Sr. AI Security Engineer
McCarthy Holdings, Inc. · St Louis, MO · Yesterday
Information TechnologyFull-time
Responsibilities
- Develop and maintain enterprise AI security standards, control requirements, and risk-based review processes.
- Assess AI applications, models, agents, APIs, integrations, vendors, and data flows before and after deployment.
- Define security requirements for AI systems across design, development, testing, deployment, operation, and retirement.
- Evaluate identity, access, identity governance, data protection, privacy, logging, monitoring, retention, and human-oversight controls.
- Test AI systems and agent workflows for prompt injection, indirect injection, jailbreaks, data leakage, excessive agency, unsafe tool use, insecure integrations, and configuration drift.
- Conduct threat modeling, architecture reviews, security assessments, and control validation for AI-enabled solutions.
- Establish processes for AI security findings, incident response, exception management, remediation, and executive reporting.
- Review AI vendors, models, third parties, subprocessors, data handling practices, and material platform or configuration changes.
- Configure, tune, validate, operate, and extend existing AI-security, AI-governance, application-security, data-security, and monitoring tools.
- Create practical security patterns, reference architectures, playbooks, standards, and guidance for engineering and product teams.
- Monitor emerging AI threats, vulnerabilities, standards, regulations, and industry practices and translate them into actionable improvements.
- Partner with development and platform teams to integrate security controls into AI development and deployment workflows.
- Communicate technical risks, business impact, and recommended actions to both technical and non-technical stakeholders.
- Promote responsible AI adoption through measurable controls, clear accountability, and continuous improvement.
Qualifications
- Bachelor’s degree in cybersecurity, computer science, information systems, engineering, or a related field, or equivalent professional experience.
- Minimum five years of proven experience in an established security architecture, security engineering, architecture, or engineering role.
- Working experience handling AI security in a production environment, including the assessment, governance, monitoring, or protection of AI applications, models, agents, or integrations.
- Strong understanding of cybersecurity principles, including identity governance, least privilege, data protection, risk assessment, incident response, security architecture, and security governance.
- Familiarity with OWASP LLM and AI risks, including prompt injection, indirect injection, jailbreaks, sensitive information disclosure, excessive agency, insecure output handling, and agent or tool-use security.
- Practical understanding of generative AI architectures, large language models, retrieval-augmented generation, AI agents, APIs, and model or application lifecycle risks.
- Able to explain how risks such as indirect prompt injection or excessive agency would surface in a real agent workflow and how those risks could be detected, validated, and mitigated.
- Experience evaluating security controls, technology vendors, data handling practices, privacy considerations, and third-party risk.
- Able to develop clear standards and communicate complex technical risks to engineers, product teams, business leaders, and executives.
- Strong analytical, written, verbal, collaboration, and problem-solving skills.
- Sound judgment, personal integrity, curiosity, and a demonstrated commitment to protecting confidential information.
Preferred Qualifications
- Experience with AI-security, application-security, cloud-security, data-security, DevSecOps, or security-monitoring tools.
- Experience performing AI red teaming, adversarial testing, penetration testing, threat modeling, or control validation.
- Familiarity with the NIST AI Risk Management Framework or comparable AI-governance frameworks.
- Experience integrating security controls into software development, cloud engineering, or platform operations.
- Familiarity with data classification, DLP, audit logging, security information and event management, and privacy-by-design practices.
- Relevant certifications such as CISSP, Security+, or a portfolio demonstrating comparable practical experience.