Jobs · Information Technology · North Carolina

Lead AI Security Engineer

Truist · Charlotte, NC · 1 mo ago
Information TechnologyFull-time

Essential Duties And Responsibilities

  • Lead the design and implementation of security controls for AI-enabled applications, agents, model integrations, orchestration layers, and AI delivery pipelines.
  • Perform AI and agentic threat modeling across prompts, context windows, retrieval flows, tools, APIs, permissions, memory, model access, data movement, and runtime execution paths.
  • Implement and validate guardrails for prompt-injection resistance, unsafe output handling, tool-use abuse, sensitive data exposure, privilege escalation, model misuse, and policy-violating behavior.
  • Build and maintain monitoring, alerting, and detection logic for AI systems, including anomalous prompts, abnormal agent actions, suspicious tool invocation, unsafe model responses, and control degradation.
  • Embed security requirements into AI design reviews, acceptance criteria, validation plans, CI/CD or LLMOps workflows, model or prompt change controls, and release-readiness gates.
  • Validate that AI solutions meet required security, governance, traceability, and evidence standards before release and continue to meet them after deployment.
  • Support AI-related incident investigation, root-cause analysis, remediation planning, and operational response for suspicious behavior, control failures, data exposure, or unsafe system outcomes.
  • Maintain control documentation, implementation guidance, runbooks, validation evidence, engineering patterns, and operating procedures for AI security engineering activities.
  • Continuously improve AI security automation, validation workflows, detection content, guardrail logic, and deployment controls as models, agents, workflows, and attack techniques evolve.

Required Qualifications

  • Bachelor’s degree or equivalent education, training, and work-related experience.
  • Minimum of 10 years of experience in security engineering or related cybersecurity roles.
  • Deep specialized knowledge in cybersecurity principles, theories, and concepts.
  • Extensive experience in software development lifecycle security practices.
  • Expertise in threat modeling, security testing, and penetration testing.
  • Proven experience implementing and managing complex information security technologies.

Additional Requirements

  • Minimum of 10 years of experience in security engineering, application security, product security, cloud security, cybersecurity operations, or related technical cybersecurity roles.
  • Demonstrated experience leading complex security engineering efforts across modern software, API, cloud-native, automation, or platform environments.
  • Strong understanding of AI, LLM, or agentic security risks, including prompt injection, insecure tool use, data exposure, model misuse, pipeline compromise, and unsafe output handling.
  • Experience with threat modeling, security testing, control validation, detection engineering, logging, monitoring, or incident response for production systems.
  • Ability to translate security requirements into implementable engineering controls, validation criteria, deployment gates, documentation, and operational runbooks.
  • Hands-on experience implementing controls for enterprise software, APIs, cloud-native services, workflow automation, model integrations, or agentic applications.
  • Experience securing CI/CD, DevSecOps, MLOps, LLMOps, model, prompt, or configuration-change pipelines through validation, approvals, evidence capture, and release controls.
  • Experience with telemetry, logging, alerting, monitoring, or detection content for identifying suspicious, anomalous, or policy-violating behavior in applications or AI workflows.
  • Understanding of identity, access control, secrets handling, least privilege, secure integration design, API protections, sandboxing, and environment-based deployment controls.
  • Ability to partner with engineering teams to convert AI security risks into practical guardrails, tests, detections, monitoring requirements, and deployment-readiness controls.
  • Strong written documentation and communication skills, especially for control designs, validation results, remediation evidence, technical guidance, and audit-ready operating procedures.

Preferred Qualifications

  • Experience securing AI agents, autonomous workflows, tool-calling systems, retrieval-augmented generation patterns, or LLM-enabled enterprise applications.
  • Familiarity with AI security guidance and frameworks such as OWASP LLM risks, OWASP agentic application risks, NIST AI RMF, MITRE ATLAS, or related industry practices.
  • Experience with adversarial testing, AI red teaming support, misuse-case validation, model or prompt evaluation, or safety monitoring for AI-enabled systems.
  • Experience in financial services, cybersecurity, regulated enterprise environments, or platforms with high audit, risk, privacy, and control expectations.
  • Working knowledge of secure tool-calling patterns, API protections, prompt and model change validation, runtime traceability, and observability for AI systems.

Similar jobs