AI AppSec Engineer Lead
About Capital Group
At Capital Group, we value your talents, traditions, and uniqueness—and we’re committed to fostering a strong sense of belonging in a respectful workplace. We intentionally seek diverse perspectives, experiences, and backgrounds, investing in a culture designed to celebrate differences. At Capital, we live our core values every day: Integrity, Client Focus, Diverse Perspectives, Long-Term Thinking, and Community.
About the role
As a Lead AI AppSec Engineer, you will work with application teams to ensure the security of custom and procured AI solutions. You will help enable Capital Group’s AI strategy by building and/or procuring solutions to protect a diverse set of enterprise AI platforms being built and deployed at Capital Group. You’ll collaborate with platform engineering, security engineering, and risk teams to ensure their solutions support scalable, secure adoption of AI. Additionally, you’ll be expected to provide mentoring, advising diverse teams across the organization, and promoting AI Security principles across Capital Group.
Responsibilities
- Secure AI Development Lifecycle: You will procure and/or build technical solutions to embed automated security checks into the AI SDLC and ML-Ops.
- AI Threat Modeling: You will threat model complex Agentic and AI systems and design security requirements collaboratively with developers, architects and business stakeholders.
- Code analysis: You will review code for security vulnerabilities in the context of AI-driven systems.
- Contribute to Standards and Policies: You will provide thought leadership for Information Security policies and standards for AI in collaboration with technology risk.
- AI/Agent SME: You will provide AI/Agent subject matter expertise for AI Incidents and Security Reviews, and help develop incident response playbooks for AI-related security incidents.
Qualifications
- 8+ years of experience in information security, application security, platform security, or penetration testing, DevSecOps, network security and other security disciplines.
- Strong knowledge of security of safety risks of Large Language Models and AI Agents (OWASP for LLM Top 10, etcetera).
- 5+ years of experience automating security checks, including SAST, SCA, and DAST, directly into CI/CD pipelines.
- Extensive experience with STRIDE/other threat modeling frameworks, agile workflows, including Scrum and Kanban.
- Experienced in at least one programming languages (Python, Java, .NET).
- Ability to effectively partner and collaborate with stakeholder teams.
- Effective communication skills and the ability to outline security risks to leadership.
Preferred Qualifications
- Knowledge and experience with technologies including Kubernetes, Containers, CI/CD, and Cloud Service Providers.
- Familiarity with function and purpose of key AI platform components such as AI gateways (Kong, Databricks Mosaic AI Gateway, custom API orchestration), Model Orchestration (Examples LangChain, LlamaIndex, etc.).
- Familiarity with key AI regulatory frameworks such as NIST AI RMF, MITRE ATLAS, GDPR, EU AI Act, etc.
- Information Security certifications (CISSP, SANS GIAC, CISA, etc.).
Compensation & Benefits
- Base Salary Ranges:
- Charlotte: $194,706-$311,530
- Southern California: $226,893-$363,029
- New York: $240,519-$384,830
- Eligibility for an individual annual performance bonus, plus Capital’s annual profitability bonus.
- Retirement plan where Capital contributes 15% of your eligible earnings.
- Generous time-away and health benefits from day one, with the opportunity for flexible work options.
- 2-for-1 matching gifts for your charitable contributions and the opportunity to secure annual grants for the organizations you love.
- On-demand professional development resources that allow you to hone existing skills and learn new ones.
Schedule & Work Environment
Your performance will be reviewed annually, and your compensation will be designed to motivate and reward the value that you provide. Flexible work options are available. Temporary positions in the United States are excluded from the above mentioned compensation and benefit plans.