Job TitleAI Runtime & Trust Security Advisor II
About your roleYou will lead the security of AI in production - both what deployed AI does and what it is allowed to do - detecting AI-specific threats such as prompt injection, jailbreaks, and inference-time data exfiltration while helping govern identity, authorization, and secrets for AI systems and agents. The role operates the market's AI protection tooling along with building detection in-house: commercial AI observability and guardrail platforms (e.g., Arize, Fiddler), data security posture management for AI (e.g., Varonis), and the enterprise SIEM/SOAR, IAM, and secrets stack. Sitting within Cybersecurity, it helps lead a cross-functional model that connects Cyber's services with the SOC, IAM, Data Governance, and platform teams as Fiserv scales AI in production.
What you'll do- Stand up and operate runtime monitoring, guardrails, and model-integrity checks for production AI workloads using commercial AI observability and guardrail platforms - detecting prompt injection, jailbreaks, model abuse, drift, and anomalous inference, and tuning thresholds and alert quality.
- Serve as the primary SOC liaison for AI security events - providing platform context, triage support, and expertise on AI-specific attack patterns general SOC analysts may not recognize - and help maintain AI-specific incident response playbooks.
- Help lead the enterprise authorization model for agentic AI - partnering with IAM and the AI Center of Excellence to define what agents may do, on behalf of whom, with what tool scope and duration - and help extend the identity fabric to AI agents as first-class principals (workload identity standards such as SPIFFE/SPIRE, OIDC).
- Operate identity anomaly detection and policy enforcement for AI workloads and agents, adjudicating scope violations and out-of-scope tool calls.
- Help lead data security posture for AI in partnership with Data Governance - operating DSPM tooling (e.g., Varonis, Cyera, or equivalent) to detect and reduce over-permissioned data exposure to copilots and agents, and responding to AI data-exposure findings.
- Partner with the Cloud and platform teams to define and operate secrets hygiene and network egress controls for AI workloads, particularly agent tool-call boundaries and model API access.
- Adjudicate novel authorization requests and escalations that require human judgment on risk tolerance, and lay the groundwork for a future automation layer as the program matures.
- Responsibilities listed are not intended to be all-inclusive and may be modified as necessary.
Experience you'll need to have- 7+ years in security engineering spanning at least two of: AI/ML runtime security, security operations and detection engineering, and identity / trust engineering.
- Hands-on familiarity with AI attack patterns: prompt injection, jailbreaks, model inversion, and inference-time data exfiltration.
- Experience operating commercial AI observability and/or guardrail platforms (Arize, Fiddler, or equivalent) and SIEM/SOAR (Splunk, Microsoft Sentinel, Chronicle, or equivalent).
- Direct experience securing non-human and service identities, including workload identity standards (SPIFFE/SPIRE, OIDC) and authorization policy engines (Open Policy Agent, Cedar).
- Working knowledge of data security posture management (Varonis, Cyera, BigID, or equivalent) and secrets management (HashiCorp Vault, AWS Secrets Manager, Azure Key Vault).
- Comfort partnering across the SOC, IAM, Data Governance, and platform teams, leading shared outcomes through influence.
- Bachelor's degree in Computer Science, Cybersecurity, or a related field, and/or equivalent work experience.
Experience that would be great to have- Experience in financial services or other regulated industries with AI-specific compliance, privileged access management, or non-human identity governance at scale.
- Hands-on experience with LLM red teaming or adversarial ML testing.
- Experience designing authorization models for multi-agent AI systems - delegation chains, capability scoping, and time-bounded access grants.
- Certification in CISSP, CISM, CCSP, or equivalent; security operations or IAM certifications.
- Familiarity with AI network egress controls (tool-call boundaries, model API access) and zero trust applied to machine identities.
How you'll workThis role is on-site Monday through Friday. Fiserv considers in-person collaboration to be an essential part of this role as in-person office experiences help you with your overall onboarding experience and leads to stronger productivity.
TravelApproximately 10% travel off-site or to other office locations is expected.
SponsorshipYou must currently possess valid and unrestricted U.S. work authorization to be considered for this role. Individuals with temporary visas including, but not limited to, F-1 (OPT, CPT, STEM), H-1B, H-2, or TN, or any candidate requiring sponsorship, now or in the future, will not be considered.
#LI-RM1
Salary Range:$109,000.00-$152,000.00
These pay ranges apply to employees in Maryland. Pay ranges for employees in other states may differ. Certain Positions are Commissions eligible.
It is unlawful to discriminate against a prospective employee due to the individual's status as a veteran.
Thank you for considering employment with Fiserv. Please:
- Apply using your legal name
- Complete the step-by-step profile and attach your resume (either is acceptable, both are preferable).