AI Security Lead EngineerThe AI Security Lead Engineer is responsible for designing, implementing, and operating enterprise grade security controls for artificial intelligence (AI) and machine learning (ML) solutions across the organization. This role leads the technical execution of AI security strategy, ensuring AI solutions are securely designed, risk assessed, continuously monitored, and compliant with applicable regulatory, privacy, and model risk requirements.
The role acts as the technical authority for AI security, partnering closely with Enterprise Architecture, Cloud Platform, DevSecOps and Business AI teams to enable secure AI innovation while protecting sensitive data, models, and decision systems across the enterprise.
KEY RESPONSIBILITIESAI Security Engineering, Controls & Enable Monitoring
- Participate in architectural design decisions from cyber and implement security design for AI/ML platforms, models, agents, APIs, and data pipelines across cloud and on prem environments
- Perform cyber review of security reference architectures and guardrails for GenAI, LLMs, copilots, RAG pipelines, and agent based systems
- Embed security by design principles into AI solution lifecycles (intake build deploy operate)
- Ensure organization standards meet Model Risk Management (MRM), SR 11 7 alignment, and regulatory requirements
- Implement and operate AI Security Posture Management (AI SPM) capabilities, including discovery of sanctioned and shadow AI
- Define and enforce controls for:
- Identity and access for AI services and agents
- Data ingestion, training, and inference pipelines
- API keys, secrets, and model endpoints
- Enable continuous monitoring for AI specific threats, anomalies, and misuse across environments
- Partner with developers and cloud platforms teams to enable secure AI adoption, not block it
- Define reusable security patterns, templates, and automation for AI pipelines (IaC, policy as code, guardrails)
- Integrate AI security controls into CI/CD and DevSecOps workflows
- Act as the AI security escalation lead for AI related security incidents and investigations
- Develop AI incident response playbooks covering model compromise, data exposure, and abuse scenarios
- Partner with SOC and IR teams to operationalize AI specific detections and response procedures
Leadership & Influence
- Serve as the technical lead and mentor for AI security engineers and partners
- Influence standards, policies, and enterprise security roadmaps for AI
- Communicate AI security risks and solutions clearly to technical and non technical stakeholders
REQUIRED QUALIFICATIONSCore Experience
- 8-12+ years of experience in cybersecurity, cloud security, or applied security engineering
- 2+ years of hands on experience securing AI/ML, data platforms, or analytics systems
- Proven experience designing and operating security controls in regulated environments (financial services strongly preferred)
Technical Expertise
- Strong knowledge of:
- AI/ML architectures (training, inference, pipelines, agents, RAG)
- Cloud platforms (AWS, Azure) and cloud native security
- Identity & Access Management (IAM) for services, workloads, and APIs
- Data protection, encryption, and privacy controls
- Experience with AI/Cloud Security tools (e.g., AI SPM, CSPM, CNAPP, DLP, logging, monitoring platforms)
Governance & Risk
- Familiarity with:
- Model Risk Management (MRM) concepts
- SR 11 7, SOC 2, ISO 27001, NIST, and privacy regulations
- Third party and vendor risk assessments for AI solutions
Engineering & Automation
Experience with:
- Infrastructure as Code (Terraform or equivalent)
- Security automation and policy as code
- CI/CD pipeline integration for security controls
Soft Skills
- Ability to translate complex technical risks into business relevant outcomes
- Strong collaboration skills across architecture, platform and business teams
- Comfortable operating as a technical authority in high visibility initiatives
Preferred Qualifications
- Experience securing GenAI/LLM platforms, copilots, or agent based systems
- Prior involvement in regulatory exams or internal audits related to AI or emerging technology
- Cloud or security certifications (AWS, CCSK, CISSP, etc.)
- Experience defining or operating an enterprise AI security program
Success Measures (First 12 Months) (Suggested)
- Standardized AI security intake, assessment, and deployment guardrails are fully operational
- Continuous AI asset discovery and monitoring enabled across environments
- Measurable reduction in AI related security and compliance gaps
- Trusted partnership established with AI committee, enterprise architecture and Cloud Platform teams
Important: The candidate must provide evidence of academic preparation or courses related to the job posting, if necessary.
Our hybrid workplace model is a flexible benefit designed to support the evolving needs of our organization and team members. As priorities and circumstances change, work arrangements may be adjusted to ensure alignment with organizational goals and employee well-being.