
AI Security Engineer (Offensive & Defensive)
Coins.ph
๐ Worldwide
hybrid
1 week ago
- AI
- Penetration Testing
- triage
- Kubernetes
- Docker
- IAM
- LangChain
- OWASP
- Python
- C++
- PyTorch
- TensorFlow
- Large Language Models
- AWS
1 week ago
Coins is the most established crypto brand in The Philippines and has gained the trust of more than 18 million users. Through the easy-to-use mobile app, users can buy and sell a variety of different cryptocurrencies and access a wide range of financial services.
Coins is fully regulated by the Bangko Sentral ng Pilipinas (BSP) and is the first ever crypto-based company in Asia to hold both Virtual Currency and Electronic Money Issuer licenses from a central bank.
Responsibilities:
- Responsible for AI Agent security review and penetration testing, including defense design and implementation against emerging threats such as AI tool misuse, context poisoning, various forms of data/prompt poisoning, and prompt injection.
- Responsible for designing and developing AI-based automated security detection tools, enabling automated alert triage, attack attribution, and improved security operations efficiency.
- Participate in building Agent behavior auditing and anomaly detection systems, identifying abnormal behavior chains during Agent runtime, constructing an AI-driven security operations platform, and exploring, designing, and implementing defense and countermeasure solutions based on real business scenarios.
- Combine security risks of cloud-native infrastructure (K8S, Docker, cloud services) to assess the attack surface of Agent runtime environments and design defense-in-depth solutions.
Requirements:
- At least 3+ years of security offense/defense experience (penetration testing/red team practice), with 1+ years of experience in LLM (large model) security offense/defense; extensive hands-on red team experience preferred.
- Familiar with network architecture and cloud-native technology stacks, including K8S, Docker container security, and cloud security (IAM, network isolation, cloud-native threat models, etc.), with the ability to assess security risks in complex infrastructure.
- Possess practical Agent development capability, able to independently build/modify AI Agents (e.g., based on frameworks such as LangChain), as well as hands-on offensive capability against Agents (practical construction and validation of attack techniques such as tool misuse, prompt injection, context poisoning).
- Familiar with security frameworks such as OWASP Top 10 for LLM and MITRE ATT&CK, familiar with common AI attack techniques, adversarial logic, and defense solutions, with a strong passion for AI security.
- Proficient in at least one programming language such as Python/Go/C++, with the ability to develop security offense/defense tools or perform deep secondary development on open-source security platforms.
- Familiar with mainstream AI frameworks (PyTorch, TensorFlow, LangChain, etc.), with practical experience in local deployment and optimization of large language models.
- Hands-on cloud security (AWS) experience or related certifications.
Nice to Have
Meaningful Collaborations- The successful candidate will work cross-functionally with other relevant teams to carry out implementations that will improve and create an impact on customer experience.
Scalable Growth - Be part of a fast-growing organization with the vision to expand its territories outside APAC which will provide opportunities for career advancement.
A Space For Bright Ideas - Let your bright ideas be converted into meaningful changes! Coins culture welcomes new ideas backed up by data to create an impact.
AI Security Engineer (Offensive & Defensive) ยท Coins.ph