Lead AI Security Engineer
Truist · Charlotte, NC · 1 mo ago
Information TechnologyFull-time
Essential Duties And Responsibilities
- Lead the design and implementation of security controls for AI-enabled applications, agents, model integrations, orchestration layers, and AI delivery pipelines.
- Perform AI and agentic threat modeling across prompts, context windows, retrieval flows, tools, APIs, permissions, memory, model access, data movement, and runtime execution paths.
- Implement and validate guardrails for prompt-injection resistance, unsafe output handling, tool-use abuse, sensitive data exposure, privilege escalation, model misuse, and policy-violating behavior.
- Build and maintain monitoring, alerting, and detection logic for AI systems, including anomalous prompts, abnormal agent actions, suspicious tool invocation, unsafe model responses, and control degradation.
- Embed security requirements into AI design reviews, acceptance criteria, validation plans, CI/CD or LLMOps workflows, model or prompt change controls, and release-readiness gates.
- Validate that AI solutions meet required security, governance, traceability, and evidence standards before release and continue to meet them after deployment.
- Support AI-related incident investigation, root-cause analysis, remediation planning, and operational response for suspicious behavior, control failures, data exposure, or unsafe system outcomes.
- Maintain control documentation, implementation guidance, runbooks, validation evidence, engineering patterns, and operating procedures for AI security engineering activities.
- Continuously improve AI security automation, validation workflows, detection content, guardrail logic, and deployment controls as models, agents, workflows, and attack techniques evolve.
Required Qualifications
- Bachelor’s degree or equivalent education, training, and work-related experience.
- Minimum of 10 years of experience in security engineering or related cybersecurity roles.
- Deep specialized knowledge in cybersecurity principles, theories, and concepts.
- Extensive experience in software development lifecycle security practices.
- Expertise in threat modeling, security testing, and penetration testing.
- Proven experience implementing and managing complex information security technologies.
Additional Requirements
- Minimum of 10 years of experience in security engineering, application security, product security, cloud security, cybersecurity operations, or related technical cybersecurity roles.
- Demonstrated experience leading complex security engineering efforts across modern software, API, cloud-native, automation, or platform environments.
- Strong understanding of AI, LLM, or agentic security risks, including prompt injection, insecure tool use, data exposure, model misuse, pipeline compromise, and unsafe output handling.
- Experience with threat modeling, security testing, control validation, detection engineering, logging, monitoring, or incident response for production systems.
- Ability to translate security requirements into implementable engineering controls, validation criteria, deployment gates, documentation, and operational runbooks.
- Hands-on experience implementing controls for enterprise software, APIs, cloud-native services, workflow automation, model integrations, or agentic applications.
- Experience securing CI/CD, DevSecOps, MLOps, LLMOps, model, prompt, or configuration-change pipelines through validation, approvals, evidence capture, and release controls.
- Experience with telemetry, logging, alerting, monitoring, or detection content for identifying suspicious, anomalous, or policy-violating behavior in applications or AI workflows.
- Understanding of identity, access control, secrets handling, least privilege, secure integration design, API protections, sandboxing, and environment-based deployment controls.
- Ability to partner with engineering teams to convert AI security risks into practical guardrails, tests, detections, monitoring requirements, and deployment-readiness controls.
- Strong written documentation and communication skills, especially for control designs, validation results, remediation evidence, technical guidance, and audit-ready operating procedures.
Preferred Qualifications
- Experience securing AI agents, autonomous workflows, tool-calling systems, retrieval-augmented generation patterns, or LLM-enabled enterprise applications.
- Familiarity with AI security guidance and frameworks such as OWASP LLM risks, OWASP agentic application risks, NIST AI RMF, MITRE ATLAS, or related industry practices.
- Experience with adversarial testing, AI red teaming support, misuse-case validation, model or prompt evaluation, or safety monitoring for AI-enabled systems.
- Experience in financial services, cybersecurity, regulated enterprise environments, or platforms with high audit, risk, privacy, and control expectations.
- Working knowledge of secure tool-calling patterns, API protections, prompt and model change validation, runtime traceability, and observability for AI systems.