You'll define the security architecture that product and AI teams build on top of, embedding secure defaults into every layer from tenant provisioning to model serving to API response handling. * Architect API security controls input validation frameworks, output encoding, rate limiting, request signing, and abuse prevention as platform-level primitives, not per-team afterthoughts. * Shape the platform's API strategy versioning, deprecation policies, developer-facing auth (API keys, OAuth client credentials), and webhook signature verification. * Design audit logging and tamper-evident trails at the application layer who accessed what data, when, through which API, with what authorization context including AI model decisions and their inputs. * Experience with runtime protection tooling: RASP, WAF tuning, or API security gateways (Salt Security, 42Crunch, or similar).
more