AI Security Engineer Offensive and Defensive

All-in-one Philippine e-wallet and cryptocurrency exchange combining crypto trading with payments, bills, QR checkout, mobile load, and remittances.

Manila, Philippines
About Coins.ph

Coins.ph is a regulated digital-asset and payments platform operating under the Coins.ph brand. Its services include buying, selling, and holding cryptocurrency; peso wallets; bill payments; mobile load; QR payments; money transfers; and remittances. The current user agreement identifies Betur, Inc. and DCPay Philippines, Inc. as the entities doing business as coins.ph.

View jobs by Coins.ph

Skills

About the Role

You will review and penetration-test AI agents, design defenses against emerging AI threats, and build automated security detection tools. You will audit agent behavior, detect runtime anomalies, assess cloud-native attack surfaces, and implement defense-in-depth solutions.

Requirements

  • Have at least 3 years of security offense and defense experience, including penetration testing or red team practice
  • Have at least 1 year of LLM security offense and defense experience
  • Understand network architecture and cloud-native technology stacks, including Kubernetes, Docker container security, IAM, network isolation, and cloud-native threat models
  • Build and modify AI agents using frameworks such as LangChain
  • Demonstrate practical offensive capabilities against agents, including tool misuse, prompt injection, and context poisoning
  • Know OWASP Top 10 for LLM and MITRE ATT&CK
  • Be proficient in Python, Go, or C++
  • Develop security offense and defense tools or extend open-source security platforms

Responsibilities

  • Review and penetration-test AI agents
  • Design and implement defenses against AI tool misuse, context poisoning, data and prompt poisoning, and prompt injection
  • Develop AI-based automated security detection tools
  • Enable automated alert triage and attack attribution
  • Build agent behavior auditing and anomaly detection systems
  • Identify abnormal agent runtime behavior chains
  • Design and implement AI-driven security operations defenses and countermeasures
  • Assess cloud-native agent runtime attack surfaces
  • Design defense-in-depth solutions for Kubernetes, Docker, and cloud services