Truist Financial

Lead AI Security Engineer

Truist Financial$120K — $150K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree or equivalent experience in cybersecurity or related fields.
  • 10+ years in security engineering or related cybersecurity roles.
  • Deep knowledge of cybersecurity principles and concepts.
  • Extensive experience with software development lifecycle security practices.
  • Expertise in threat modeling, security testing, and penetration testing.
  • Proven experience managing complex information security technologies.

Responsibilities

  • Lead design and implementation of security controls for AI applications and pipelines.
  • Perform threat modeling for AI-related prompts and data flows.
  • Implement guardrails to prevent prompt-injection and data exposure.
  • Build and maintain monitoring and alerting mechanisms for AI systems.
  • Embed security requirements in AI design reviews and CI/CD workflows.
  • Validate security compliance of AI solutions before and after deployment.
  • Support incident responses and investigations for suspicious AI behavior.

Benefits

  • Opportunities for continuous learning and professional development.
  • Collaborative work environment with cross-functional teams.
  • Impactful role influencing the secure deployment of AI technology.
  • Exposure to cutting-edge AI security challenges and practices.
Full Job Description
• The Lead AI Security Engineer is a senior hands-on security engineer responsible for designing, implementing, and advancing controls that protect AI-enabled applications, agentic workloads, model integrations, and AI delivery pipelines across the full software and AI lifecycle. • This role focuses on securing agent behavior, prompt and context flows, tool invocation, data access, model interaction, pipeline integrity, runtime execution, observability, and deployment readiness in a regulated enterprise environment. • The engineer leads implementation of AI-specific security patterns including prompt-injection defenses, guardrails, output filtering, secure tool-use boundaries, identity and permission controls, evidence capture, logging, monitoring, and detection content for AI-enabled systems. • The work spans architecture review, threat modeling, adversarial test readiness, control validation, automation, detection engineering, deployment gating, production monitoring, and incident response support for AI and agentic solutions. • Daily work includes partnering with product, engineering, platform, data, risk, and security teams to translate AI security requirements into implementable controls that enable safe, traceable, resilient, and governed deployment of enterprise AI capabilities. ESSENTIAL DUTIES AND RESPONSIBILITIES Following is a summary of the essential functions for this job. Other duties may be performed, both major and minor, which are not mentioned below. Specific activities may change from time to time. • Lead the design and implementation of security controls for AI-enabled applications, agents, model integrations, orchestration layers, and AI delivery pipelines. • Perform AI and agentic threat modeling across prompts, context windows, retrieval flows, tools, APIs, permissions, memory, model access, data movement, and runtime execution paths. • Implement and validate guardrails for prompt-injection resistance, unsafe output handling, tool-use abuse, sensitive data exposure, privilege escalation, model misuse, and policy-violating behavior. • Build and maintain monitoring, alerting, and detection logic for AI systems, including anomalous prompts, abnormal agent actions, suspicious tool invocation, unsafe model responses, and control degradation. • Embed security requirements into AI design reviews, acceptance criteria, validation plans, CI/CD or LLMOps workflows, model or prompt change controls, and release-readiness gates. • Validate that AI solutions meet required security, governance, traceability, and evidence standards before release and continue to meet them after deployment. • Support AI-related incident investigation, root-cause analysis, remediation planning, and operational response for suspicious behavior, control failures, data exposure, or unsafe system outcomes. • Maintain control documentation, implementation guidance, runbooks, validation evidence, engineering patterns, and operating procedures for AI security engineering activities. • Continuously improve AI security automation, validation workflows, detection content, guardrail logic, and deployment controls as models, agents, workflows, and attack techniques evolve. Required Qualifications: The requirements listed below are representative of the knowledge, skill and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. • Bachelor’s degree or equivalent education, training, and work-related experience. • Minimum of 10 years of experience in security engineering or related cybersecurity roles. • Deep specialized knowledge in cybersecurity principles, theories, and concepts. • Extensive experience in software development lifecycle security practices. • Expertise in threat modeling, security testing, and penetration testing. • Proven experience implementing and managing complex information security technologies. Additional Requirements: • Minimum of 10 years of experience in security engineering, application security, product security, cloud security, cybersecurity operations, or related technical cybersecurity roles. • Demonstrated experience leading complex security engineering efforts across modern software, API, cloud-native, automation, or platform environments. • Strong understanding of AI, LLM, or agentic security risks, including prompt injection, insecure tool use, data exposure, model misuse, pipeline compromise, and unsafe output handling. • Experience with threat modeling, security testing, control validation, detection engineering, logging, monitoring, or incident response for production systems. • Ability to translate security requirements into implementable engineering controls, validation criteria, deployment gates, documentation, and operational runbooks. • 3+ years of experience in a lead security engineering, application security, AI security, cybersecurity operations, or closely related technical discipline. • Hands-on experience implementing controls for enterprise software, APIs, cloud-native services, workflow automation, model integrations, or agentic applications. • Working knowledge of LLM and agentic security concepts such as prompt injection, indirect prompt injection, insecure tool use, excessive agency, sensitive data exposure, model misuse, and control boundary enforcement. • Experience securing CI/CD, DevSecOps, MLOps, LLMOps, model, prompt, or configuration-change pipelines through validation, approvals, evidence capture, and release controls. • Experience with telemetry, logging, alerting, monitoring, or detection content for identifying suspicious, anomalous, or policy-violating behavior in applications or AI workflows. • Understanding of identity, access control, secrets handling, least privilege, secure integration design, API protections, sandboxing, and environment-based deployment controls. • Ability to partner with engineering teams to convert AI security risks into practical guardrails, tests, detections, monitoring requirements, and deployment-readiness controls. • Strong written documentation and communication skills, especially for control designs, validation results, remediation evidence, technical guidance, and audit-ready operating procedures. Preferred Qualifications: • Experience securing AI agents, autonomous workflows, tool-calling systems, retrieval-augmented generation patterns, or LLM-enabled enterprise applications. • Experience with Microsoft, Azure, Copilot, Copilot Studio, Azure AI, or other enterprise AI and automation platforms. • Familiarity with AI security guidance and frameworks such as OWASP LLM risks, OWASP agentic application risks, NIST AI RMF, MITRE ATLAS, or related industry practices. • Experience with adversarial testing, AI red teaming support, misuse-case validation, model or prompt evaluation, or safety monitoring for AI-enabled systems. • Experience in financial services, cybersecurity, regulated enterprise environments, or platforms with high audit, risk, privacy, and control expectations. • Working knowledge of secure tool-calling patterns, API protections, prompt and model change validation, runtime traceability, and observability for AI systems.

About Truist Financial

Truist Financial Careers

Join the dynamic team at Truist Financial, a leader in the financial services sector, and propel your career to new heights. At Truist Financial, we offer more than just job opportunities; we provide a platform for professional growth and innovation in an environment that values diversity and leadership.

Why Truist Financial?

At Truist Financial, we are committed to building a diverse and inclusive workplace where every team member is empowered to contribute their unique skills and perspectives. We believe that our strength lies in our diversity, and we are dedicated to fostering a culture that embraces the differences that make each of us unique.

Explore a World of Opportunities

Whether you're seeking your first internship or a seasoned professional looking to advance your career, Truist Financial offers a range of employment opportunities across various disciplines. Our team is growing, and we are constantly looking for talented individuals who are eager to make an impact.

Innovate and Lead

Join us and be part of a culture of innovation where your ideas can help shape the future of banking. At Truist Financial, you’ll work alongside industry leaders and have access to cutting-edge resources that foster continuous professional development and innovation.

Develop Your Career

Truist Financial is deeply invested in the career progression of our employees. We offer robust training programs, including leadership development and diversity training, to ensure you have the tools needed to succeed. Our commitment to your growth is reflected in our comprehensive benefits package, designed to support you both professionally and personally.

Networking and Professional Development

Enhance your professional network and connect with like-minded colleagues through our various networking events and community engagement initiatives. At Truist Financial, we believe in the power of connections and the impact they can have on your career.

Join Our Team

Ready to take the next step in your career? Explore the current job openings at Truist Financial. We are hiring across multiple departments, looking for passionate, curious, and innovative individuals to join our team. Check out our available positions and find the one that best matches your skills and interests.

Prepare for Your Interview

Make a great first impression. Visit our Careers page for tips on how to craft a compelling resume and succeed in your interview at Truist Financial. We are excited to see how you can contribute to our team and help us drive the future of banking.

Stay Connected

Don’t miss out on future opportunities or insights into our company culture and industry trends. Subscribe to our job alert emails and stay informed about new positions and career tips directly from our professionals. At Truist Financial, we’re not just offering jobs; we’re building careers. Join us and discover how you can make a difference and fuel your future.

SEARCH TRUIST FINANCIAL JOBS

READ CAREERS BLOG

Learn more about Truist Financial
Size
50,283 employees
Market Cap
$56.6 billion
Industry
5 Year Trend
+14.3%
NASDAQ

Similar Jobs

More Jobs at Truist Financial

More Information Technology Jobs

Find similar Lead AI Security Engineer jobs: