Senior Security Engineer, Corporate AI Security (Hybrid)

Homebase
Full timePosted 21 January 2026

Tech Stack

Job Description

Hi, Future Homie!At Homebase, you’ll join a team that’s bold, fast-moving, and obsessed with helping small businesses thrive. We build with empathy, act with urgency, and take big swings that drive real-world impact. Here, every Homie shows up to raise the bar, support one another, and celebrate wins as a team.We’re not just building an app—we’re building unstoppable teams. So what do you say, are you in? 📍Your Impact Starts HereWe're looking for a Senior Corporate AI Security Engineer who's passionate about enabling secure AI innovation at scale. You'll pioneer AI security at Homebase, building the frameworks and controls that allow teams to leverage cutting-edge AI technology from generative AI tools to MCP deployments while protecting sensitive data and maintaining compliance. This is a ground-floor opportunity to define and own AI security architecture, working at the intersection of emerging AI technology and corporate security to enable teams to innovate confidently internally.Note: This role is focused on internal AI tooling and operations security, not product-facing AI features.These are the key ways you'll contribute and create impact in this role:Design and implement security standards for internal AI tools, APIs, model integrations, and AI lifecycle management that enable safe, scalable AI adoption across Homebase.Establish governance frameworks for internal AI agent deployment, training data handling, and inference operations that balance security rigor with business enablement.Monitor and secure MCP (Model Context Protocol) server deployments with continuous verification and audit trails, establishing a zero-trust architecture for internal AI interactions.Architect identity and access management for AI agents, automation tools, and machine-to-machine services, implementing least privilege principles for non-human identities.Implement DLP and policy enforcement for internal and third-party AI tools (ChatGPT, Claude, Gemini, etc.) to safeguard sensitive data during prompt exchanges and model training.Build privacy-preserving data handling frameworks to prevent exfiltration and intellectual property exposure through AI pipelines.Partner with each internal security domain (AppSec, Detection, GRC, and Infrastructure Security) to identify repetitive patterns and manual tasks, then increase team velocity by collaborating to automate security processes using AI and modern tooling.Drive alignment with emerging AI governance regulations, ensuring SOC 2 readiness for AI-enabled systems.Evaluate new AI tools through comprehensive risk assessment and procurement review, streamlining secure adoption processes.Partner with AI enablement, data science, IT, and all of the internal security team members to enable secure AI enablement within Homebase.Automate security processes and provide guidance on AI risks to technical and business stakeholders, helping every team adopt AI safely and confidently.🚀 The Foundation for Success - These are the experiences and strengths that will set you up for success in this role:5+ years of experience in security engineering, with 2+ years focused on AI/ML security, MCP, and automation in the security contextDeep understanding of AI/ML architectures, including LLMs, model deployment pipelines, and API integrationsHands-on experience with identity and access management (IAM), particularly for machine-to-machine authentication and non-human identitiesStrong knowledge of data protection principles, including DLP, encryption, and privacy-preserving technologiesExperience implementing zero-trust architecture and least privilege access controlsFamiliarity with AI security frameworks such as NIST AI RMF, OWASP ML Top 10, or MITRE ATLASProficiency in security automation using Python, Ruby, or similar languagesStrategic thinker who can balance security rigor with business enablement, with strong communication skills to explain complex AI security concepts to technical and non-technical audiencesSelf-sta ... (truncated, view full listing at source)