Full-Time

AI Software Engineer

Bishop Fox

Bishop Fox

201-500 employees

Offensive cybersecurity services and risk management

No salary listed

California, USA

In Person

Category
Software Engineering (2)
,
Required Skills
LLM
Kubernetes
Microsoft Azure
Python
Threat modeling
Machine Learning
Java
Docker
Vulnerability Analysis
Microservices
AWS
REST APIs
LangChain
penetration testing
C/C++
Google Cloud Platform
Requirements
  • Bachelor’s degree or higher in Computer Science, Computer Engineering, Software Engineering, Artificial Intelligence, Cybersecurity, Information Security, or a closely related technical field
  • Strong foundation in algorithms, data structures, and object-oriented programming
  • Proficiency in programming languages such as Python, Java, C++, or similar
  • Experience developing AI or machine learning systems for security-related applications
  • Experience working with large language models (LLMs) and prompt engineering techniques
  • Experience with AI orchestration frameworks (e.g., LangChain, LlamaIndex, AutoGen, Semantic Kernel, or similar)
  • Experience implementing secure software development lifecycle (SSDLC) practices
  • Knowledge of cybersecurity concepts including vulnerability management, threat modeling, penetration testing, SIEM/SOAR platforms, and common attack vectors
  • Experience deploying applications in cloud environments (AWS, Azure, or GCP)
  • Familiarity with containerization and orchestration tools (Docker, Kubernetes)
  • Experience building RESTful APIs and microservices architectures
Responsibilities
  • Architect and implement AI-powered systems that perform autonomous or semi-autonomous cybersecurity tasks, including vulnerability analysis, threat detection, alert triage, log analysis, and secure code review
  • Design multi-agent architectures capable of orchestrating specialized AI agents (e.g., vulnerability scanning agents, log analysis agents, exploit pattern detection agents)
  • Develop retrieval-augmented generation (RAG) pipelines to enable AI systems to securely query internal knowledge bases, threat intelligence feeds, CVE databases, and security documentation
  • Utilize large language models to generate secure software components, scripts, detection logic, and test cases
  • Review and refine AI-generated code to ensure compliance with secure coding standards (e.g., OWASP Top 10, secure SDLC practices)
  • Implement automated guardrails to detect insecure outputs, prompt injection vulnerabilities, model hallucinations, and data leakage risks
  • Design validation frameworks to benchmark AI-generated security outputs against known vulnerability patterns
  • Design and implement reinforcement learning from human feedback workflows for cybersecurity use cases
  • Develop evaluation metrics for AI accuracy in threat detection, vulnerability identification, and remediation recommendations
  • Continuously refine prompt engineering strategies, model tuning parameters, and system architecture to improve security reliability and precision
  • Implement explainability mechanisms to support auditability and defensibility of AI-driven security decisions
  • Develop and maintain APIs and microservices to integrate AI-powered security tools into enterprise platforms
  • Architect scalable and fault-tolerant distributed systems to support real-time security event processing
  • Deploy AI-enabled services within secure cloud environments (AWS, Azure, or GCP) using containerization and orchestration technologies (Docker, Kubernetes)
  • Integrate AI systems with SIEM, SOAR, vulnerability management, and endpoint detection platforms
  • Conduct threat modeling for AI systems to identify adversarial risks, model exploitation vectors, and prompt injection vulnerabilities
  • Implement secure authentication, authorization, encryption, and data governance controls
  • Develop safeguards to prevent misuse of AI systems in exploit development or unintended security bypass scenarios
  • Perform security reviews and penetration testing of AI-driven software components
  • Design automated test pipelines for AI-driven security workflows
  • Conduct adversarial testing to evaluate resilience against malicious inputs
  • Monitor system performance metrics (latency, false positive rates, detection accuracy)
  • Optimize inference pipelines and distributed systems for reliability and scalability
  • Produce detailed architectural documentation for AI security systems
  • Collaborate with cybersecurity researchers, product teams, software engineers, and cloud architects to translate threat intelligence and security requirements into scalable AI-enabled solutions
  • Provide technical guidance on AI governance, responsible AI deployment, and secure AI lifecycle management
Desired Qualifications
  • Master’s degree in Computer Science, Artificial Intelligence, or Cybersecurity
  • Experience designing AI systems for automated threat detection or exploit analysis
  • Experience with reinforcement learning, fine-tuning, or model evaluation frameworks
  • Experience integrating AI systems with cybersecurity tooling ecosystems
  • Familiarity with NIST, ISO 27001, or similar security standards

Bishop Fox focuses on offensive cybersecurity, testing clients’ networks and applications against real-world attack techniques to find and fix vulnerabilities before attackers exploit them. Its flagship Cosmos blends automated scanning with expert testing to continuously identify and remediate high-risk exposures on dynamic attack surfaces. Unlike many firms that rely on point-in-time tests, Bishop Fox emphasizes hands-on, real-world attack simulations and ongoing remediation across a broad set of services. The goal is to help organizations continuously reduce risk by exposing and closing security gaps before they can be exploited.

Company Size

201-500

Company Stage

Series B

Total Funding

$154M

Headquarters

Phoenix, Arizona

Founded

2005

Simplify Jobs

Simplify's Take

What believers are saying

  • Revenue hit $73.5 million in 2025 from rising offensive security demand.
  • $129 million Series B funding in 2022 fuels expansion into Europe and AI tools.
  • Launched AIMap on May 1, 2026, capturing AI infrastructure security market.

What critics are saying

  • Google's Mandiant acquisition bundles offensive security, eroding Cosmos market share by 2027.
  • Bishop Fox's open-source AIMap enables competitors to replicate AI scanning immediately.
  • No funding since 2022 exhausts cash on 2026 executive hires, risking shutdown by 2028.

What makes Bishop Fox unique

  • Bishop Fox leads with Cosmos platform for continuous threat exposure management.
  • Largest private offensive security firm simulates real-world attacks on AI and cloud.
  • Designed Fortune 100 third-party security program testing over 1,000 partners since 2019.

Help us improve and share your feedback! Did you find this helpful?

Your Connections

People at Bishop Fox who can refer or advise you

Benefits

Health Insurance

Dental Insurance

Vision Insurance

401(k) Retirement Plan

401(k) Company Match

Paid Vacation

Paid Holidays

Remote Work Options

Flexible Work Hours

Family Planning Benefits

Fertility Treatment Support

Parental Leave

Wellness Program

Gym Membership

Phone/Internet Stipend

Growth & Insights and Company News

Headcount

6 month growth

1%

1 year growth

2%

2 year growth

1%
The Manila Times
Feb 11th, 2025
Bishop Fox appoints Christopher Martin as Chief Operating Officer

Bishop Fox also expanded its European presence, and added former @Stake and Neohapsis CEO, James Mobley to its Advisory Board.

HIT Consultant
Aug 29th, 2024
Penalizing Hospitals Won’T Stop Ransomware: Why Collaboration, Not Fines, Is Key To Healthcare Cybersecurity

Chris Bowen, Founder and CISO, ClearDATAThe recent $50 million initiative announced by the Advanced Research Projects Agency for Health (ARPA-H) can’t hurt in the ongoing battle against ransomware in the healthcare sector. This investment is aimed at strengthening the cybersecurity defenses of hospitals nationwide, protecting sensitive patient data, and enhancing the resilience of healthcare systems against cyber threats. However, I must emphasize that while $50 million is a step in the right direction, it is merely a drop in the bucket given the scale of the problem. For years, the healthcare sector has been a prime target for cybercriminals, with ransomware attacks becoming alarmingly frequent and increasingly destructive. Major organizations like Change Healthcare and Ascension have faced significant disruptions due to these breaches. The 2023 Ponemon Institute report indicates that 45% of healthcare organizations experienced a ransomware attack, with 67% of those incidents causing significant disruptions to patient care. These attacks not only compromise patient data but also jeopardize the delivery of essential healthcare services, potentially endangering lives. The introduction of ARPA-H’s Universal PatchinG and Remediation for Autonomous DEfense (UPGRADE) program is a timely and necessary intervention. A Proactive Approach to Cybersecurity The UPGRADE program aims to develop a comprehensive and scalable software suite to enhance the cybersecurity posture of hospitals. By reducing the patching time for vulnerable healthcare products from months to mere days, UPGRADE seeks a transformative shift in how hospitals can defend against cyber threats. The initiative focuses on four key areas:  creating a vulnerability mitigation platform developing high-fidelity digital twins of hospital equipment rapidly detecting software vulnerabilities developing defenses for each identified vulnerability These technical goals represent a proactive approach to cybersecurity, moving away from the reactive measures that have characterized the healthcare sector’s responses in the past. For instance, developing digital twins will allow hospitals to simulate and test the impact of patches and updates in a controlled environment, thereby reducing the risk of unintended consequences that could disrupt patient care and providing hospital staff and patients with much-needed confidence and peace of mind. Penalties Are Counterproductive Despite the strategic direction of the UPGRADE program, it is crucial to reconsider how regulatory bodies like the Office for Civil Rights (OCR) approach cybersecurity in healthcare

SecurityBrief Asia
Mar 4th, 2024
Bishop Fox launches comprehensive service for business application security

Bishop Fox launches comprehensive service for business application security.

Bishop Fox
Oct 24th, 2023
Cosmos: Unleashing the Power of Perimeter Protection

To add real-world context behind attackers' actions, Bishop Fox launched the groundbreaking 2022 SANS Survey Report: Inside the Minds & Methods of Modern Adversaries, where Bishop Fox delved deep into the minds and tactics of modern adversaries.

Phoenix New Times
Jul 18th, 2023
Bishop Fox appoints Patrick Davis as CFO

Bishop Fox appoints Patrick Davis as CFO.