Lead AI Security Engineer
Software Engineering, Data Science
Toronto, ON, Canada · New York, NY, USA · Washington, DC, USA
Posted on Sep 29, 2026
Jozu secures and governs AI for organizations deploying models, agents, and MCP servers from any source. We verify artifacts before they run, enforce policy while they run, and produce a tamper-evident record of both. Our customers are enterprises, regulated industries, and governments, including teams operating in air-gapped environments. We build this with OCI artifacts, cryptographic signing and attestation, security scanning, micro-VM isolation, policy engines, and Kubernetes. Our engineering work centers on artifact packaging and distribution, runtime isolation, policy evaluation and enforcement, and cryptographically chained audit logs. We created KitOps, now a CNCF project, and authored the CNCF ModelPack specification, the only openly governed standard for AI/ML packaging. We are a small team from several countries working on one goal: making AI safe to deploy. We’re looking for an experienced machine learning engineer to help Jozu make AI safe to deploy. You’ll help define how models, agents, and MCP servers are inspected, verified, and constrained: what a malicious or tampered artifact looks like, how to detect it before it loads, and how to keep an agent inside its policy once it is running. You’ll turn that into scanners, models, and enforcement code that let our customers adopt AI faster without giving up control of it. You’ll do all this with a constant eye on security, performance, and operational stability, including in air-gapped environments where nothing can phone home. Candidates should enjoy working in a collaborative, analytical, and fast-paced environment and be comfortable interacting with technical cross-functional teams. Ideal candidates dive deep into data, have strong communication skills, and can confidently prioritize and choose the right tradeoffs. We are a remote-first team who meet for in-person working sessions. We welcome applicants from anywhere between the Pacific and Eastern time zones, but would prefer a candidate in Toronto, New York City, or Washington DC. We value critical thinking, curiosity, problem-solving, and an open and empathetic communication style. Personal and team growth is an integral part of Jozu. We love to learn and challenge ourselves, and always support each other as we grow. We are excited to take on tough challenges and celebrate together when we achieve our goals. In this role, you’ll be able to:- Help refine how we detect unsafe models, agents, and MCP servers, and where ML is the right tool for that versus static analysis or policy.- Build, train, and operate the models behind our scanning and runtime inspection: malicious serialization and code detection, prompt and tool-call inspection, and anomalous agent behavior.- Design, build, test and deploy new libraries, frameworks, or full systems for our core products while keeping to the highest standards of testing and code quality.- Work with experienced engineers and product owners to automate artifact analysis at scale, across models and agents pulled from public and internal sources.- Build the evaluation and labeling pipelines that tell us whether a detector actually works, including on adversarial samples.- Take end-to-end ownership, from defining a detection problem to shipping the model into a customer-hosted, sometimes air-gapped, deployment.- Set the quality bar for our detections: false positive rates, drift, versioning, and how model updates reach customers who cannot pull from the internet.- Do your work with minimal meetings and remember what it’s like to do consistent deep work. What you’ll need to succeed:- Bachelor’s degree in computer science /information systems/engineering/related field.- Strong understanding of Python and GoLang.- Proven track record of developing and deploying machine learning models to production.- Experience with machine learning frameworks (e.g., TensorFlow, PyTorch) and with the model file formats and serialization they use.- Comfort reasoning about adversarial inputs: what an attacker would do to evade the detector you just built.- Excellent communication and collaboration skills, and the ability to work effectively in a small team.- A love of code simplicity and performance. Ideally candidates will also have some of the following:- Security background: malware analysis, static analysis, vulnerability research, or software supply chain security.- Experience with OCI, Git, and GitOps.- Familiarity with OCI registries and artifacts, container image internals, or signing and attestation formats.- Understanding of the ML project lifecycle and how models get packaged, versioned, and shipped.- Experience with Go, Kubernetes, agent frameworks, or MCP.- Experience shipping software into on-premises or air-gapped environments. This role will let you work on problems that do not have settled answers yet, and give you a voice in early decisions about a product in a market that is forming right now. You’ll work across ML, security, and systems engineering rather than in one lane. The ideal candidate is at home with cloud-native technology running across public, private, and air-gapped infrastructure. We work in Go and Python, on Kubernetes, with OCI artifacts, micro-VM and Kata container isolation, cryptographic signing and attestation, and MCP.