NewEngineering

Senior AI Platform Security Engineer

Charger Logistics Inc

Brampton30 min ago

Apply now

About the role

Charger logistics Inc. is a world- class asset-based carrier with locations across North America. With over 20 years of experience providing the best logistics solutions, Charger logistics has transformed into a world-class transport provider and continue to grow.

We are looking for a highly motivated Senior AI Platform Security Engineer to join our team based out of our Brampton office and own the platform our AI agents run on. We're standardizing on Google's Gemini Enterprise Agent Platform (formerly Vertex AI) for agents in GCP, with Datadog for observability and zero-trust networking connecting cloud agents to internal systems.

You'll build, secure and operate this stack: agent identity and governance in GCP, the network paths that let agents reach our private systems safely, and the monitoring that shows what every agent is doing and what it costs.

Responsibilities

  • Build and operate our agent infrastructure on Gemini Enterprise Agent Platform, including Agent Engine, Agent Gateway, Agent Registry, Agent Identity and Model Armor.
  • Own the security architecture for agents in GCP:
  • a unique identity for every agent
  • least-privilege IAM
  • all tool calls routed through Agent Gateway
  • Model Armor protection against prompt injection and data leakage
  • registration before production
  • Design and run zero-trust access for cloud agents reaching internal systems, using Cloudflare Tunnel or Tailscale, narrowly scoped service publishing, and approved-destination lists for outbound traffic.
  • Own agent observability in Datadog: end-to-end tracing, token and cost monitoring, latency and drift alerts, with OpenTelemetry as the standard.
  • Enable pre-production testing and evaluation of agents, and require security review before launch.
  • Maintain audit logging and contain agent security incidents, working with our IAM team on credential revocation.
  • Build the paved road (templates, standards and guardrails) so teams can ship agents quickly and safely, and support the teams building them.
  • Work with our IAM team on identity across GCP, Okta and Entra ID.

Requirements

  • 5+ years in cloud platform, DevOps/SRE or cloud security engineering, with strong GCP depth. A Professional Cloud Security Engineer or Professional Cloud Architect certification is a plus.
  • Solid GCP IAM fundamentals: service accounts, workload identity, org policy and VPC Service Controls.
  • Hands-on experience with Vertex AI / Gemini Enterprise Agent Platform, or real depth with LLM applications and agent frameworks (ADK, LangChain, LangGraph or similar).
  • Zero-trust networking and threat modeling experience (Cloudflare, Tailscale, Zscaler or equivalent) on Linux.
  • Production observability experience (Datadog preferred) and working knowledge of OpenTelemetry.
  • Terraform and strong Python.
  • The judgment and confidence to say no. You're the control point between fast-moving AI experiments and production.

Nice to Have

  • LLM observability or evaluation tooling (Datadog LLM Observability, Langfuse, Arize or similar).
  • MCP, agent-to-agent orchestration, or defenses against prompt injection.
  • Policy-as-code (OPA or GCP org policy constraints) or secrets management (Secret Manager, Vault).
  • Integration with Okta or Entra ID.
  • Experience in logistics, transportation, supply chain or another high-volume, 24/7 operations environment.

Benefits

  • Competitive Salary
  • Healthcare Benefit Package
  • Career Growth

Source: the employer's own careers page.

Similar jobs