Staff Engineer, AI Security

EQ Bank | Equitable Bank

• $110K — $130K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 7-9 years of experience in cyber security, software engineering, cloud engineering, or platform engineering, with 4 years specifically in a cyber security role.
  • Expert-level knowledge of AI and cloud security controls, serving as a trusted internal resource.
  • Strong understanding of AI technologies, generative AI, machine learning platforms, and AI-enabled business solutions.
  • Experience securing cloud platforms like Microsoft Azure, GCP, or OCI.
  • Familiarity with security risks specific to AI, such as prompt injection and model poisoning.
  • Deep knowledge of security practices, including application security, API security, and secure software development.
  • Proficient in developing automation and security tools using programming languages like Python or PowerShell.

Responsibilities

  • Design, implement, and operate security controls for AI platforms and cloud services.
  • Embed security requirements into AI solutions throughout the delivery lifecycle alongside engineering teams.
  • Automate AI security guardrails and policy enforcement across both established and emerging AI technologies.
  • Conduct security assessments and enablement for platforms like Microsoft 365 Copilot and OpenAI.
  • Implement data protection controls for AI training and inference in collaboration with Data Governance teams.
  • Maintain identity, access, and model access controls for AI integrations and APIs.
  • Develop security standards and guidance for the safe adoption of AI technologies.

Benefits

  • Competitive discretionary bonus
  • Market leading RRSP match program
  • Comprehensive medical, dental, vision, life, and disability benefits
  • Employee Share Purchase Plan
  • Maternity/Parental leave top-up
  • Generous vacation policy and personal days
  • Professional development opportunities and comprehensive career development program
Full Job Description
The Work

This role leads the design, implementation, and operation of security controls for Artificial Intelligence (AI), generative AI, machine learning, AI agents, copilots, automation platforms, agentic AI platforms, orchestration frameworks, model providers, and the cloud services that support them.

Reporting to the Senior Director, Cyber Security Engineering & Operations and working as a fully dedicated, embedded security partner to the AI Centre of Enablement and the Enterprise Technology, Data & AI organization, the incumbent provides senior technical leadership to ensure AI solutions are delivered securely and in line with enterprise security standards and regulatory expectations.

The incumbent develops reusable security patterns, guardrails, control implementations, automation, and detection capabilities that support enterprise AI adoption while protecting the bank from data leakage, model misuse, insecure integrations, excessive permissions, unsafe automation, and unapproved use of AI technologies. The role enables teams through practical, reusable guardrails and secure patterns rather than relying only on review and enforcement. This is a senior individual contributor role with no direct reports.

The Core Responsibilities!

  • Design, implement, and operate security controls for AI platforms, generative AI solutions, AI agents, machine learning environments, and supporting cloud services.


  • Partner with the AI Centre of Enablement, AI Engineering, Data Engineering, and Technology teams to embed security requirements into AI solutions across the delivery lifecycle.


  • Build and automate AI security guardrails and policy enforcement across approved and emerging AI technologies, including enterprise copilots, AI coding assistants, model platforms, orchestration frameworks, agentic AI platforms, and third-party AI services.


  • Support security assessment and enablement for platforms and frameworks such as Microsoft 365 Copilot, Copilot Studio, GitHub Copilot, Azure AI services, Enterprise Gemini, Cursor AI, OpenAI, Anthropic, LangChain, LangGraph, LangFuse, and future enterprise-approved AI technologies.


  • Implement data protection controls for AI training, grounding, and inference in partnership with Data Governance and Privacy teams.


  • Configure and maintain identity, access, and model access controls for AI platforms, APIs, agents, and integrations.


  • Develop and maintain security standards, implementation patterns, and technical guidance for the secure adoption of AI technologies.


  • Review solution designs and provide practical security guidance to address risks, control gaps, and regulatory requirements.


  • Work as a collaborative security partner across Cyber, Architecture, Data, Engineering, AI Engineering, and business teams to enable secure delivery with minimal unnecessary friction.


  • Perform and support adversarial testing of AI solutions, and work with engineering teams to prioritize and remediate security weaknesses.


  • Develop security monitoring requirements and detection capabilities for AI-related security events, misuse, and unapproved AI usage.


  • Assess security risk in the AI supply chain, including models, plug-ins, agents, and third-party AI services.


  • Support governance, compliance, audit, and risk management activities related to AI, including the AI control library and AI intake and lifecycle processes.


  • Create and maintain technical documentation, standards, procedures, and implementation guidance.


  • Mentor engineers, architects, and delivery teams on practical AI security patterns, risks, and control implementation.


Let's Talk About You!

  • A college diploma or university degree in computer science, engineering, information security, or a related technical field is required.


  • 7-9 years of experience in cyber security, software engineering, cloud engineering, or platform engineering, including a minimum of 4 years in a cyber security role.


  • Expert level knowledge of AI and cloud security controls, sufficient to act as the internal subject matter expert others rely on for direction.


  • Experience designing, implementing, and supporting security controls within cloud-native and enterprise technology environments.


  • Strong understanding of AI technologies, including generative AI, large language models (LLMs), AI agents, retrieval-augmented generation, machine learning platforms, model integrations, and AI-enabled business solutions.


  • Strong understanding of AI-specific security risks, including prompt injection and indirect prompt injection, sensitive information disclosure, data and model poisoning, insecure output handling, excessive agency, system prompt leakage, vector and embedding weaknesses, and AI supply chain risk.


  • Experience securing cloud platforms and services, preferably Microsoft Azure; experience with GCP or OCI is an asset.


  • Experience securing one or more enterprise AI platforms, copilots, AI coding assistants, model providers, orchestration frameworks, or agentic AI technologies. Experience with Microsoft AI services, Enterprise Gemini, Cursor AI, OpenAI, Anthropic, LangChain, LangGraph, LangFuse, or similar platforms is considered an asset.


  • Strong knowledge of application security, API security, identity and access management, secrets management, encryption, and secure software development practices.


  • Experience developing automation, integrations, or security tooling using modern programming and scripting languages such as Python or PowerShell.


  • Experience working with CI/CD pipelines, Infrastructure-as-Code, containers, and cloud-native technologies.


  • Strong understanding of security monitoring, logging, detection, and incident response concepts.


  • Working knowledge of AI and security frameworks, including NIST AI RMF, ISO/IEC 42001, OWASP Top 10 for LLM Applications, MITRE ATLAS, NIST CSF, and CIS Controls.


  • Ability to review technical designs and provide practical security guidance that balances risk management with business objectives.


  • Curiosity and a continuous learning mindset, with the ability to stay current as AI security threats, controls, platforms, and regulatory expectations evolve.


  • Pragmatic judgment with the ability to balance security risk, regulatory expectations, delivery timelines, and business value.


  • Strong analytical and problem-solving skills with the ability to assess complex technical environments and identify effective solutions.


  • Demonstrated ability to influence technical decisions without direct authority and help teams adopt secure patterns rather than simply identifying gaps.


  • Relevant industry certifications such as CISSP, CCSP, GIAC, Microsoft Azure Security Engineer, Google Professional Cloud Security Engineer, or equivalent are considered an asset.


Communication Skills:

  • Moderately complex: provides technical information and guidance, conducts working sessions and design reviews, and influences groups of technical and business stakeholders across the bank.


  • Produces clear documentation, standards, patterns, and implementation guides intended for reuse by other teams.


  • Translates technical AI risk into business language for management, governance forums, and delivery partners.


  • Collaborates as an embedded partner across Cyber, Architecture, Data, Engineering, AI Engineering, and business teams, using practical guidance and influence to enable secure outcomes.


  • Coaches and mentors technical and non-technical stakeholders to improve enterprise understanding of AI security risks and controls.


  • Engages with vendors and external partners to exchange technical information and validate security capabilities.


What we offer [For full-time permanent roles]

Competitive discretionary bonus

Market leading RRSP match program

🩺 Medical, dental, vision, life, and disability benefits

📝 Employee Share Purchase Plan

Maternity/Parental top-up while you care for your little one

Generous vacation policy and personal days

Virtual events to connect with your fellow colleagues

Professional development and comprehensive Career Development program

A fulfilling opportunity to join one of the top FinTechs and help create a new kind of banking experience

The incumbent will be working hybrid and in office time will be spent working from EQ Bank's additional office space located at 2200-25 Ontario Street, Toronto, ON.

Similar Jobs

More Jobs at EQ Bank | Equitable Bank

More Information Technology Jobs

Find similar Staff Engineer, AI Security jobs: