Cetera Financial Group

Senior Security Engineer

Cetera Financial Group$120K — $145K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 8-10+ years in IT/cyber risk or security engineering with exposure to AI/ML systems
  • Knowledge of AI risk and control frameworks like NIST AI RMF
  • Experience with AI threat modeling methodologies, including MITRE ATT&CK
  • Understanding of AI attack techniques and their mitigations
  • Ability to translate technical findings into policy and audit documentation
  • Experience in regulated environments, preferably in financial services
  • Strong communication skills across technical and compliance teams

Responsibilities

  • Operationalize AI governance controls aligning with risk management frameworks
  • Lead evaluation and onboarding of third-party AI vendors
  • Maintain documentation of AI components and their risk inventories
  • Conduct ongoing AI vendor risk and compliance assessments
  • Design threat models for AI systems using MITRE ATLAS
  • Coordinate red-teaming and adversarial testing of AI/ML systems
  • Integrate AI vulnerabilities into existing vulnerability management processes
  • Identify and assess unsanctioned AI usage across the enterprise
  • Collaborate with cross-functional teams to embed AI risk management into processes
  • Support governance, audit activities, and maintain AI risk control documentation

Benefits

  • Inclusive health, dental, vision, and life insurance plans
  • Access to mental health benefits
  • 20+ days of paid time off, paid holidays, and 2 paid wellness days
  • 401(k) savings plan with a generous company contribution
  • Paid parental leave for birth, adoption, and fostering
  • Health Savings and Flexible Spending Account options
  • Employee Assistance Program (EAP) and identity theft protection
  • Paid caregiver leave for family members' care
  • Additional benefits for peace of mind such as pet insurance
Full Job Description
Job Description

We are seeking an AI Risk and Compliance Engineer to operationalize AI governance controls, manage AI-related third-party and vendor risk, and lead adversarial threat modeling for AI/ML systems using the MITRE ATLAS framework. This role serves as a key bridge across IT Risk, Cloud Security, Legal/Procurement, and AI/ML Engineering teams, translating AI risk management framework requirements into practical, auditable processes within a regulated financial services environment.

What will you do:
• Operationalize AI governance controls: Implement and maintain controls aligned to recognized AI risk management frameworks (spanning governance, mapping, measurement, and management of AI risk), including control documentation, risk-control matrices (RCM), and evidence collection to support audits and regulatory exams.
• Lead AI third-party risk management: Evaluate and onboard third-party AI/ML tools and vendors against security, privacy, and compliance criteria; document AI-specific vendor and contract requirements, SLAs, and fourth-party disclosures; support due diligence for AI vendors and data provenance reviews.
• Maintain AI/vendor risk inventories: Build and maintain documentation of third-party AI components (models, datasets, APIs, pre-trained/foundation models) covering provenance, functionality, and known limitations, and map internal controls to those components.
• Run ongoing AI risk assessments: Conduct recurring vendor risk and compliance assessments covering AI system performance, data quality, algorithmic bias, and security controls; monitor pre-trained/foundation model drift and SLA adherence; assess concentration and dependency risk across AI vendors.
• Perform AI threat modeling: Design and execute threat models for AI/ML systems using the MITRE ATLAS framework to identify adversarial tactics and techniques - including prompt injection, data/model poisoning, model evasion, model extraction, and supply-chain risk in ML pipelines - across the AI development and deployment lifecycle.
• Coordinate adversarial testing: Plan and coordinate red-teaming, adversarial testing, and penetration testing of AI/ML systems, and drive ongoing threat assessments informed by current threat intelligence and prior incidents.
• Integrate AI into vulnerability management: Ensure AI-specific vulnerabilities and security findings are captured, prioritized, and remediated through existing enterprise vulnerability management processes.
• Identify and assess unsanctioned AI usage: Support discovery and risk assessment of unsanctioned (shadow) AI tool usage across the enterprise and recommend remediation or approval pathways.
• Partner cross-functionally: Work closely with IT Risk, Cloud Security, Legal, Procurement, and Application/AI Engineering teams to embed AI risk and compliance requirements into intake, procurement, and development processes.
• Support governance and audit activities: Develop and maintain AI risk standards, control narratives, and runbooks; support internal and external audits and regulatory compliance activities (e.g., FINRA) by producing control evidence tied to the organization's AI risk management framework.

What you will have:
• 8-10+ years of experience in IT/cyber risk, GRC, security engineering, or a related discipline, with direct exposure to AI/ML systems
• Working knowledge of AI risk and control frameworks (e.g., NIST AI RMF or similar industry AI risk management frameworks) and OWASP Top 10 for LLMs
• Practical experience with, or strong working knowledge of, threat modeling methodologies for AI/ML systems, including familiarity with MITRE ATT&CK and MITRE ATLAS
• Experience building or operating third-party/vendor risk management processes - due diligence, contracting/SLAs, ongoing monitoring, and issue remediation
• Understanding of AI-specific attack techniques (prompt injection, data/model poisoning, model evasion, model extraction/inversion) and associated mitigations
• Ability to translate technical risk findings into control objectives, policy language, and audit-ready documentation
• Experience in regulated environments (financial services or FINRA preferred)
• Strong communication skills across technical, risk, legal, and compliance stakeholders

Preferred Qualifications:
• Experience with GRC platforms (e.g., Archer, ServiceNow GRC) for control and risk-register management
• Certifications such as CRISC, CISSP, CCSP, or IAPP AIGP (AI Governance Professional)
• Experience with AWS Bedrock or other cloud AI/ML platforms and cloud-native AI security
• Familiarity with model cards, data lineage/provenance tooling, and AI bill-of-materials (AI-BOM) concepts
• Prior participation in red team, purple team, or adversarial testing exercises involving ML systems
• Exposure to AI governance committees or model risk management (MRM) functions

What we give you in return:

Not many teams can say that they support people's dreams coming to life. We happen to do that every day. And as important as we know your career is, we recognize that there's a whole lot more to life. To ensure that our employees can make the most of their time outside of working hours, we offer a competitive salary and for full-time roles, a benefits package including:
  • Inclusive health, dental, vision, and life insurance plans built to support diverse lifestyles, offer preventative care, and protect against hardship.
  • Easy access to mental health benefits to meet our team members and their families where they are.
  • 20+ days of paid time off (PTO), paid holidays, and 2 paid wellness days to give our employees the time they need to stay close with their loved ones, recharge, and give back to their communities.
  • 401(k) savings plan with a generous company contribution (up to 5%), and access to a financial professional to offer our employees the opportunity to plan-ahead for a strong financial future well beyond their working years.
  • Paid parental leave to support all team members with birth, adoption, and fostering.
  • Health Savings and Flexible Spending Account options to help you save money on healthcare, daycare, commuting, and more.
  • Employee Assistance Program (EAP), LifeLock, Pet Insurance and more.
  • Paid caregiver leave to provide time away from work when caring for an ill or recovering family member.
  • Additional benefits such as an Employee Assistance Program (EAP), identity theft protection (LifeLock), pet insurance, and other voluntary benefits to provide extra peace of mind

About Cetera Financial Group

Cetera Financial Group is a network of independent broker-dealer firms that provide financial advice to individuals and small businesses. The company was founded in 2010 and is headquartered in El Segundo, California. Cetera Financial Group offers a range of services, including investment advice, financial planning, and insurance products. The company has over 8,000 financial advisors and manages over $200 billion in assets.
Learn more about Cetera Financial Group
Size
8,000 employees
Industry
Founded
2010

Similar Jobs

More Jobs at Cetera Financial Group

More Information Technology Jobs

Find similar Senior Security Engineer jobs: