AI Security Engineer
Macee
AI Security Engineer
Samenvatting
Wat krijg je?
Wat ga je doen?
- Translate security controls into cloud configurations
- Engineer continuous compliance evidence pipelines
- Maintain secure Terraform infrastructure modules
- Implement GitOps CI/CD security gates
- Harden AKS and GKE GPU pools
Wat verwachten wij?
- 5 years experience in software development lifecycle
- Cloud platform engineering experience with AI focus
- Hands-on experience with Azure and GCP
- Experience with Kubernetes and GPU node pools
Volledige vacaturetekst
ASML's AI Foundation is scaling Enterprise and Scientific AI workloads across Azure and GCP, ensuring every model is provably secure before production. As an AI Security Engineer, you build the Terraform modules and GitOps pipelines that make compliance continuous. You will work in a high-talent density environment on strategically important platforms, enjoying the technical depth of hardening Kubernetes GPU pools and implementing advanced LLM guardrails. Dive into this mission-critical role and secure the future of AI!
Possible extension: YES
Hours per week: 36
ZZP not possible
Job description
ASML's AI Foundation is scaling Enterprise AI and Scientific AI workloads across Azure and GCP, and every one of these workloads must be provably secure before it reaches production. As AI Security Engineer you translate the ASML AI Security Framework, control by control, into working platform configuration and the machine-verifiable evidence that proves adherence to it. This is not a policy or advisory function: you build the Terraform modules, GitOps pipelines and policy-as-code gates that make compliance continuous rather than a point-in-time audit exercise. You operate across Kubernetes GPU node pools, network segmentation, identity and the hardened API layer that sits between models and their consumers, and you instrument the platform end to end so anomalies and drift surface automatically. You work daily alongside Senior AI Security auditors and a high-density team of AI Engineers, in an environment where implementations are expected to pass governance the first time. It is a role with real technical depth and direct influence on how ASML secures one of its strategically important platforms.
- Translate ASML AI Security Framework control descriptions into working platform configuration across Azure and GCP
- Engineer machine-verifiable evidence pipelines that continuously attest control compliance
- Build and maintain Terraform modules for secure Enterprise AI and Scientific AI infrastructure
- Implement GitOps CI/CD security gates in Azure DevOps and GitHub Actions
- Configure and harden AKS/GKE GPU node pools, including workload and session isolation
- Design VNet/VPC segmentation and private endpoints for AI workloads
- Implement RBAC/ABAC least-privilege models, managed/workload identity and agent authentication
- Set up geo-aware and risk-based access blocking controls
- Build and operate a hardened API integration layer/proxy that removes direct model access
- Configure a centralized MCP gateway with tool-level access controls
- Implement LLM guardrails for prompt/response injection, content filtering, kill-switch and inference rate limiting
- Build observability with OpenTelemetry, Prometheus, Loki, Tempo and Grafana, including anomaly and drift detection
- Enforce data and model classification, training-data/model isolation and model-theft prevention measures
- Collaborate with Senior AI Security auditors to ensure implementations pass ISO 27001, EU AI Act and GDPR governance consistently
Must-haves
- 5+ years of experience in software development lifecycle (SDLC) fundamentals
- Hands-on cloud platform engineering experience with an AI/ML focus
- Hands-on experience with Azure and GCP
- Experience with Kubernetes (AKS/GKE), including GPU node pools
- Expert-level Terraform and infrastructure-as-code experience
- Experience with GitOps and CI/CD pipelines (Azure DevOps or GitHub Actions)
- Experience with IAM, RBAC/ABAC least-privilege design and managed/workload identity
- A security-first mindset and the ability to translate control intent into defensible implementation
- Experience with policy-as-code and continuous compliance attestation
- Strong understanding of network segmentation, VNet/VPC design and private endpoints
- Ability to work effectively alongside senior specialists in a high talent density environment
- Experience with LLM guardrails, prompt/response injection prevention and content filtering
- Experience with observability stacks such as OpenTelemetry, Prometheus, Loki, Tempo and Grafana
- Knowledge of ISO 27001, EU AI Act and GDPR compliance requirements
- Experience with MCP gateway or similar tool-level access control architectures
- Experience with data/model classification and model-theft prevention techniques
- Strong stakeholder management skills
- Clear and confident communication with technical and audit stakeholders
- Sharp analytical thinking
- Structured, Agile/DevOps way of working
- High degree of ownership
- Proactive attitude
- Precise, detail-oriented mindset
- Collaborative team player in a high talent density environment
- Pragmatic problem solver who balances security intent with delivery speed
- Continuous learning mindset across a broad technology stack
- Azure
- GCP
- Kubernetes (AKS, GKE)
- Terraform
- Azure DevOps
- GitHub Actions
- OpenTelemetry
- Prometheus
- Loki
- Tempo
- Grafana
- MCP (Model Context Protocol) gateway
Over de werkgever
Zo werkt solliciteren
- Snel en eenvoudig via je mobiel
- Solliciteer in 1 minuut
- CV niet verplicht
- Volg je sollicitatie via Track & Trace
- Volg je sollicitatie via Track & Trace
Goed om te weten
Makkelijk solliciteren Solliciteren