Enterprise AI Governance & Trust Layer Engineer
Skills
About this role
Accountabilities • Design and deploy enterprise AI trust layers and governance middleware that establish secure data boundaries between internal systems, enterprise applications, and foundational LLMs.
• Implement real-time PII detection and masking using regular expressions, Named Entity Recognition (NER), tokenization, and related data-classification technologies. • Develop policy-as-code guardrails for data privacy, compliance, and sovereignty requirements, including frameworks aligned with regulations such as GDPR, CCPA, and HIPAA. • Build automated and immutable AI transaction audit trails covering model inputs and outputs, token usage, access activity, and other information required for monitoring and forensic analysis. • Implement toxicity, bias, and content-safety controls using moderation models and classification gates to prevent harmful or non-compliant outputs. • Develop defenses against prompt injection, jailbreaks, malicious payloads, and attempts to override system instructions through secure input parsing and validation mechanisms. • Configure secure API proxy architectures, OAuth 2.0 authentication and validation flows, RBAC, and centralized access controls across integrated AI systems. • Collaborate with security, data engineering, and other technical teams to integrate governance controls into enterprise AI workflows and continuously strengthen the overall security posture.
Requirements
• 5–9 years of overall engineering experience, including at least 3 years specifically designing, building, and maintaining AI safety, privacy, governance, or security pipelines. • Strong proficiency in Python, regular expressions, automated data classification, API architecture, and cloud security frameworks. • Demonstrated understanding of AI security risks, including prompt injection, jailbreaks, data leakage, data drift, token transmission constraints, and zero-data-retention API models. • Experience engineering privacy layers, governance controls, or security trust layers between enterprise systems and LLM-based applications. • Strong understanding of authentication, authorization, secure API design, data protection, and enterprise access-control principles. • Ability to translate privacy and security requirements into practical technical controls and automated guardrails. • Strong analytical and problem-solving skills, with the ability to investigate complex AI security and data-flow issues. • Excellent collaboration and communication skills when working with security, data engineering, and other technical stakeholders. • A CISSP, Certified DevSecOps Professional (CDP), or relevant cloud security specialty certification is mandatory. • Experience with Salesforce Einstein Trust Layer or comparable enterprise AI safety platforms is an advantage. • Familiarity with vector embeddings and custom text-classification models for identifying nuanced enterprise intellectual-property or data leaks is desirable.