AI Cybersecurity Lead
Rockefeller Capital Management New York, New York, United States
Financial Services · 1,001-5,000 employees
About the role
The AI Cybersecurity Lead will define and execute the firm's AI security strategy, serving as the senior technical authority for secure AI and agentic system operations. This role involves designing secure architectures, establishing governance controls, and leading threat modeling to protect against AI-specific risks.
What they look for
Requirements
Candidates must have over 10 years of cybersecurity experience, including at least 5 years in security engineering or architecture. Proficiency in securing production AI systems, cloud environments, and Python-based security tooling is required.
Benefits
Full description
About Rockefeller Capital Management
Rockefeller Capital Management was established in 2018 as a leading independent financial advisory services firm. Originally founded in 1882 as the family office of John D. Rockefeller, the Firm has evolved to offer strategic advice to ultra- and high-net-worth individuals and families, institutions, and corporations from offices in 35 markets throughout the United States, as well as an office in London. The Firm oversees $228 billion in client assets as of July 31, 2026.
Position
The Technology and Operations team is seeking a pragmatic, technically deep, execution-focused cybersecurity leader to secure the firm's adoption of artificial intelligence, generative AI, and agentic technologies. As the AI Cybersecurity Lead, you will serve as the firm's senior technical authority for AI security, partnering across Technology, Risk, Compliance, Legal, and the business to enable rapid AI adoption while managing risk. This is a hands-on leadership role responsible for designing secure AI architectures, establishing governance and security controls, and protecting data, models, credentials, and business processes from threats such as prompt injection, model abuse, data leakage, and unauthorized agent actions. Success requires translating emerging AI risks into practical, enforceable controls while shaping the firm's long-term AI security strategy.
Responsibilities
- Own the firm's AI security strategy and serve as the senior technical authority on secure design and operation of AI, generative AI, and agentic systems.
- Design secure AI architectures and reusable security patterns for AI applications, retrieval systems, model integrations, agent frameworks, and MCP services.
- Establish and enforce security controls across agent execution, permissions, data access, secrets management, credential protection, and runtime containment.
- Lead AI threat modeling, adversarial testing, and security assessments covering prompt injection, jailbreaks, excessive permissions, and autonomous attack scenarios.
- Build AI detection and response capabilities with Security Operations, including monitoring, logging, investigations, and incident response for AI-related threats.
- Embed security throughout the AI development lifecycle, including governance, dependency management, secure orchestration, and deployment controls.
- Assess third-party AI platforms and services for security, privacy, data protection, and operational risk.
- Monitor emerging AI threats and regulatory developments, advise senior leadership, and document security standards, architecture, and risk assessments.
Qualifications
- 10+ years of cybersecurity experience including 5+ years in security engineering or security architecture.
- Bachelor's degree in a technical discipline or equivalent engineering experience.
- Hands-on experience securing production AI systems, including LLM applications, retrieval-augmented generation (RAG) solutions, agent frameworks, and model hosting platforms.
- Deep cloud security expertise, preferably within Azure environments (Entra ID, Azure OpenAI/AI Foundry, Key Vault, Defender for Cloud), with comparable AWS or GCP experience considered.
- Strong knowledge of identity, access, secrets, and credential management, including OAuth 2.0, OpenID Connect, managed identities, token exchange, vaulting, and workload authentication.
- Experience performing AI threat modeling, adversarial testing, red teaming, or penetration testing, with expertise in threats such as prompt injection, model abuse, excessive permissions, data exfiltration, and supply chain compromise.
- Strong detection engineering and secure SDLC experience, including security monitoring, logging requirements, vulnerability management, secure design reviews, and CI/CD pipeline security.
- Proficiency in Python and experience building security tooling, automation, evaluation frameworks, or detection capabilities.
- Working knowledge of security and AI governance frameworks including NIST CSF, NIST AI RMF, MITRE ATT&CK/ATLAS, OWASP Top 10 for LLM Applications, CIS, and CSA frameworks.
- Experience with modern AI ecosystems, including agent frameworks, orchestration platforms, MCP, LangGraph, Semantic Kernel, Microsoft Copilot Studio, or similar technologies, along with securing containerized, Kubernetes, and sandboxed workloads, preferred.
- Experience applying data protection controls to AI systems and communicating complex security risks to both technical and executive audiences; experience with AI incident response, model supply chain security, or AI security research is a plus, preferred.
Skills
- Judgment under ambiguity; ability to design enforceable controls for agentic systems where settled industry practice does not yet exist and distinguishes a real control from a policy statement.
- Builds rather than documents; ability to deliver working prototypes, reference patterns, and automation using Python, PowerShell, Terraform or Bicep, and GitHub Actions that engineering can adopt directly.
- Vendor skepticism; ability to evaluate AI security tooling against a concrete threat model and clearly identifies coverage gaps.
- Clear technical communication; ability to produce architecture documentation, threat models, and control narratives that withstand audit and regulatory review.
- Constructive gatekeeping; ability to decline unsafe requests while offering workable alternatives that keep AI adoption moving.
Compensation Range
The anticipated base salary range for this role is $175,000 to $225,000. Base salary for the role will depend on several factors, including a candidate’s qualifications, skills, competencies, and experience, and may fall outside of the range shown. In addition, this role may be eligible for a discretionary bonus. Rockefeller Capital Management offers a comprehensive benefit package including health coverage, vacation time, paid leave, retirement plan, and more. Visit careers.rockco.com to learn more about additional opportunities and benefits offerings.
Disclosure
Rockefeller & Co. LLC, Rockefeller Financial LLC, Rockefeller Trust Company, N.A., The Rockefeller Trust Company (Delaware), Rockefeller Financial Services, Inc. and all other subsidiaries of Rockefeller Capital Management L.P. (individually and collectively, “Rockefeller”) is an equal opportunity employer and does not discriminate on the basis of race, religion, sex, gender, sexual orientation, gender identity or expression, national origin, citizenship, age, military or veteran status, marital or partnership status, caregiver status, legally recognized disability, or any other basis protected by applicable federal, state or local law (“protected characteristics”).
Rockefeller Capital Management participates in the E-Verify program in certain locations, as required by law.
Similar roles
-
Cloud Security Engineer
Gifthealth Inc Columbus, Ohio, United States · $115K–$150K/yr
-
Senior Cybersecurity Engineer (Identity and Access Management)
Open Dealer Exchange Southfield, Michigan, United States
-
Cybersecurity Engineer
Open Dealer Exchange Southfield, Michigan, United States
-
Senior Information Security Engineer
Zscaler United States · $134K–$168K/yr
-
Cybersecurity Analyst
Smiths Group Pune, Maharashtra, India
-
Staff Product Security Engineer
Affirm Canada · CA$181K–CA$241K/yr