to use AI. We’ve built Casper Studios to roughly 45 people, worked with 30+ clients, and done deals with some of the largest companies, PE funds, and model providers.\n\nIt all comes down to how we work with clients. Before we build anything, we listen, understand the business, and help them figure out the highest-leverage way to get started on their AI journey.\n\nAbout the Role\n\nWe're hiring an AI Security & DevOps Engineer to own how Casper takes AI systems from prototype to production securely. This role will set and enforce the technical standard: threat models, secure defaults, authentication and secrets patterns, CI/CD gates, and the agent-specific controls that AI systems need and traditional security programs don't cover. In parallel, this role will own the client security conversation: engaging their security team early, translating their requirements into what we build, and producing the evidence that gets an enterprise deployment approved.\n\nThe AI Security & DevOps Engineer will work across every engagement rather than sitting on one. Our clients are largely regulated enterprises on Microsoft stacks, so the work spans identity, cloud, data protection, and the newer surface of agents, tools, and connectors. This position will be the person who knows the difference between a proof of concept and a production system in a bank, scales the rigor accordingly, and decides what ships.\n\nWhat You’ll Do\n\nOwn Casper's dev-to-production security standard and make it something engineers actually use\n\nDefine and run the security gate in our delivery process: threat models, design reviews, and the call on what ships\n\nHarden what we build - identity and authentication, secrets management, data protection, egress controls, and the agent surface: prompt injection, tool and connector permissioning, untrusted input in agent loops, MCP auth\n\nOwn the platform work security depends on: CI/CD, automated scanning and review across our repos, infrastructure-as-code, environment and access management, logging and telemetry\n\nAudit our own repos and internal systems, and fix what you find\n\nLead the client security conversation - engage their security team early, extract requirements, map approved and unapproved vendors, and produce the threat models and evidence packs that clear review the first time\n\nSet our point of view on preferred vendors for auth, secrets, telemetry, and scanning so engagements stop relitigating the same decisions\n\nFeed security into scoping - realistic timelines and a production roadmap that accounts for how long validation takes\n\nRaise the security bar across engineering through review, pairing, and written standards\n\nWhat You’ll Bring\n\nDeep hands-on application and product security experience - you've threat modeled, found real vulnerabilities, and written the fixes yourself\n\nReal DevOps and platform depth: CI/CD, infrastructure-as-code, cloud (Azure especially, plus AWS/GCP), secrets management, and observability. You've built the pipeline, not just reviewed it\n\nIdentity and authentication depth - OAuth/OIDC, SSO/SCIM, RBAC, conditional access - with working knowledge of Microsoft Entra\n\nDemonstrated LLM and agent security expertise: prompt injection, excessive agency, tool and connector permissioning, insecure output handling, retrieval abuse, and AI supply chain risk\n\nSecure SDLC in practice: SAST/DAST/SCA, dependency and supply chain controls, and automated review engineers don't route around\n\nThe judgment to right-size controls to the stage and the stakes\n\nClient-facing credibility - you can hold a room with an enterprise security team and translate risk into terms an executive can decide on\n\nAI-native mindset - you use modern AI tooling daily with customized workflows. You can't threat model an agent system you've never built with\n\nHigh agency and strong writing. The standards, evidence packs, and memos are yours, and they need to be good enough that busy people act on them\n\nNice to Haves\n\nRegulated-industry exposure - financial services, healthcare, or another environment where security review is genuinely adversarial\n\nConsulting, agency, or forward-deployed background where you earned trust with a client's security org rather than inherited it\n\nFamiliarity with OWASP Top 10 for LLM Applications, MITRE ATLAS, NIST AI RMF, or ISO 42001\n\nSOC 2 or ISO 27001 experience - useful context, not the job\n\nAI red teaming, adversarial testing, or abuse-case analysis\n\nYou Might Be A Fit If\n\nYou've been a first security hire and built the function from nothing\n\nYou're an AppSec or platform engineer who went deep on LLM and agent security and now gets pulled into every AI review\n\nYou've been the security lead on client-facing delivery and know how to get a skeptical enterprise security team to yes\n\nYou've owned production readiness for systems that had to clear a real audit\n\nYou want standard-setting authority and are comfortable being the only person in the company who does what you do\n\nWhy This Role Is Hard To Fill\n\nMost people land on one side of a line. GRC and compliance people can run a program but can't read the code or fix what's broken in it. Strong AppSec engineers often haven't been client-facing and won't hold up in an enterprise security review. Traditional DevOps engineers know the pipeline but not the AI-specific attack surface. And people from large in-house security teams tend to bring processes that a services business moving at our pace can't absorb.\n\nThis person writes the hardening, owns the platform, and is persuasive in front of a client CISO.\n\nThe role is broad, so where you're coming from can be too. What matters most: hands-on depth, sound judgment about risk, the credibility to hold the line, strong writing, and comfort building the system while the work is already happening.\n\nLogistics\n\nFully remote, US/Canada based, with occasional client travel. We have team members across North America and internationally, mostly overlapping North American time zones. Work when and where you want, as long as the work gets done\n\nCompensation calibrated to your location and seniority - we'll talk comp and align on specifics early\n\nBenefits\n\nMedical, Dental, and Vision Coverage: Comprehensive health benefits to keep you and your family healthy.\n\nFlexible PTO: Take the time you need to relax and rejuvenate.\n\nHealth FSA/HSA: Manage out-of-pocket health expenses effectively.\n\nLife Insurance: Providing peace of mind for you and your loved ones.\n\nCompensation Range: $150K - $180K","company":"Casper Studios","rawCompany":"casper studios","city":"Denver","state":"CO","isRemote":false,"isActive":false,"createdAt":"2026-09-29T11:20:09.051Z","occupations":[{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"},{"code":"15-1299.08","title":"Computer Systems Engineers/Architects","slug":"computer-systems-engineers-architects"},{"code":"15-1252.00","title":"Software Developers","slug":"software-developers"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541511","title":"Custom Computer Programming Services","slug":"custom-computer-programming-services"},{"code":"513210","title":"Software Publishers","slug":"software-publishers"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"AI Security & DevOps Engineer","description":"About Casper Studios\n\nWe’re an AI services firm that helps companies figure out where and how to use AI. We’ve built Casper Studios to roughly 45 people, worked with 30+ clients, and done deals with some of the largest companies, PE funds, and model providers.\n\nIt all comes down to how we work with clients. Before we build anything, we listen, understand the business, and help them figure out the highest-leverage way to get started on their AI journey.\n\nAbout the Role\n\nWe're hiring an AI Security & DevOps Engineer to own how Casper takes AI systems from prototype to production securely. This role will set and enforce the technical standard: threat models, secure defaults, authentication and secrets patterns, CI/CD gates, and the agent-specific controls that AI systems need and traditional security programs don't cover. In parallel, this role will own the client security conversation: engaging their security team early, translating their requirements into what we build, and producing the evidence that gets an enterprise deployment approved.\n\nThe AI Security & DevOps Engineer will work across every engagement rather than sitting on one. Our clients are largely regulated enterprises on Microsoft stacks, so the work spans identity, cloud, data protection, and the newer surface of agents, tools, and connectors. This position will be the person who knows the difference between a proof of concept and a production system in a bank, scales the rigor accordingly, and decides what ships.\n\nWhat You’ll Do\n\nOwn Casper's dev-to-production security standard and make it something engineers actually use\n\nDefine and run the security gate in our delivery process: threat models, design reviews, and the call on what ships\n\nHarden what we build - identity and authentication, secrets management, data protection, egress controls, and the agent surface: prompt injection, tool and connector permissioning, untrusted input in agent loops, MCP auth\n\nOwn the platform work security depends on: CI/CD, automated scanning and review across our repos, infrastructure-as-code, environment and access management, logging and telemetry\n\nAudit our own repos and internal systems, and fix what you find\n\nLead the client security conversation - engage their security team early, extract requirements, map approved and unapproved vendors, and produce the threat models and evidence packs that clear review the first time\n\nSet our point of view on preferred vendors for auth, secrets, telemetry, and scanning so engagements stop relitigating the same decisions\n\nFeed security into scoping - realistic timelines and a production roadmap that accounts for how long validation takes\n\nRaise the security bar across engineering through review, pairing, and written standards\n\nWhat You’ll Bring\n\nDeep hands-on application and product security experience - you've threat modeled, found real vulnerabilities, and written the fixes yourself\n\nReal DevOps and platform depth: CI/CD, infrastructure-as-code, cloud (Azure especially, plus AWS/GCP), secrets management, and observability. You've built the pipeline, not just reviewed it\n\nIdentity and authentication depth - OAuth/OIDC, SSO/SCIM, RBAC, conditional access - with working knowledge of Microsoft Entra\n\nDemonstrated LLM and agent security expertise: prompt injection, excessive agency, tool and connector permissioning, insecure output handling, retrieval abuse, and AI supply chain risk\n\nSecure SDLC in practice: SAST/DAST/SCA, dependency and supply chain controls, and automated review engineers don't route around\n\nThe judgment to right-size controls to the stage and the stakes\n\nClient-facing credibility - you can hold a room with an enterprise security team and translate risk into terms an executive can decide on\n\nAI-native mindset - you use modern AI tooling daily with customized workflows. You can't threat model an agent system you've never built with\n\nHigh agency and strong writing. The standards, evidence packs, and memos are yours, and they need to be good enough that busy people act on them\n\nNice to Haves\n\nRegulated-industry exposure - financial services, healthcare, or another environment where security review is genuinely adversarial\n\nConsulting, agency, or forward-deployed background where you earned trust with a client's security org rather than inherited it\n\nFamiliarity with OWASP Top 10 for LLM Applications, MITRE ATLAS, NIST AI RMF, or ISO 42001\n\nSOC 2 or ISO 27001 experience - useful context, not the job\n\nAI red teaming, adversarial testing, or abuse-case analysis\n\nYou Might Be A Fit If\n\nYou've been a first security hire and built the function from nothing\n\nYou're an AppSec or platform engineer who went deep on LLM and agent security and now gets pulled into every AI review\n\nYou've been the security lead on client-facing delivery and know how to get a skeptical enterprise security team to yes\n\nYou've owned production readiness for systems that had to clear a real audit\n\nYou want standard-setting authority and are comfortable being the only person in the company who does what you do\n\nWhy This Role Is Hard To Fill\n\nMost people land on one side of a line. GRC and compliance people can run a program but can't read the code or fix what's broken in it. Strong AppSec engineers often haven't been client-facing and won't hold up in an enterprise security review. Traditional DevOps engineers know the pipeline but not the AI-specific attack surface. And people from large in-house security teams tend to bring processes that a services business moving at our pace can't absorb.\n\nThis person writes the hardening, owns the platform, and is persuasive in front of a client CISO.\n\nThe role is broad, so where you're coming from can be too. What matters most: hands-on depth, sound judgment about risk, the credibility to hold the line, strong writing, and comfort building the system while the work is already happening.\n\nLogistics\n\nFully remote, US/Canada based, with occasional client travel. We have team members across North America and internationally, mostly overlapping North American time zones. Work when and where you want, as long as the work gets done\n\nCompensation calibrated to your location and seniority - we'll talk comp and align on specifics early\n\nBenefits\n\nMedical, Dental, and Vision Coverage: Comprehensive health benefits to keep you and your family healthy.\n\nFlexible PTO: Take the time you need to relax and rejuvenate.\n\nHealth FSA/HSA: Manage out-of-pocket health expenses effectively.\n\nLife Insurance: Providing peace of mind for you and your loved ones.\n\nCompensation Range: $150K - $180K","datePosted":"2026-09-29T11:20:09.051Z","dateModified":"2026-09-29T11:20:09.051Z","hiringOrganization":{"@type":"Organization","name":"Casper Studios","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Denver","addressRegion":"CO","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"5b20ca226c16a7db94dcdff1"},"url":"https://jobsearcher.com/jobs/5b20ca226c16a7db94dcdff1"}}