AI Detect and Respond Engineer

Docusign•Published 1 hours ago•First seen 1 hours ago
Company Overview Docusign brings agreements to life. Over 1.5 million customers and more than a billion people in over 180 countries use Docusign solutions to accelerate the process of doing business and simplify people’s lives. With intelligent agreement management, Docusign unleashes business-critical data that is trapped inside of documents. Until now, these were disconnected from business systems of record, costing businesses time, money, and opportunity. Using Docusign’s Intelligent Agreement Management platform, companies can create, commit, and manage agreements with solutions created by the #1 company in e-signature and contract lifecycle management (CLM). What you'll do We are seeking a talented and proactive AI Detect and Respond Engineer to join our team. This position is focused on defending the organization against AI-enabled threats and leveraging AI to enhance our defensive capabilities. You will act as the bridge between AI security and our operational defense teams (SOC & CSIRT, Detection Engineering, and Threat Intelligence). In this role, you will focus on the threats introduced by LLM and agentic systems, including, but not limited to, prompt injection and indirect prompt injection, unsafe or over-permissioned tool and MCP integrations, agent hijacking and privilege escalation, unintended autonomous actions, and data exfiltration through model inputs and outputs. You will build the detection and monitoring capability that makes this activity visible to our defenders, and design the controls that contain it. You will also implement AI-powered tooling that improves the speed and efficacy of our threat detection and response workflows. This position is an individual contributor role reporting to the Sr Director of AI & Data Security. Responsibility Monitor the threat landscape for emerging tactics, techniques, and procedures (TTPs) targeting LLM and agentic systems, including new prompt injection and jailbreak methods, tool and MCP abuse, and agent-to-agent attack patterns Build monitoring and visibility for LLM and agent activity, including prompt and response logging, tool invocation and MCP call telemetry, and audit trails sufficient to investigate agent actions after the fact Own the configuration and ongoing management of AI protection platforms such as AI Guardrails, including policy authoring, prompt and response inspection rules, and enforcement for sanctioned and unsanctioned AI usage Collaborate with environment owners and Security Tooling teams to implement model security scanning capabilities to ensure coverage and provide ongoing maintenance Extend AI detection and enforcement coverage across our Azure and AWS environments, including cloud-native AI services (e.g., Azure OpenAI Service, Amazon Bedrock) and their associated logging and audit telemetry Collaborate with the Detection and Response teams to develop playbooks and detection logic for AI based risks and attacks, prompt injection, elevation of privilege, data exfiltration, etc Partner with Threat Intelligence teams to track threat actors leveraging LLMs for code generation, exploit development, or reconnaissance Translate technical AI security risks into business impact and communicate recommendations to operational stakeholders Job Designation Hybrid: Employee divides their time between in-office and remote work. Access to an office location is required. (Frequency: Minimum 2 days per week; may vary by team but will be weekly in-office expectation) Positions at Docusign are assigned a job designation of either In Office, Hybrid or Remote and are specific to the role/job. Preferred job designations are not guaranteed when changing positions within Docusign. Docusign reserves the right to change a position's job designation depending on business needs and as permitted by local law. What you bring Basic 5+ years of experience in a Detection and Response engineering role, with at least 1 year focused on AI/ML systems Experience configuring and operating security enforcement platforms (e.g., Zscaler, Netskope, or comparable proxy, DLP, or AI guardrail tooling), including policy tuning and lifecycle maintenance Experience securing workloads in cloud providers (e.g., Azure, AWS) including familiarity with their native AI/ML services and logging and telemetry sources Experience with LLM and agentic attack techniques, including prompt injection and indirect prompt injection, jailbreaks, tool and function-calling abuse, excessive agency, and exfiltration through model outputs Experience investigating or detecting threats in systems where the audit trail is non-deterministic, and building detection logic against noisy or probabilistic signals Experience with the MITRE ATLAS framework (Adversarial Threat Landscape for Artificial-Intelligence Systems), MITRE ATT&CK, and OWASP Top 10 for LLMs and Agents Experience with scripting languages such as Python, Go, or PowerShell for security automation Experience with SIEM, SOAR, and EDR platforms, and an understanding of how to integrate AI/ML models into these workflows Experience translating technical security risks into business context and actionable recommendations Bachelor's or Master's degree in Computer Science, Information Security, or a related field Preferred Excellent communication and collaboration skills, with the ability to influence technical and non-technical stakeholders Certifications: GCIH, GCTI, CISSP, or AI-specific security certifications Experience with "Red Teaming" AI systems or conducting adversarial simulations Knowledge of frameworks such as NIST AI RMF, ISO 42001, and NIST CSF Experience operating security tooling across multi-cloud environments and integrating enforcement controls with identity, network, and endpoint platforms Experience driving automation strategies, predictive analytics, and data-driven insights Life at Docusign Working here Docusign is committed to building trust and making the world more agreeable for our employees, customers and the communities in which we live and work. You can count on us to listen, be honest, and try our best to do what’s right, every day. At Docusign, everything is equal. We each have a responsibility to ensure every team member has an equal opportunity to succeed, to be heard, to exchange ideas openly, to build lasting relationships, and to do the work of their life. Best of all, you will be able to feel deep pride in the work you do, because your contribution helps us make the world better than we found it. And for that, you’ll be loved by us, our customers, and the world in which we live. Accommodation Docusign is committed to providing reasonable accommodations for qualified individuals with disabilities in our job application procedures. If you need such an accommodation, or a religious accommodation, during the application process, please contact us at accommodations@docusign.com. If you experience any issues, concerns, or technical difficulties during the application process please get in touch with our Talent organization at taops@docusign.com for assistance. Applicant and Candidate Privacy Notice = Hybrid