Bjak
AI Security Engineer
About this role
Secure AI-powered financial products by managing third-party model integrations, protecting customer data shared with vendors, and preventing prompt injection attacks. Work cross-functionally to design controls for AI agent permissions, data isolation, and regulatory compliance in a fintech platform serving Southeast Asia.
What you'll do
- Assess and minimize customer data exposure to third-party AI model providers, including vendor controls and data retention policies
- Design AI agent permission controls using least privilege principles to limit tools, actions, and system access
- Implement and test data isolation mechanisms across prompts, conversation history, retrieval systems, and connected services
- Threat model and test prompt injection vulnerabilities through uploaded documents, retrieved content, and untrusted inputs
- Support regulatory compliance efforts for SC TRM and BNM RMiT AI technology risk assessments and control evidence
- Build security monitoring, testing frameworks, and incident response procedures for AI misuse and data exposure
What they're looking for
- Application or product security engineering
- AI system security and LLM integrations
- Prompt injection and indirect injection attack testing
- Python and TypeScript/Node.js programming
- AWS or GCP cloud platforms
- Regulatory compliance (SC TRM, BNM RMiT)
- API security and third-party vendor risk
- Data isolation and access control design
Opens the application — the Jobs AI extension fills it for you. Set up autofill
Opens the official application on the employer’s site. No login required.
Bjak
Bjak is a Southeast Asian fintech super app offering insurance, payments, savings, wallets, and investment products through a unified platform. The company is hiring full stack engineers, backend engineers, iOS developers, and Android engineers to build scalable features and reliable systems across mobile and web products.
- Website
- bjak.com
Likely interview questions
- Walk us through a time you designed security controls for a third-party integration—what was your risk assessment process?
- How would you approach threat modeling prompt injection attacks in a document-upload feature?