Lila Sciences is a startup building an AI platform that trains models on scientific literature and integrates laboratory validation to enable autonomous scientific discovery.
<p><strong>Your Impact at LILA</strong></p> <p>As a Principal Security Engineer focused on AI Security, you will define and drive the technical strategy for securing how AI is used across Lila's enterprise. You will operate as a senior individual contributor, partnering with IT and business teams to ensure safe and compliant adoption of AI tools and platforms.</p> <p>While Lila builds AI-powered systems, this role is primarily focused on securing the use of third-party and internally deployed AI tools across the enterprise — ensuring sensitive data, intellectual property, and scientific workflows are protected as AI becomes deeply embedded in how work gets done.</p> <p><strong>What You'll Be Building</strong></p> <ul> <li><strong>Enterprise AI Security Strategy</strong> — Define and implement security controls and guardrails for the use of AI tools (e.g., LLM APIs, SaaS AI platforms, and internal AI services) across the organization.</li> <li><strong>AI Gateway & Agentic Gateway Security</strong> — Design and implement AI gateway controls to manage and monitor access to external and internal AI systems. Secure agentic workflows by enforcing identity, authorization, tool-use constraints, and policy controls for autonomous or semi-autonomous agents.</li> <li><strong>AI Red Teaming & Adversarial Testing</strong> — Conduct red teaming and adversarial testing focused on enterprise AI usage, including prompt injection, data exfiltration, jailbreaks, and abuse of connected tools and plugins.</li> <li><strong>Data Protection for AI Usage</strong> — Develop and enforce controls to prevent sensitive data leakage through AI systems, including input/output filtering, data classification, tokenization, and secure handling of prompts, embeddings, and outputs.</li> <li><strong>Multi-Layer AI Security (Network, Endpoint, Data)</strong> — Integrate AI security into existing enterprise security layers: network visibility and control over AI service access, API traffic inspection, and zero trust enforcement; endpoint security for developer machines, research environments, browsers, and plugins; data layer controls ensuring proper handling of sensitive data when interacting with AI systems.</li> <li><strong>AI Threat Modeling (Enterprise Context)</strong> — Develop threat models focused on enterprise AI usage, including risks such as data leakage, prompt injection, model misuse, supply chain risks from AI vendors, and unauthorized agent actions.</li> <li><strong>Vendor & Platform Security</strong> — Assess and guide secure adoption of third-party AI vendors and platforms, including evaluating data handling practices, model behavior, and integration risks.</li> <li><strong>Incident Response for AI Usage</strong> — Define and support response approaches for AI-related incidents, such as sensitive data exposure, policy violations, or misuse of AI tools.</li> <li><strong>Cross-Functional Technical Leadership</strong> — Partner with Legal, Compliance, IT, and Engineering to align AI usage with regulatory requirements, data governance policies, and responsible AI practices.</li> <li><strong>Security Enablement</strong> — Contribute to internal guidance and education on safe AI usage, including secure prompting, data handling, and appropriate use of AI tools.</li> <li><strong>Security Tooling & Implementation</strong> — Evaluate and implement tooling for AI security, including AI gateways, DLP integrations, monitoring solutions, and policy enforcement mechanisms.</li> </ul> <p><strong>What You’ll Need to Succeed</strong></p> <ul> <li>8+ years of experience in information security, with strong expertise in enterprise, cloud, or application security.</li> <li>Hands-on experience designing and implementing security controls in enterprise environments.</li> <li>Familiarity with AI/ML systems and how modern AI tools (LLMs, copilots, APIs) are used in practice.</li> <li>Experience with cloud platforms (AWS/GCP), SaaS security, and zero trust architectures.</li> <li>Experience with data protection technologies (e.g., DLP, data classification, access controls).</li> <li>Practical experience with threat modeling, red teaming, or adversarial testing.</li> <li>Strong communication and influence skills across technical and non-technical stakeholders.</li> </ul> <p><strong>Bonus Points For</strong></p> <ul> <li>Experience securing enterprise use of LLMs, copilots, or generative AI platforms.</li> <li>Familiarity with AI gateways, prompt filtering, or model interaction controls.</li> <li>Experience evaluating or securing third-party AI vendors and APIs.</li> <li>Background in regulated environments (biotech, healthcare, defense, or government).</li> <li>Experience with browser security, endpoint controls, or SaaS security platforms.</li> <li>Knowledge of privacy-enhancing technologies or confidential computing.</li> <li>Contributions to AI/ML security research or community.</li> </ul><div class="content-pay-transparency"><div class="pay-input"><div class="description"><p><strong>Compensation</strong></p> <p>We offer competitive base compensation with bonus potential and generous early-stage equity. Your final offer will reflect your background, expertise, and expected impact.</p> <p><strong>U.S. Benefits.</strong> Full-time U.S. employees receive a comprehensive benefits program including medical, dental, and vision coverage; employer-paid life and disability insurance; flexible time off with generous company wide holidays; paid parental leave; an educational assistance program; commuter benefits, including bike share memberships for office based employees; and a company subsidized lunch program.</p> <p><strong>International Benefits.</strong> Full-time employees outside the U.S. receive a comprehensive benefits program tailored to their region. USD salary ranges apply only to U.S.-based positions; international salaries are set to local market.</p></div><div class="title">Expected Base Salary Range</div><div cl