Senior Enterprise AI Security Engineer
Boxinc · Redwood City, CA, United States · 2026-10-01
About this role
WHAT IS BOX?
Box (NYSE:BOX) is the leader in Intelligent Content Management. Our platform enables organizations to fuel collaboration, manage the entire content lifecycle, secure critical content, and transform business workflows with enterprise AI. We help companies thrive in the new AI-first era of business. Founded in 2005, Box simplifies work for leading global organizations, including JLL, Morgan Stanley, and Nationwide. Box is headquartered in Redwood City, CA, with offices across the United States, Europe, and Asia.
By joining Box, you will have the unique opportunity to continue driving our platform forward. Content powers how we work. It’s the billions of files and information flowing across teams, departments, and key business processes every single day: contracts, invoices, employee records, financials, product specs, marketing assets, and more. Our mission is to bring intelligence to the world of content management and empower our customers to completely transform workflows across their organizations. With the combination of AI and enterprise content, the opportunity has never been greater to transform how the world works together and at Box you will be on the front lines of this massive shift.
WHY BOX NEEDS YOU
Box has a world class security organization responsible for protecting our customer and employee data around the globe. We are looking for a Senior Enterprise AI Security Engineer to join our Enterprise Security team and own how Box adopts AI internally — safely, quickly, and at scale.
This role pairs enterprise security architecture with hands-on engineering. You will assess the AI tools and agent workflows Boxers want to use, then convert each assessment into a control that holds for everyone who adopts something similar later. You do not need to have trained a model, but you do need working intuition for the failure modes: an agent handed more authority than its task requires, untrusted text arriving as instructions, or company data leaving quietly inside an API call.
You will partner closely with IT, Infrastructure, Incident Response, Legal, Privacy, and the business functions piloting AI, shaping the technical direction of Box's secure AI adoption program.
WHAT YOU'LL DO
Core Mission
Design, build, deploy, and maintain comprehensive security systems that allow Box's workforce use AI tools and agents productively without losing visibility, identity boundaries, or control of company data.
•
Architect and operate the control plane for workforce AI: AI gateways, prompt and response logging, and egress controls across approved assistants and copilots/agents
•
Extend identity and access management to agentic and non-human identities — scoping, credential lifecycle, delegation, OAuth grant review, and revocation for agents and connectors reaching into corporate SaaS
•
Gate what internal agents can reach: an approval path for MCP servers and connectors, scoped permissions per tool, and isolated execution for anything that runs code
•
Harden the AI-era endpoint and browser layer: enterprise browser policy, extension governance, AI-assisted developer tooling, and local agent runtimes
•
Build the shared enforcement layer — policy engines, brokers, approval registries, internal libraries — that catches risky behavior in flight: injected instructions, attempts to talk around a restriction, tools used outside their intended purpose, sensitive data heading somewhere it should not, and agents behaving nothing like they did last week
•
Lead security architecture reviews and threat modeling for AI vendors, AI features enabled inside existing SaaS platforms, and internal agent deployments, tracing where untrusted content, company data, and privileged credentials meet in each one
•
Own the standards, reference architectures, and paved paths that define what approved AI usage concretely means at Box, and build reusable patterns
•
Partner with IT, Infrastructure, Incident Response, Engineering, Legal, and Privacy to mature AI governance, including AI-specific response playbooks
•
Automate through scripting, infrastructure-as-code, and orchestration instead of manual review queues, and bring AI-assisted investigation tooling to the security team itself
•
Help raise the technical bar across the team through design and code review, mentoring and guidance
Future Focus
This role is for a security engineer who can meet today's adoption requests while building for fleets of agents acting on behalf of employees, delegated authority across systems of record, and corporate data flowing through models. Your work will directly shape how Box secures its people, protects customer data, and holds its position as a trusted leader in intelligent content management.
WHO YOU ARE
Box is an AI-first company. This means you approach your work with a growth mindset and find ways to leverage AI to help make faster, smarter decisions that will 10X your impact at Box, while providing safe adoption patterns for the company.
You are a security professional with:
•
Bachelor's or Master's degree in computer science, information security, or a related field, or equivalent practical experience
•
6+ years in enterprise or corporate security engineering, security platform engineering, application or product security, or a combination — with meaningful recent time spent on AI or agentic systems
•
Hands-on experience securing real AI deployments — enterprise assistants, internal agents and the tool ecosystems around them, grounded search or RAG over company data, or AI coding tools inside a developer environment
•
A working mental model of how AI systems get abused and paired with the ability to analyze AI workflows to determine guardrails.
•
Strong identity and access management fundamentals
•
Experience with security automation in Python, Go, or a similar language, and a track record of building tooling, libraries, or platform controls
•
Fluency in the emerging problems of this space:…
Skills asked for
- python
- go
Similar jobs
- Senior Partner Sales Manager, Enterprise WestBoxinc · Redwood City
- Senior Enterprise Systems AnalystChanzuckerberginitiative · Redwood City
- Senior Enterprise Systems Analyst, ProcurementChanzuckerberginitiative · Redwood City
Your next role is already in here.
Search live openings from thousands of employers, save the ones worth a second look, and let JobBob keep watch for the rest.