AI Defense Engineer

WilmerHale
  • Boston, MA
  • $120,000–$149,000
  • Full-time
11 days ago

Job Description

WilmerHale is a leading, full-service international law firm with 1,000 lawyers located throughout 12 offices in the United States and Europe. Our lawyers work at the intersection of government, technology and business, and we remain committed to our guiding principles of providing quality, excellent legal and client services; developing diversity among our lawyers and staff and cultivating an environment that promotes an ambitious spirit, collaboration and collegiality by drawing on the extraordinary talents and dynamic experience of our lawyers. Our goal is to reflect the diversity of our clients and the communities in which we practice.

About the Role

The AI Defense Engineer is a technical contributor who helps secure AI capabilities in a global law firm environment. Working under the guidance of the Director of Information Security and in partnership with other Information Services colleagues, this role assists with implementing practical defenses, guardrails, policy enforcement layers, monitoring and detections, adversarial testing, and secure operating practices for AI-enabled systems. The role builds experience translating emerging AI threats into actionable technical controls that help protect firm and client information while supporting responsible AI adoption.

The role supports a smart-integration, buy-before-build security strategy by assisting with the evaluation, selection, configuration, and operational use of commercial AI security solutions. This includes supporting assessments of solutions against legal-sector expectations such as matter confidentiality, ethical walls, client audit requirements, data residency constraints, and contractual information technology service obligations.

Success in this role includes supporting efficient AI tool reviews and approvals, contributing to assessments of internally developed AI solutions, and helping produce evidence of AI cybersecurity protections for audit and client-facing needs. With guidance, the AI Defense Engineer helps engineering and security teams adopt secure-by-default practices, assists with adversarial evaluations that identify issues before production, strengthens telemetry and detections for early abuse indicators, and develops knowledge of evolving AI technology and threat trends.

What You Will Be Doing

  • Threat Modeling & Risk Assessment - Assist with technical threat modeling for AI/ML systems, including neural networks, expert systems, retrieval-augmented generation, classification models, and related AI services. Help identify and document AI-specific risks, including prompt injection, data leakage, jailbreaks, unsafe autonomy, and misuse of vendor-enabled AI capabilities. Support mitigation planning by documenting recommended control configurations, reference patterns, and exception considerations for review by security and technology stakeholders.
  • AI Defense Engineering - Assist with implementing, configuring, and maintaining security controls, guardrails, and enforcement mechanisms for AI services, including input/output filters, policy enforcement layers, content safety checks, rate limiting, and abuse detection. Help monitor and investigate AI-specific attack patterns using logs, telemetry, and model signals. Work with platform and security teams to support the secure integration and operational use of enterprise AI services, including credentials, data flows, storage, and access controls across Copilot and other commercial LLM platforms.
  • Adversarial Testing & Red Teaming - Execute established adversarial test suites for AI applications, including prompt libraries, fuzzing harnesses, and automated testing tools. Simulate common attacker behaviors targeting AI endpoints and agents, document results, and help track identified issues as actionable vulnerabilities. Partner with application, product, and security teams to validate fixes, perform re-testing, and support residual risk tracking.
  • Tooling & Automation - Assist with integrating AI security capabilities into existing and future security stacks, including SIEM, SOAR, EDR, WAF, API gateways, and identity platforms.
  • Incident Response & Forensics for AI Systems - Support security incident response activities involving AI services, abuse, data exfiltration through AI systems, compromised API keys, or poisoned training data. Under guidance, review logs and model behavior to help reconstruct attack paths and identify durable fixes. Contribute to playbook and runbook improvements and post-incident technical reviews.
  • Collaboration - Collaborate with engineering, product, infrastructure, and security colleagues. Communicate technical findings, risks, and recommended remediations clearly to stakeholders. Provide implementation-focused input into AI security standards, guidelines, and procedures, with attention to vendor capability fit, maintainability, and total cost of ownership (TCO).
  • Security Improvements & Operational Readiness - Contribute to prioritized AI security engineering work by translating threat information, risk findings, and operational observations into practical technical recommendations. Participate in technical design reviews, support secure AI architecture patterns, and help ensure AI security controls are tested, documented, supportable, and ready for operational use.
  • Demonstrates a strong commitment to professionalism, delivering high-quality service, and maintaining a positive, solution-oriented (“can-do”) approach. Effectively supports internal departments, external clients, and vendors through clear, courteous communication via electronic correspondence, telephone, and in-person interactions.


Required Skills

What You Will Bring to This Position

  • Foundational knowledge of ML/AI pipelines, including data collection, feature engineering, training, evaluation, deployment, and monitoring.
  • Basic understanding of how enterprise AI services (SaaS/PaaS) are deployed and governed, including data handling, routing, and isolation controls.
  • Hands-on exposure to at least one major cloud platform (AWS, Azure, or GCP) and familiarity with modern infrastructure concepts such as containers, Kubernetes, secrets management, and CI/CD.
  • Foundational security knowledge, including authentication and authorization, network security, data protection, logging and telemetry, secure software engineering practices, and vulnerability management.
  • Familiarity with one or more AI application frameworks (e.g., LangChain, Semantic Kernel, or LlamaIndex), agentic/orchestration platforms, APIs, microservices, or data platforms, a plus
  • Ability to analyze identified risks and, with guidance, translate them into practical technical recommendations such as configuration updates, controls, guardrails, and playbooks.
  • Strong written and verbal communication skills and the ability to collaborate effectively with data scientists, software engineers, and security teams.


Required Experience
  • 1+ years of experience in security engineering, application security, ML/ML Ops engineering or a related technical area.

Education

  • Bachelor’s degree in computer science, information security, or related field; or equivalent work experience.

 

Why Join Us?

  • A values‑driven firm that fosters collaboration and respect
  • The hiring range for this position is $120,000 - $149,000 annually, with final compensation based on experience, qualifications and internal equity
  • This position is eligible for a Hybrid Schedule
  • Medical, dental, and vision insurance
  • 401(k) with company match and profit-sharing options
  • Paid time off and holidays
  • For additional information about our benefits, please click here

 

Our Commitment

Wilmer Cutler Pickering Hale and Dorr LLP (WilmerHale) is an equal opportunity employer and is committed to compliance with all applicable laws prohibiting employment discrimination. It is our policy to take all employment actions and make all employment decisions without regard to race, color, religion, creed, gender, sex (including pregnancy), sexual orientation, gender identity or expression, national origin, ancestry, age, marital status, citizenship status, genetic predisposition or carrier status, disability, military status, status as a disabled or other protected veteran, or any other protected status under applicable law. WilmerHale will make reasonable accommodation for qualified individuals with disabilities and otherwise as required by applicable law. 

#L1-KB1

L1-Hybrid

Numbers & Facts

LocationBoston, MA
Job TypeFull-time
Salary$120,000–$149,000

Skills

  • Access Authorizationunmatched
  • Access Controlunmatched
  • Amazon Web Services (AWS)unmatched
  • Application Frameworkunmatched
  • Application Programming Interface (API)unmatched
  • Applications Securityunmatched
  • Artificial Intelligence (AI)unmatched
  • Authenticationunmatched
  • Automationunmatched
  • Change Controlunmatched
  • Cloud Computingunmatched
  • Communication Skillsunmatched
  • Computer Scienceunmatched
  • Computer Securityunmatched
  • Continuous Deployment/Deliveryunmatched
  • Continuous Integrationunmatched
  • Customer Relationsunmatched
  • Customer Support/Serviceunmatched
  • Data Collectionunmatched
  • Data Scienceunmatched
  • Data Storageunmatched
  • Dental Insuranceunmatched
  • Diversityunmatched
  • Documentationunmatched
  • Establish Prioritiesunmatched
  • Expert Systemsunmatched
  • Forensic Scienceunmatched
  • Fuzz Testingunmatched
  • GCP (Good Clinical Practices)unmatched
  • Governmentunmatched
  • Identify Issuesunmatched
  • Incident Managementunmatched
  • Incident Responseunmatched
  • Information Technology & Information Systemsunmatched
  • Information/Data Security (InfoSec)unmatched
  • Injectionsunmatched
  • Input/Outputunmatched
  • International Lawunmatched
  • Internet Securityunmatched
  • Kernel Programmingunmatched
  • Legalunmatched
  • Machine Toolunmatched
  • Microservicesunmatched
  • Microsoft Windows Azureunmatched
  • Model Reviewunmatched
  • Network Securityunmatched
  • Neural Networksunmatched
  • Operational Improvementunmatched
  • Operations Security (OPSEC)unmatched
  • Platform as a Service (PaaS)unmatched
  • Presentation/Verbal Skillsunmatched
  • Riskunmatched
  • Risk Analysisunmatched
  • Security Information and Event Management (SIEM)unmatched
  • Software Engineeringunmatched
  • Software as a Service (SaaS)unmatched
  • Support Documentationunmatched
  • Team Playerunmatched
  • Technical/Engineering Designunmatched
  • Telemetryunmatched
  • Test Automationunmatched
  • Test Suiteunmatched
  • Test Toolsunmatched
  • Testingunmatched
  • Threat Modelingunmatched
  • Threat and risk analysis (TRA)unmatched
  • Total Cost of Ownershipunmatched
  • Traffic Shapingunmatched
  • Trend Analysisunmatched
  • Vision Planunmatched
  • Writing Skillsunmatched

Be found by employers

5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

Level up your application

Professional resume templates

Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

Free resume templates

Free resume builder

Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

Free resume builder