Senior Associate AI Security Engineer
About the role
The Senior Associate AI Security Engineer is part of Truist’s AI Security Engineering function and is responsible for designing, engineering, deploying, and operating security controls for AI, ML, and Generative AI systems across cloud platforms. This role focuses on the security engineering foundations required for AI-enabled applications, agents, prompt-driven workflows, and tool-integrated automations operating in a regulated enterprise environment.
Responsibilities
- Design, implement, test, and operate security controls for AI and agent systems, including model-level, data-level, and platform-level protections.
- Implement AI guardrails and safety controls (e.g., prompt injection defenses, content safety filters, policy enforcement, model access controls).
- Support secure AI platform onboarding for internal teams, ensuring alignment with Truist AI Security Standards and Review Processes.
- Perform technical security assessments of AI systems and cloud-hosted AI services.
- Design and implement Infrastructure as Code (IaC) using Terraform and CloudFormation to deploy AI security controls consistently.
- Build and maintain CI/CD pipelines (GitLab) for security tooling, guardrails, and configuration-as-code.
- Automate operational workflows using Python and scripting to reduce manual security operations.
- Secure cloud environments supporting AI workloads across AWS and Azure, including containerized and orchestrated workloads supporting AI pipelines (ECS, EKS, Kubernetes).
- Partner with AI platform teams, application engineers, cloud security, and governance stakeholders to embed security into AI delivery.
- Contribute to the evolution of enterprise AI security standards, patterns, and reference architectures.
- Support incident response, threat modeling, and remediation activities related to AI systems.
Requirements
- Bachelor’s degree or equivalent education, training, and work-related experience.
- Minimum of 3 years of experience in security engineering or related cybersecurity roles.
- Developing knowledge in cybersecurity principles, theories, and concepts.
- Experience in software development lifecycle security practices.
- Proficiency in implementing and managing information security technologies.
- Experience with Azure and/or AWS, Infrastructure as Code (IaC) using Terraform and CloudFormation, building and managing CI/CD pipelines (GitLab), and implementing or operating cloud security tooling (e.g., Microsoft Purview, Sentinel, Wiz or equivalent).
- Familiarity with AI-specific security controls, such as: Prompt injection mitigation, content safety / moderation controls, model access and usage restrictions, secure data handling for AI pipelines, exposure to Azure and Azure-hosted AI services, and experience working in regulated environments with strong risk and governance requirements.
Qualifications
- Hands-on experience implementing technical controls for enterprise software, APIs, cloud-native services, or automation workflows.
- Working knowledge of AI/LLM security concepts such as prompt injection, unsafe output handling, tool-use abuse, sensitive data exposure, and control boundary enforcement.
- Experience with logging, alerting, monitoring, or detection content for identifying suspicious or policy-violating behavior in applications or workflows.
- Understanding of access control, identity boundaries, secrets handling, secure integration design, and environment-based deployment controls.
- Ability to work with engineering teams to translate security concerns into implementable guardrails, validations, and release controls.
- Strong written documentation and communication skills, especially for controls, findings, remediation evidence, and technical guidance.
- Experience operating within enterprise governance, security, and release-management practices where evidence-based deployment readiness matters.
Skills
- Experience with AI or agentic security controls, prompt and output protection strategies, or security validation of LLM-enabled features.
- General understanding of AI/LLM security concepts such as prompt injection, unsafe output handling, tool-use abuse, sensitive data exposure, and control boundary enforcement.
- Experience with logging, alerting, monitoring, or detection content for identifying suspicious or policy-violating behavior in applications or workflows.
- Understanding of access control, identity boundaries, secrets handling, secure integration design, and environment-based deployment controls.
- Ability to work with engineering teams to translate security concerns into implementable guardrails, validations, and release controls.
- Strong written documentation and communication skills, especially for controls, findings, remediation evidence, and technical guidance.
- Experience operating within enterprise governance, security, and release-management practices where evidence-based deployment readiness matters.
Benefits
All regular teammates (not temporary or contingent workers) working 20 hours or more per week are eligible for benefits, though eligibility for specific benefits may be determined by the division of Truist offering the position. Truist offers medical, dental, vision, life insurance, disability, accidental death and dismemberment, tax-preferred savings accounts, and a 401k plan to teammates. Teammates also receive no less than 10 days of vacation (prorated based on date of hire and by full-time or part-time status) during their first year of employment, along with 10 sick days (also prorated), and paid holidays. For more details on Truist’s generous benefit plans, please visit our Benefits site. Depending on the position and division, this job may also be eligible for Truist’s defined benefit pension plan, restricted stock units, and/or a deferred compensation plan. As you advance through the hiring process, you will also learn more about the specific benefits available for any non-temporary position for which you apply, based on full-time or part-time status, position, and division of work. Truist is an Equal Opportunity Employer that does not discriminate on the basis of race, gender, color, religion, citizenship or national origin, age, sexual orientation, gender identity, disability, veteran status, or other classification protected by law. Truist is a Drug Free Workplace. EEO is the Law E-Verify IER Right to Work