Logo for Esko

Senior AI Platform Engineer - Security

Role overview

Qualifications

  • Strong software engineering experience designing, building, and operating secure production systems in Python, TypeScript, or a similar language.
  • At least 5 years’ experience in a software engineering role with experience securing cloud, distributed, or platform services.
  • Practical experience with threat modelling, application security testing, and turning identified risks into effective engineering controls.
  • Undergraduate, Master’s degree or PhD in Computer Science / Machine Learning / Data Science / Artificial Intelligence, or related disciplines.

Responsibilities

  • Help shape the AI Platform's security architecture and take end-to-end ownership of substantial security components.
  • Design and build identity, authorization, delegated-access, and policy-enforcement controls for AI systems.
  • Secure retrieval, tool use, and execution against prompt injection, unauthorized actions, data leakage, and other AI-specific threats.
  • Build audit and monitoring capabilities so security-relevant activity is traceable and high-risk behavior can be detected.

Key facts

  • Remote from: Czechia
  • Full time
  • Senior (5-10 years)
  • Platform Engineer
  • Czech

Hard skills

Other skills

  • Communication
  • Collaboration

About the company

Esko logo

Esko

Industrial Automation

Esko is a global provider of integrated software and hardware solutions that accelerate the go-to-market process of packaged goods. Our products empower teams to support and manage the packaging design and print processes for brand owners, retailers, pre-media and trade shops, manufacturers, and converters. Our mission is to provide the most innovative, integrated platform and comprehensive portfolio of tools that intelligently automate, connect, and accelerate the concept to market processes for every packaged product. Esko is a Veralto company (www.veralto.com).

Company details

Company typeLarge
IndustryIndustrial Automation
Company size1001 - 5000

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

Senior AI Platform Engineer - Security 

Location: Prague (Hybrid); Czech Republic (Remote) 
Function: Software Engineering  
Reports to: Team Leader, Esko AI  

  
About the role  

Esko's products handle sensitive customer content and support business-critical workflows. AI-powered and agentic systems introduce additional security challenges because they combine access to sensitive data, specialized tools, and potentially consequential actions within those workflows.  

We are building shared security foundations for Esko's AI Platform so product teams can develop AI capabilities without implementing critical controls independently. As part of the platform team, you will help shape and build these foundations, taking end-to-end ownership of substantial security areas.  

You will collaborate closely with Esko's cloud platform teams, security engineers, compliance specialists, and product engineering teams to develop controls that are secure, practical, and reusable across products. This is a hands-on engineering role, not a compliance or review position.  
  
This is a hands-on engineering role. It is not a compliance or review position. 
  

What you will do  

  • Help shape the AI Platform's security architecture and take end-to-end ownership of substantial security components.  

  • Design and build identity, authorization, delegated-access, and policy-enforcement controls for AI systems, including tenant-, user-, document-, and tool-level permissions.  

  • Secure retrieval, tool use, and execution against prompt injection, unauthorized actions, data leakage, and other AI-specific threats.  

  • Design controls proportionate to the risk of an action, including approval gates, isolation, execution limits, and recovery mechanisms.  

  • Build audit and monitoring capabilities so security-relevant activity is traceable and high-risk behavior can be detected, investigated, and routed for appropriate review.  

  • Conduct threat modelling and adversarial testing, translating findings into shared platform controls and secure defaults for product teams.  

  • Work with cloud platform teams, security engineers, compliance specialists, and product engineering teams to integrate controls that satisfy Esko's security obligations while remaining practical to adopt and operate.  

What we are looking for

  • Strong software engineering experience designing, building, and operating secure production systems in Python, TypeScript, or a similar language.  

  • At least 5 years’ experience in a software engineering role with experience securing cloud, distributed, or platform services, including authentication, authorization, policy enforcement, and multi-tenant isolation.  

  • Practical experience with threat modelling, application security testing, and turning identified risks into effective engineering controls.  

  • Experience designing or building systems using LLMs, retrieval-augmented generation, or agents, with an understanding of their distinctive security failure modes.  

  • Experience building reusable platform controls, APIs, or shared services used by multiple engineering teams.  

  • Sound judgement in balancing security, usability, and operational complexity, including recognizing when stronger isolation or human approval is required.  

  • Ability to communicate security decisions and tradeoffs clearly across engineering, security, compliance, and product stakeholders.  

  • Undergraduate, Master’s degree or PhD in Computer Science / Machine Learning / Data Science / Artificial Intelligence, or related disciplines.  

  • Excellent written and verbal communication, with the ability to work fluently with both technical and business stakeholders alike.  

Preferred experience  

  • Multi-tenant enterprise SaaS platforms.  

  • Permission-aware retrieval systems.  

  • Tool-calling systems or workflow automation.  

  • Adversarial testing or security evaluation for AI systems.  

  • Sandboxing untrusted files or code.  

  • MCP or similar tool-integration protocols.  

  • Document, graphics-processing, or other content-centric platforms.  

What success looks like  

  • Agents operate with scoped permissions.  

  • Sensitive actions require appropriate approval.  

  • Retrieval respects customer access boundaries.  

  • Agent activity is fully auditable.  

  • Automated means are in place to detect high-risk activities which are alerted for further review.  

  • Product teams adopt shared security controls.  

  • Secure AI features reach production faster.  

What We Offer 

  • Joining a highly experienced and long-established engineering hub in Prague 

  • Flexibility to shape and grow the MLOps function - you will be our internal expert 

  • Opportunity to collaborate internationally across multiple product teams 

  • At Veralto, your potential is amplified. Our culture of continuous improvement defines who we are, drives our success, and translates to a career without limits for our team of curious associates 

At Esko, a Veralto Company, innovation comes in every color and never in the same package. Join Esko and see how diversity of people and thought fuels a career journey like no other. Create unique technology solutions for the packaging value chain, bring new ideas to life, make and influence decisions, and experience career growth, rewards, and recognition in our global Packaging & Color organizations. Esko is proud to be a Product Quality & Innovation company in Veralto (NYSE: VLTO).  Imagine a world where everyone has access to clean water, safe food and medicine, and trusted essential goods. That is the tomorrow Veralto is creating today.  Veralto is a $5B global leader in essential technology solutions made up of over 16,000 associates across our Water Quality and Product Identification segments all united by a powerful purpose: Safeguarding the World’s Most Vital Resources.  

#LI-SP1

#LI-Remote

At Veralto, we value diversity and the existence of similarities and differences, both visible and not, found in our workforce, workplace and throughout the markets we serve.  Our associates, customers and shareholders contribute unique and different perspectives as a result of these diverse attributes.
 

Unsolicited Assistance

We do not accept unsolicited assistance from any headhunters or recruitment firms for any of our job openings. All resumes or profiles submitted by search firms to any employee at any of the Veralto companies, in any form without a valid, signed search agreement in place for the specific position, approved by Talent Acquisition, will be deemed the sole property of Veralto and its companies. No fee will be paid in the event the candidate is hired by Veralto and its companies because of the unsolicited referral.

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Platform Engineer Related jobs

Other jobs at Esko

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.