Senior Enterprise AI Security Engineer

Reposted Yesterday
Be an Early Applicant
Redwood City, CA, USA
Hybrid
190K-238K Annually
Senior level
Cloud • Information Technology • Software
The Role
Design, implement, and scale enterprise security architecture across identity, endpoints, network, SaaS, and AI systems. Lead zero-trust transformation, automate security workflows, build AI-augmented detection and response tooling, perform risk assessments and threat modeling, and mentor junior engineers while partnering cross-functionally to improve telemetry, monitoring, and incident response.
Summary Generated by Built In

WHAT IS BOX? 

Box (NYSE:BOX) is the leader in Intelligent Content Management. Our platform enables organizations to fuel collaboration, manage the entire content lifecycle, secure critical content, and transform business workflows with enterprise AI. We help companies thrive in the new AI-first era of business. Founded in 2005, Box simplifies work for leading global organizations, including JLL, Morgan Stanley, and Nationwide. Box is headquartered in Redwood City, CA, with offices across the United States, Europe, and Asia.

By joining Box, you will have the unique opportunity to continue driving our platform forward. Content powers how we work. It’s the billions of files and information flowing across teams, departments, and key business processes every single day: contracts, invoices, employee records, financials, product specs, marketing assets, and more. Our mission is to bring intelligence to the world of content management and empower our customers to completely transform workflows across their organizations. With the combination of AI and enterprise content, the opportunity has never been greater to transform how the world works together and at Box you will be on the front lines of this massive shift.


WHY BOX NEEDS YOU 


Box has a world class security organization responsible for protecting our customer and employee data around the globe. We are looking for a Senior Enterprise AI Security Engineer to join our Enterprise Security team and own how Box adopts AI internally — safely, quickly, and at scale.

This role pairs enterprise security architecture with hands-on engineering. You will assess the AI tools and agent workflows Boxers want to use, then convert each assessment into a control that holds for everyone who adopts something similar later. You do not need to have trained a model, but you do need working intuition for the failure modes: an agent handed more authority than its task requires, untrusted text arriving as instructions, or company data leaving quietly inside an API call.

You will partner closely with IT, Infrastructure, Incident Response, Legal, Privacy, and the business functions piloting AI, shaping the technical direction of Box's secure AI adoption program.


WHAT YOU'LL DO 


Core Mission

Design, build, deploy, and maintain comprehensive security systems that allow Box's workforce use AI tools and agents productively without losing visibility, identity boundaries, or control of company data.


  • Architect and operate the control plane for workforce AI: AI gateways, prompt and response logging, and egress controls across approved assistants and copilots/agents

  • Extend identity and access management to agentic and non-human identities — scoping, credential lifecycle, delegation, OAuth grant review, and revocation for agents and connectors reaching into corporate SaaS

  • Gate what internal agents can reach: an approval path for MCP servers and connectors, scoped permissions per tool, and isolated execution for anything that runs code

  • Harden the AI-era endpoint and browser layer: enterprise browser policy, extension governance, AI-assisted developer tooling, and local agent runtimes

  • Build the shared enforcement layer — policy engines, brokers, approval registries, internal libraries — that catches risky behavior in flight: injected instructions, attempts to talk around a restriction, tools used outside their intended purpose, sensitive data heading somewhere it should not, and agents behaving nothing like they did last week

  • Lead security architecture reviews and threat modeling for AI vendors, AI features enabled inside existing SaaS platforms, and internal agent deployments, tracing where untrusted content, company data, and privileged credentials meet in each one

  • Own the standards, reference architectures, and paved paths that define what approved AI usage concretely means at Box, and build reusable patterns

  • Partner with IT, Infrastructure, Incident Response, Engineering, Legal, and Privacy to mature AI governance, including AI-specific response playbooks

  • Automate through scripting, infrastructure-as-code, and orchestration instead of manual review queues, and bring AI-assisted investigation tooling to the security team itself

  • Help raise the technical bar across the team through design and code review, mentoring and guidance


Future Focus

This role is for a security engineer who can meet today's adoption requests while building for fleets of agents acting on behalf of employees, delegated authority across systems of record, and corporate data flowing through models. Your work will directly shape how Box secures its people, protects customer data, and holds its position as a trusted leader in intelligent content management.


WHO YOU ARE


Box is an AI-first company. This means you approach your work with a growth mindset and find ways to leverage AI to help make faster, smarter decisions that will 10X your impact at Box, while providing safe adoption patterns for the company.


You are a security professional with:

  • Bachelor's or Master's degree in computer science, information security, or a related field, or equivalent practical experience

  • 6+ years in enterprise or corporate security engineering, security platform engineering, application or product security, or a combination — with meaningful recent time spent on AI or agentic systems

  • Hands-on experience securing real AI deployments — enterprise assistants, internal agents and the tool ecosystems around them, grounded search or RAG over company data, or AI coding tools inside a developer environment

  • A working mental model of how AI systems get abused and paired with the ability to analyze AI workflows to determine guardrails.

  • Strong identity and access management fundamentals

  • Experience with security automation in Python, Go, or a similar language, and a track record of building tooling, libraries, or platform controls

  • Fluency in the emerging problems of this space: shadow AI, agentic and non-human identity, SaaS-to-SaaS integration risk, browser security, and data exfiltration paths

  • Exceptional communication skills, with the ability to explain AI risk and its business impact to practitioners

  • Proven ability to work independently with autonomy, manage ambiguity, and recommend secure but risk-profiled decisions

Nice to have
  • A track record of shipping internal security platforms

  • Exposure to isolation and permissioning for autonomous workloads, or to AI red teaming and evaluation work


BENEFITS

Visit this webpage to check out all of our exciting healthcare benefits: https://join.collectivehealth.com/box

For all other benefits, please check out: Box Benefits + Perks

Box lives its values, with community and in-person collaboration being a core part of our culture. Boxers are expected to work from their assigned office a minimum of 3 days per week. Your Recruiter will share more about how we work and company culture during the hiring process.

At Box, we believe unique and diverse experiences benefit our culture, our products, our customers, our company, and our world. We aim to recruit a passionate, high-performing workforce that reflects the world we live in. If you are head-over-heels about this role but unsure if you meet all the requirements, we encourage you to apply!

Box lives its values, with community and in-person collaboration being a core part of our culture. Boxers are expected to work from their assigned office a minimum of 3 days per week.Your Recruiter will share more about how we work and company culture during the hiring process.

At Box, we believe unique and diverse experiences benefit our culture, our products, our customers, our company, and our world. We aim to recruit a passionate, high-performing workforce that reflects the world we live in. If you are head-over-heels about this role but unsure if you meet all the requirements, we encourage you to apply!


EQUAL OPPORTUNITY

We are an equal opportunity employer and value diversity at our company. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, disability, and any other protected ground of discrimination under applicable human rights legislation. Box strives to respect the dignity and ‎‎independence of people with disabilities and is committed to giving them the same ‎‎opportunity to succeed as all other employees. Inclusiveness is core to our culture at Box, and we strive to ensure you get the most from your interview experience.

Box makes reasonable accommodations for applicants with disabilities. If a reasonable accommodation is needed to participate in the job application or interview process, please complete this form. Reasonable accommodations may include scheduling adjustments, document dictation and beyond.

Notice to applicants in Los Angeles:  Box, Inc and its related branches will consider for employment, qualified applicants with criminal histories in a manner consistent with the Los Angeles Fair Chair Ordinance.  The Fair Chance Ordinance is provided here. 

Notice to applicants in San Francisco:  Box, Inc and its related branches will consider for employment, qualified applicants with criminal histories in a manner consistent with the San Francisco Fair Chair Ordinance.  The Fair Chance Ordinance is provided here. 

For details on how we protect your information when you apply, please see our Personnel Privacy Notice. If you are a California-resident, please read our California Applicant & Candidate Privacy Notice here.

#LI-Hybrid

Box is committed to fair and equitable compensation practices. Actual base salary (or OTE if commissionable role) is dependent upon factors such as: knowledge, skill level, experience, and work location. This role is also eligible for equity and benefits. For more information, check out our benefits and perks. 
In accordance with OFCCP compliance, here is the Pay Transparency Provision. 

Chicago Pay Range
$190,000—$237,500 USD
Box is committed to fair and equitable compensation practices. Actual base salary (or OTE if commissionable role) is dependent upon factors such as: knowledge, skill level, experience, and work location. This role is also eligible for equity and benefits. For more information, check out our benefits and perks. 
 
In accordance with OFCCP compliance, here is the Pay Transparency Provision. 
Redwood City Pay Range
$211,000—$263,000 USD

Skills Required

  • Bachelor's or Master's degree in computer science, information security or related field
  • 8+ years of experience in corporate/enterprise security engineering (endpoint, network security, cloud security, SaaS security, identity, or a combination)
  • Deep expertise in macOS security with solid knowledge of Windows and ChromeOS
  • Experience deploying and operating device trust and endpoint detection solutions (EDR/XDR) at scale
  • Experience with ZTNA/zero trust architectures, VPNs and hybrid/in-office deployments
  • Experience with identity and access management (IAM/PAM/passwordless authentication)
  • Experience with CASB, Secure Web Gateway, SSPM and DLP solutions
  • Strong understanding of emerging security challenges (shadow IT, AI & agentic identities, SaaS-to-SaaS integrations, browser security, data exfiltration)
  • Experience with security automation using Python, Go, or similar languages
  • Proficiency with SIEM platforms (Splunk, Elastic, SumoLogic) for log analysis and rule creation
  • Experience securing cloud-native and hybrid environments (AWS, GCP, Azure)
  • Familiarity with IaC (Terraform), CI/CD pipelines, and DevSecOps practices
  • Understanding of AI security risks and experience securing AI-centric deployments
  • Exceptional communication skills and ability to translate complex security topics for varied audiences
  • Proven ability to work independently with high autonomy and manage ambiguity

Box Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Box and has not been reviewed or approved by Box.

  • Equity Value & Accessibility — Box grants equity to new hires and offers an ESPP, making ownership a meaningful part of total rewards. Engineering compensation ranges indicate equity is a significant driver of competitive total compensation.
  • Healthcare Strength — Comprehensive medical, dental, vision, and mental-health support are emphasized as core benefits. Health coverage is portrayed as strong across official materials and third-party overviews.
  • Leave & Time Off Breadth — Flexible PTO, paid volunteer time off, holidays, and a paid sabbatical after seven years signal generous time-away policies. These elements are explicitly promoted and stand out in the package.

Box Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Redwood, CA
2,500 Employees
Year Founded: 2005

What We Do

Box (NYSE:BOX) is the leading Content Cloud, a single platform that empowers organizations to manage the entire content lifecycle, work securely from anywhere, and integrate across best of breed apps. Founded in 2005, Box simplifies work for leading global organizations, including AstraZeneca, JLL, and Nationwide. Box is headquartered in Redwood City, CA, with offices across the United States, Europe, and Asia. Visit box.com to learn more. And visit box.org to learn more about how Box empowers nonprofits to fulfill their missions.

Why Work With Us

We have an inclusive culture that is based on development and growth. We value our people as individuals and know that they can make an impact when properly empowered. We fill 30% of all of our open positions with internal people. Everyone is an owner and we are candid with each other in order to learn.

Gallery

Gallery

Similar Jobs

PwC Logo PwC

Site Reliability Engineer

Artificial Intelligence • Professional Services • Business Intelligence • Consulting • Cybersecurity • Generative AI
Hybrid
9 Locations
370000 Employees
124K-280K Annually

Evolver (evolver.ai) Logo Evolver (evolver.ai)

Senior Security Engineer

Artificial Intelligence • Software • Generative AI
In-Office
Palo Alto, CA, USA
52 Employees

Evolver Logo Evolver

Senior Security Engineer

Artificial Intelligence • Information Technology • Cybersecurity • Defense
In-Office
Palo Alto, CA, USA
1000 Employees

Similar Companies Hiring

Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Revel Thumbnail
Aerospace • Hardware • Robotics • Software
Marina Del Rey, California
60 Employees
Blee Thumbnail
Artificial Intelligence • Marketing Tech • Software
New York, New York
30 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account