How to apply for Security Operations Specialist
HiddenLayer
About HiddenLayer
HiddenLayer builds security for machine learning models and AI systems, protecting them from adversarial attacks. It was founded by AI and security specialists and has won RSA's Innovation Sandbox, CB Insights AI 100, CyberTech 100, and SC's Most Promising Early-Stage Start-up. The company recently raised funding and is growing its enterprise build-out.
About the role
This role runs security operations for HiddenLayer's own cloud infrastructure, endpoints, logging, and alerting, while also acting as the internal AI security expert. You will use HiddenLayer's own tools to protect its AI deployments, join customer calls to demonstrate threat hunting, and support product and IT security needs. It combines hands-on SecOps work with direct customer-facing AI security work.
A typical day
You might start by reviewing alerts and logs from cloud and endpoint systems, then spend time on a threat hunting task or a vulnerability workflow. Later you could join a customer call to demonstrate AIDR threat hunting, then work with engineering or IT on cloud hardening or a compliance control. The mix of internal SecOps and customer-facing AI security work will vary by week.
Who HiddenLayer is looking for
- Has hands-on security operations experience across cloud infrastructure security, endpoint security management, and logging/alerting management.
- Has done threat hunting and vulnerability and risk management, including tooling, processes, workflows, and automation.
- Understands AI/ML security risks such as adversarial attacks, model scanning, or ML risk assessment, or can show fast learning in this area.
- Can work with engineering and IT teams on cloud hardening, compliance framework security controls, and security tool ownership.
Tips for this application
- Lead your resume with concrete SecOps work: which cloud platforms you secured, what endpoint tools you managed, and what logging/alerting systems you ran.
- Give examples of threat hunting that led to a detection, a blocked attack, or a process change. Quantify where possible.
- Show any AI or ML security exposure, even if it is coursework, side projects, or reading on adversarial AI. This company's whole product is AI security.
- Mention specific security tooling you have owned or managed, since the role includes security tool ownership and management.
- If you have customer-facing experience, highlight it. This role joins customer calls to demonstrate AIDR usage and threat hunting.
What to cover in your cover letter
Explain why AI security specifically interests you and connect it to HiddenLayer's focus on adversarial AI attacks. Describe a threat hunting or detection effort you ran end to end. Show you can support both engineering and IT teams on security priorities. State that you can be the internal AI security expert and use HiddenLayer's own tools on its deployments.
Draft a cover letterResearch before applying
- Read HiddenLayer's product pages on AIDR, model scanning, threat modeling, and red team assessment to understand what you would be using and demonstrating.
- Look up what adversarial AI attacks are, including common techniques, so you can speak to them in interviews.
- Review the company's funding news and award wins to understand its stage and growth plans.
- Check HiddenLayer's public content, talks, or blog posts to learn how it describes AI security to customers.
Likely interview topics
Based on the job description, expect questions about:
- Walk through a threat hunting investigation you led from hypothesis to conclusion.
- How would you secure a cloud environment that hosts machine learning model training and inference?
- How do you build logging and alerting that catches real threats without flooding the team with noise?
- What do you know about adversarial AI attacks, and how would you explain AIDR to a customer on a call?
- How have you handled vulnerability and risk management, including automation and workflow design?
Common mistakes to avoid
- Applying with only general IT security experience and no cloud, endpoint, or logging/alerting specifics.
- Ignoring the AI security angle. The role requires being the internal AI security expert and using HiddenLayer tools.
- Claiming customer-facing skills without any examples of presenting technical material to customers or stakeholders.
Deadline
No deadline is listed. Roles without a deadline usually close once the employer has enough candidates, so apply soon if you are interested.