Director, Security Products: Key Management

DigitalOcean

$230K — $288K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 10+ years in cybersecurity; 4-5 years specifically in AI/ML security or adversarial machine learning.
  • Demonstrated experience driving organizational-level AI security strategies.
  • In-depth knowledge of adversarial ML attacks and defenses, including evasion and poisoning techniques.
  • Ability to synthesize academic AI security research into practical engineering guidance.
  • Strong programming skills in Python and Go for security tooling and automation development.
  • Experience communicating technical risks to executive audiences effectively.
  • Proficient in evaluating architecture of AI/ML systems and familiar with security frameworks.

Responsibilities

  • Define AI security controls integration in customer-focused products with engineering leadership.
  • Develop and deploy in-house AI/ML models and tooling in collaboration with data science teams.
  • Lead adversarial testing and AI red teaming initiatives to identify vulnerabilities.
  • Conduct security reviews and provide architectural guidance for AI product development.
  • Perform threat modeling throughout the entire AI lifecycle and monitor deployed models.
  • Drive the AI Security strategy and roadmap for DigitalOcean, prioritizing risk investments.
  • Establish an AI Risk & Governance framework for responsible AI/ML development and monitoring.

Benefits

  • Remote work opportunity.
  • Engagement with a key external AI security community.
  • Direct influence on the AI security strategy and roadmap.
  • Collaboration with leadership teams across security and data science.
  • Opportunity to present at executive and board-level briefings.
Full Job Description
We are looking for a Principal Engineer, AI/ML Security who is passionate about securing AI systems and operationalizing ML-powered security at cloud scale.

In this role, you will report to the VP, Deputy CISO and partner closely with Security Data Science and Security leadership teams. You will lead DigitalOcean's engagement with the external AI security community and serve as our internal expert and escalation point for all AI-related security risk.
What You'll Do:
  • Partner with Product Security and Engineering leadership to define how AI security controls are integrated into DigitalOcean's customer-facing products.
  • Partner with Security Data Science and Security Engineering to build, deploy, and serve in-house AI/ML models, guardrails, tooling, and automations. Participate in ongoing monitoring of deployed models to detect drift, evaluate performance, and plan and implement improvements alongside model stakeholders.
  • Lead adversarial testing and AI red teaming, including jailbreaking, prompt-injection, evasion, and poisoning testing.
  • Lead security reviews of major AI product initiatives from design through launch, providing architectural sign-off and escalation guidance for high-risk decisions.
  • Threat modeling across the AI lifecycle: data ingestion, training/fine-tuning, evaluation, model serving, RAG, agent frameworks, and post-deployment monitoring
  • Own and drive DigitalOcean's AI Security strategy and multi-year roadmap, defining where we invest, what risks we prioritize, and how AI security evolves as the threat landscape and product portfolio change.
  • Architect and lead the AI Risk & Governance framework: establishing policies, standards, and controls for the responsible development, deployment, and monitoring of AI/ML systems across DigitalOcean and Cloudways.
  • Represent AI security at executive and board-level briefings; communicate risk posture, program progress, and strategic decisions to the CISO and senior leadership in clear, business-contextualised terms.
  • Define DigitalOcean's position on emerging AI security topics including agentic AI, model supply chain risk, synthetic data integrity, and AI-enabled social engineering.
What You'll Add to DigitalOcean:
  • 10+ years of experience in cybersecurity, with at least 4-5 years focused on AI/ML security, adversarial machine learning, or security data science in a production cloud or technology environment.
  • Demonstrated track record of defining and driving AI or security programs at an organizational level - not just executing within them. You have owned a strategy, not just implemented one.
  • Deep, practitioner-level knowledge of adversarial ML attack and defence: evasion, poisoning, model extraction, membership inference, and prompt injection at both conceptual and implementation depth.
  • Ability to read, evaluate, and synthesise academic AI security research and translate it into concrete engineering guidance and organizational policy.
  • Experience engaging executive and senior leadership audiences on technical risk: you can translate complex AI threat scenarios into business-level impact and justify investment decisions accordingly.
  • Strong programming skills in Python and Go with a track record of building security tooling and automation, not just reviewing others' code. You can stand up adversarial testing, detection, and guardrail capabilities yourself.
  • Proficiency reviewing and critiquing AI/ML system architecture (data ingestion, feature engineering, training pipelines, model serving, continuous monitoring) made by ML engineers and data scientists.
  • Hands-on experience with AI red-team and defensive tooling and with model supply-chain frameworks.
  • Bachelor's or Master's degree in Computer Science, Information Security, Mathematics, or a related field - or equivalent depth of practical experience.
  • Fluency in OWASP LLM Top 10, MITRE ATLAS, NIST AI RMF, ISO/IEC 42001, and the EU AI Act.
  • Prior experience in a cloud provider, security product company, or large-scale internet platform where AI/ML systems operate at significant customer-facing scale.
  • Familiarity with LLM security in production: securing RAG pipelines, agentic frameworks, and model APIs against prompt injection, jailbreaking, and data exfiltration.
Compensation Range:
  • $230,400 - $288,000

*This is a remote role



#LI-Remote

Application Limit: You may apply to a maximum of 3 positions within any 180-day period. This policy promotes better role-candidate matching and encourages thoughtful applications where your qualifications align most strongly.

Similar Jobs

More Jobs at DigitalOcean

More Information Technology Jobs

Find similar Director, Security Products: Key Management jobs: