Senior Security Engineer and AI Security Architect - 991308 **Internal to Department Only**

Nova Southeastern University

$110K — $130K *
US-Anywhere
+ 2 other locationsRemote
Education, Government & Non-Profit
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in a relevant field
  • 6-8 years of IT experience focused on security engineering and architecture
  • Expertise in engineering enterprise security platforms and securing cloud environments
  • Certified Information Systems Security Professional (CISSP) or equivalent certification required within a year
  • Knowledge of AI and machine learning security risks and controls

Responsibilities

  • Oversee enterprise security architecture and architectural review for new systems
  • Engineer and maintain core security platforms, ensuring their health and lifecycle management
  • Lead detection engineering and continuous improvement of false positives in security analytics
  • Manage the cloud security posture and establish baseline standards
  • Define the university's zero trust architecture roadmap and conditional access designs
  • Establish AI security architecture and guardrails for AI technologies
  • Drive threat modeling for high-risk systems and lead remediation efforts
  • Evaluate emerging security technologies to advise on security investments

Benefits

  • Professional development opportunities
  • Access to cutting-edge security tools and technologies
  • Collaborative and innovative working environment
  • Contribution to impactful university initiatives
Full Job Description
Primary Purpose:

Provides senior technical leadership for the University's information security function, with ownership of security architecture, detection and monitoring engineering, cloud security, identity security design, and the security technology portfolio. Establishes architectural standards and security guardrails for AI-enabled technologies, including assessment of model, data, integration, and vendor risks.

Job Category: Exempt

Hiring Range:

Pay Basis: Annually

Subject to Grant Funding? No

Essential Job Functions:

1. Oversees enterprise security architecture, including security reference architectures, design standards, architectural review of new systems and integrations, and formal security design approval for major initiatives.

2. Engineers and maintains the university's core security platforms, including SIEM, endpoint detection and response, email security, network security controls, secure web gateway, and data loss prevention; owns platform health, tuning, integration, and lifecycle.

3. Leads detection engineering, including development and tuning of correlation rules, analytics, and use cases mapped to MITRE ATT&CK, and continuous reduction of false positives to improve analyst effectiveness.

4. Oversees cloud security posture across the university's cloud footprint, including cloud security posture management, cloud identity and entitlement management, infrastructure-as-code scanning, workload protection, and secure landing zone and baseline standards.

5. Defines and advances the university's zero trust architecture roadmap, including network segmentation, conditional access design, device trust, and least-privilege access patterns.

6. Establishes AI security architecture, including security guardrails and reference patterns for AI-enabled platforms, evaluation of model and data exposure risk, controls addressing prompt injection, sensitive data leakage, insecure output handling, and supply chain risk consistent with the OWASP Top 10 for Large Language Model Applications, and secure integration standards for AI services and agents.

7. Partners with the Manager of Security Governance, Risk, and Compliance to translate AI and cloud architecture decisions into documented, testable controls and audit evidence.

8. Leads threat modeling for high-risk applications, research computing environments, clinical systems, and third-party integrations, and drives remediation and design changes to completion.

9. Engineers and matures the vulnerability management and attack surface management toolchain, including scanning coverage, asset correlation, risk-based prioritization, and remediation reporting.

10. Establishes cryptographic standards and supports encryption, certificate, and key management practices across enterprise and cloud environments.

11. Embeds security into the software development lifecycle in partnership with Enterprise Applications and Digital Platforms, including secure coding standards, static and dependency analysis, secrets management, and pipeline security controls.

12. Serves as the senior technical escalation point for complex security incidents, providing advanced analysis, containment engineering, and forensic support, and leading technical root cause analysis.

13. Provides technical mentorship, design review, and skills development for Security Analysts and other technical staff.

14. Evaluates emerging security technologies, conducts proofs of concept, develops business justification, and advises the CISO on security tooling investment and roadmap.

15. Completes special projects as assigned.

16. Performs other duties as assigned or required.

Job Requirements:

Required Knowledge, Skills, & Abilities: Knowledge:
1. Comprehensive knowledge of security architecture principles, defense-in-depth design, and zero trust architecture models.
2. Comprehensive knowledge of SIEM and endpoint detection and response engineering, detection development, and the MITRE ATT&CK framework.
3. Comprehensive knowledge of cloud security across at least one major provider (Amazon Web Services, Microsoft Azure, or Google Cloud Platform), including identity, network, workload, and posture management controls.
4. Working knowledge of artificial intelligence and machine learning system architecture and the associated security risks, including model and data exposure, prompt injection, insecure output handling, and AI supply chain risk.
5. Working knowledge of identity and access management architecture, including federation, single sign-on, conditional access, and privileged access management.
6. Working knowledge of secure software development practices, DevSecOps tooling, container and Kubernetes security, and API security.
7. Working knowledge of cryptography, public key infrastructure, and certificate lifecycle management.
8. Working knowledge of incident response, digital forensics, and threat hunting methodologies.

Skills:
1. Complex Problem Solving - Proficient skills in identifying complex problems and reviewing related information to develop and evaluate options and implement solutions.
2. Systems Engineering - Advanced skills in designing, deploying, integrating, and operating enterprise security platforms at scale.
3. Automation and Scripting - Proficient skills in at least one scripting or automation language, such as Python or PowerShell, and in infrastructure-as-code tooling.
4. Technical Communication - Proficient skills in documenting architecture decisions and explaining technical risk to non-technical stakeholders and executive leadership.
5. Mentorship - Proficient skills in developing the technical capability of less experienced staff.
Abilities:
1. Ability to make and defend architectural decisions that balance security, usability, academic freedom, and cost.
2. Ability to operate as the senior technical authority in a small team without a peer technical reviewer.
3. Ability to lead technical work through matrixed teams and vendors without direct supervisory authority.
4. Ability to remain effective under pressure during active security incidents.
5. Ability to evaluate emerging technology rapidly and reach a defensible recommendation.

Physical Requirements and Working Environment:
1. Speech Recognition - Must be able to identify and understand the speech of another person.
2. Speech Clarity - Must be able to speak clearly so others can understand you.
3. Near Vision - Must be able to see details at close range (within a few feet of the observer).
4. Travel - Must be able to travel on a daily and/or overnight basis.
5. May be required to work nights or weekends.
6. May be exposed to short, intermittent, and/or prolonged periods of sitting and/or standing in performance of job duties.
7. May be required to accomplish job duties using various types of equipment/supplies, to include but not limited to pens, pencils, and computer keyboards.

Required Certifications/Licensures: Must possess one of the following certifications at the time of hire or obtain at least one (1) within twelve (12) months of hire and maintain it in good standing throughout employment:

Certified Information Systems Security Professional (CISSP) or equivalent senior security certification.

Required Education: Bachelor's degree

Major (if required:

Required Experience: 1. Minimum six (6) to eight (8) years' experience in information technology experience, including security engineering, security architecture, or equivalent technical security roles.

2. Experience with engineering enterprise security platforms and securing cloud environments.

Preferred Qualifications:

1. Experience designing security controls for artificial intelligence or machine learning platforms.
2. Experience in higher education, academic health, or research computing environments.
3. Experience in a decentralized environment with significant shadow IT and diverse regulatory requirements.
4. Experience with managed detection and response provider integration and oversight.
5. Experience securing research data environments subject to NIST SP 800-171 or Controlled Unclassified Information requirements.

Is this a safety sensitive position? No

Background Screening Required? Yes

Pre-Employment Conditions:

Similar Jobs

More Jobs at Nova Southeastern University

More Education, Government & Non-Profit Jobs

Find similar Senior Security Engineer and AI Security Architect - 991308 **Internal to Department Only** jobs: