Jobs · Engineering · New York

Corporate Vice President -AI/ML Security Operations Engineer

New York Life · New York, NY · Yesterday
Engineering$148k/yrFull-time

About the role

The AI / ML Security Operations Engineer is a senior engineering role embedded within the Application Security organization, responsible for securing New York Life's machine learning and AI pipelines as they evolve from isolated experimentation into production, agentic, and automated decisioning systems. This role sits at the intersection of ML engineering, platform engineering, and security, and is accountable for establishing the controls, guardrails, and reference patterns that scale as AI adoption accelerates across the enterprise.

Responsibilities

  • Build guardrails for agentic and tool-invoking AI use cases
  • Protect ML supply chain integrity
  • Integrate ML security controls into existing AppSec CI/CD and SSDLC processes
  • Contribute security requirements to ML platform and identity decisions owned by partner teams
  • Partner directly with data scientists, ML engineers, and platform owners to operationalize secure-by-default patterns

Requirements

  • Bachelor's degree in Computer Science, Engineering, or equivalent practical experience, with 5+ years in application security, cloud security, or security engineering
  • Hands-on production experience securing at least one major ML platform. Vertex AI strongly preferred, with SageMaker or Azure ML acceptable as transferable experience that will be cross-validated against GCP
  • Strong working knowledge of the end-to-end ML lifecycle and MLOps workflows: data ingestion, feature pipelines, training jobs, model registry, deployment patterns, and online/offline serving
  • Practical understanding of how ML environments should be separated across dev, training, staging, and production, and the ability to partner with platform teams to ensure those boundaries hold from a security standpoint
  • Working knowledge of non-human identities, service accounts, workload identity federation, and automated CI/CD or pipeline-driven workflows, with the ability to evaluate whether identity patterns proposed by partner teams meet security requirements
  • Fluency with AI/ML-specific threat scenarios including data poisoning, model theft, training data exfiltration, inference abuse, prompt injection, indirect prompt injection, unsafe tool invocation, and agentic misuse, and the ability to translate them into concrete controls
  • Hands-on experience integrating security controls into CI/CD pipelines and infrastructure-as-code environments (Terraform, GitHub Actions, GitLab CI, Cloud Build, or equivalent)
  • Working understanding of cloud IAM principles and least-privilege design, sufficient to review and provide security input on identity patterns owned by platform and cloud teams
  • Proficiency in Python for automation, security tooling, and detection logic. Candidates should be able to walk through code they have personally written, not just review it
  • Ability to operate as both a hands-on engineer and a pattern-setter, comfortable building the first instance of a control and then turning it into a reusable enterprise standard

Qualifications

  • Direct experience securing agentic AI systems, orchestration frameworks (LangChain, LangGraph, Vertex AI Agent Builder, ADK, CrewAI), or autonomous tool-invoking workflows in production
  • Working familiarity with AI security frameworks such as MITRE ATLAS, OWASP LLM Top 10, OWASP ML Top 10, NIST AI RMF, Google Secure AI Framework (SAIF), or Databricks AI Security Framework
  • Experience designing governance models for ML platforms in financial services, healthcare, or another regulated industry, including how controls map to model risk management (SR 11-7) and applicable audit requirements
  • Background working alongside data scientists and ML engineers on production model deployments, not just reviewing their work from a security distance
  • Exposure to model risk management, model validation, or model controls partnerships with second-line risk functions
  • Experience with policy-as-code and guardrail enforcement at scale (OPA / Rego, Cloud Custodian, Conftest, Sentinel, or equivalent)
  • Familiarity with detection engineering for ML workloads, including log sources from Vertex AI, model serving endpoints, agent execution traces, and how to write meaningful detections against them
  • Hands-on exposure to LLM gateways, content safety and guardrail products (Lakera, Protect AI, NeMo Guardrails, Llama Guard, Vertex AI Safety Filters), or self-built equivalents

Skills

  • Direct experience securing agentic AI systems, orchestration frameworks (LangChain, LangGraph, Vertex AI Agent Builder, ADK, CrewAI), or autonomous tool-invoking workflows in production
  • Working familiarity with AI security frameworks such as MITRE ATLAS, OWASP LLM Top 10, OWASP ML Top 10, NIST AI RMF, Google Secure AI Framework (SAIF), or Databricks AI Security Framework
  • Experience designing governance models for ML platforms in financial services, healthcare, or another regulated industry, including how controls map to model risk management (SR 11-7) and applicable audit requirements
  • Background working alongside data scientists and ML engineers on production model deployments, not just reviewing their work from a security distance
  • Exposure to model risk management, model validation, or model controls partnerships with second-line risk functions
  • Experience with policy-as-code and guardrail enforcement at scale (OPA / Rego, Cloud Custodian, Conftest, Sentinel, or equivalent)
  • Familiarity with detection engineering for ML workloads, including log sources from Vertex AI, model serving endpoints, agent execution traces, and how to write meaningful detections against them
  • Hands-on exposure to LLM gateways, content safety and guardrail products (Lakera, Protect AI, NeMo Guardrails, Llama Guard, Vertex AI Safety Filters), or self-built equivalents

Benefits

  • Discretionary bonus eligible
  • Annual discretionary bonus
  • Participation in an incentive program

Pay

Salary Range: $147,500-$211,000

Overtime eligible: Exempt

Schedule

Hybrid - 3 days per week

Location

Hybrid - 3 days per week

Similar jobs

VP of Corporate Security

Target HospitalityThe Woodlands, TX· 1 wk ago
Information Technologyapply on recruiting2.ultipro.com