Position
The Technology and Operations team is seeking a pragmatic, technically deep, execution-focused cybersecurity leader to secure the firm's adoption of artificial intelligence, generative AI, and agentic technologies. As the AI Cybersecurity Lead, you will serve as the firm's senior technical authority for AI security, partnering across Technology, Risk, Compliance, Legal, and the business to enable rapid AI adoption while managing risk. This is a hands-on leadership role responsible for designing secure AI architectures, establishing governance and security controls, and protecting data, models, credentials, and business processes from threats such as prompt injection, model abuse, data leakage, and unauthorized agent actions. Success requires translating emerging AI risks into practical, enforceable controls while shaping the firm's long-term AI security strategy.
Responsibilities
- Own the firm's AI security strategy and serve as the senior technical authority on secure design and operation of AI, generative AI, and agentic systems.
- Design secure AI architectures and reusable security patterns for AI applications, retrieval systems, model integrations, agent frameworks, and MCP services.
- Establish and enforce security controls across agent execution, permissions, data access, secrets management, credential protection, and runtime containment.
- Lead AI threat modeling, adversarial testing, and security assessments covering prompt injection, jailbreaks, excessive permissions, and autonomous attack scenarios.
- Build AI detection and response capabilities with Security Operations, including monitoring, logging, investigations, and incident response for AI-related threats.
- Embed security throughout the AI development lifecycle, including governance, dependency management, secure orchestration, and deployment controls.
- Assess third-party AI platforms and services for security, privacy, data protection, and operational risk.
- Monitor emerging AI threats and regulatory developments, advise senior leadership, and document security standards, architecture, and risk assessments.
Qualifications
- 10+ years of cybersecurity experience including 5+ years in security engineering or security architecture.
- Bachelor's degree in a technical discipline or equivalent engineering experience.
- Hands-on experience securing production AI systems, including LLM applications, retrieval-augmented generation (RAG) solutions, agent frameworks, and model hosting platforms.
- Deep cloud security expertise, preferably within Azure environments (Entra ID, Azure OpenAI/AI Foundry, Key Vault, Defender for Cloud), with comparable AWS or GCP experience considered.
- Strong knowledge of identity, access, secrets, and credential management, including OAuth 2.0, OpenID Connect, managed identities, token exchange, vaulting, and workload authentication.
- Experience performing AI threat modeling, adversarial testing, red teaming, or penetration testing, with expertise in threats such as prompt injection, model abuse, excessive permissions, data exfiltration, and supply chain compromise.
- Strong detection engineering and secure SDLC experience, including security monitoring, logging requirements, vulnerability management, secure design reviews, and CI/CD pipeline security.
- Proficiency in Python and experience building security tooling, automation, evaluation frameworks, or detection capabilities.
- Working knowledge of security and AI governance frameworks including NIST CSF, NIST AI RMF, MITRE ATT&CK/ATLAS, OWASP Top 10 for LLM Applications, CIS, and CSA frameworks.
- Experience with modern AI ecosystems, including agent frameworks, orchestration platforms, MCP, LangGraph, Semantic Kernel, Microsoft Copilot Studio, or similar technologies, along with securing containerized, Kubernetes, and sandboxed workloads, preferred.
- Experience applying data protection controls to AI systems and communicating complex security risks to both technical and executive audiences; experience with AI incident response, model supply chain security, or AI security research is a plus, preferred.
Skills
- Judgment under ambiguity; ability to design enforceable controls for agentic systems where settled industry practice does not yet exist and distinguishes a real control from a policy statement.
- Builds rather than documents; ability to deliver working prototypes, reference patterns, and automation using Python, PowerShell, Terraform or Bicep, and GitHub Actions that engineering can adopt directly.
- Vendor skepticism; ability to evaluate AI security tooling against a concrete threat model and clearly identifies coverage gaps.
- Clear technical communication; ability to produce architecture documentation, threat models, and control narratives that withstand audit and regulatory review.
- Constructive gatekeeping; ability to decline unsafe requests while offering workable alternatives that keep AI adoption moving.
Compensation Range
The anticipated base salary range for this role is $175,000 to $225,000. Base salary for the role will depend on several factors, including a candidate’s qualifications, skills, competencies, and experience, and may fall outside of the range shown. In addition, this role may be eligible for a discretionary bonus. Rockefeller Capital Management offers a comprehensive benefit package including health coverage, vacation time, paid leave, retirement plan, and more. Visit careers.rockco.com to learn more about additional opportunities and benefits offerings.