Principle Security Engineer
Jobgether United States
Internet Marketplace Platforms · 11-50 employees
About the role
The Principle Security Engineer will operationalize AI risk, security, and compliance capabilities within a regulated financial services environment. This role involves leading third-party risk management, executing adversarial threat modeling, and embedding responsible AI practices across the organization.
What they look for
Requirements
Candidates must have 10+ years of experience in IT/cyber risk, governance, or security engineering with direct exposure to AI/ML systems. Proficiency in AI risk frameworks, threat modeling methodologies, and regulatory environments is essential.
Benefits
Full description
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Principle Security Engineer based in United States.
The Principle Security Engineer will play a key role in building and operationalizing AI risk, security, and compliance capabilities within a regulated financial services environment. This role combines security engineering, governance, third-party risk management, and adversarial threat modeling for AI and machine learning systems. You will translate recognized AI risk management frameworks into practical, auditable controls and processes. The position will also address emerging AI threats, vendor dependencies, data provenance, and the security of AI-enabled technologies. Working across risk, security, legal, procurement, and engineering teams, you will help embed responsible AI practices throughout the organization. This is an opportunity to shape an evolving AI security and governance program while addressing complex and emerging cyber risks.
\n
Accountabilities:
- Operationalize AI governance controls aligned with recognized AI risk management frameworks, including control documentation, risk-control matrices, and audit evidence collection.
- Lead third-party AI and ML risk management activities, including vendor due diligence, security and privacy assessments, contractual requirements, SLAs, fourth-party disclosures, and data provenance reviews.
- Build and maintain inventories of third-party AI components, including models, datasets, APIs, and pre-trained or foundation models, documenting provenance, functionality, limitations, and associated controls.
- Conduct recurring AI risk and compliance assessments covering system performance, data quality, algorithmic bias, security controls, model drift, SLA adherence, concentration risk, and vendor dependencies.
- Design and execute AI/ML threat models using the MITRE ATLAS framework to identify adversarial techniques such as prompt injection, data and model poisoning, model evasion, model extraction, and ML supply-chain threats.
- Coordinate red-team, adversarial testing, and penetration testing activities for AI/ML systems, incorporating current threat intelligence and lessons from previous incidents.
- Integrate AI-specific vulnerabilities and security findings into enterprise vulnerability management processes and ensure appropriate prioritization and remediation.
- Support the identification and assessment of unsanctioned or “shadow” AI usage and recommend appropriate remediation, risk acceptance, or approval pathways.
- Partner with IT Risk, Cloud Security, Legal, Procurement, and Application/AI Engineering teams to embed AI risk requirements into technology intake, procurement, development, and deployment processes.
- Develop and maintain AI risk standards, control narratives, procedures, and runbooks while supporting internal and external audits and regulatory activities.
Requirements:
- 10+ years of experience in IT/cyber risk, governance, risk and compliance, security engineering, or a related discipline, with direct exposure to AI/ML systems.
- Working knowledge of AI risk and control frameworks such as the NIST AI Risk Management Framework or comparable industry frameworks.
- Strong familiarity with the OWASP Top 10 for LLMs and emerging AI security risks.
- Practical experience with, or strong working knowledge of, AI/ML threat modeling methodologies, including MITRE ATT&CK and MITRE ATLAS.
- Experience building or operating third-party and vendor risk management programs, including due diligence, contracting, SLAs, ongoing monitoring, and issue remediation.
- Understanding of AI-specific attack techniques, including prompt injection, data/model poisoning, model evasion, and model extraction or inversion, along with relevant mitigations.
- Ability to translate complex technical risk findings into clear control objectives, policies, standards, and audit-ready documentation.
- Experience working in regulated environments, preferably within financial services or organizations subject to FINRA requirements.
- Strong communication and collaboration skills, with the ability to work effectively across technical, security, risk, legal, compliance, and engineering stakeholders.
- Experience with GRC platforms such as Archer or ServiceNow GRC is preferred.
- Certifications such as CRISC, CISSP, CCSP, or IAPP AIGP are preferred.
- Experience with AWS Bedrock or other cloud AI/ML platforms and cloud-native AI security is a plus.
- Familiarity with model cards, data lineage and provenance tools, and AI Bill of Materials (AI-BOM) concepts is preferred.
- Experience participating in red-team, purple-team, or adversarial testing exercises involving ML systems is a plus.
- Exposure to AI governance committees or model risk management functions is desirable.
Benefits:
- Opportunity to shape AI risk and security practices within a regulated financial services environment.
- Exposure to emerging AI/ML security threats, governance frameworks, and adversarial testing methodologies.
- Cross-functional collaboration with cybersecurity, IT risk, cloud security, legal, procurement, and AI engineering teams.
- Opportunity to influence AI governance, third-party risk, vulnerability management, and security architecture practices.
- Work focused on emerging technologies and evolving AI security challenges.
- Opportunity to contribute to audit readiness, regulatory compliance, and enterprise-wide risk management initiatives.
\nHow Jobgether works:
We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.
We appreciate your interest and wish you the best!
Why Apply Through Jobgether?
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
#LI-CL1
Similar roles
-
Information Security Engineer
MEDITECH Canton, Massachusetts, United States · $66K–$105K/yr
-
Information Security Engineer
RSC2 INC Aberdeen Proving Ground, Maryland, United States · $105K–$245K/yr
-
Cybersecurity Analyst
Saxton & Stump Manheim Township, Pennsylvania, United States
-
Electronic Security Engineer
CertiPath Inc Arlington, Virginia, United States · $110K–$125K/yr
-
Information Systems Security Engineer
Booz Allen Hamilton Warner Robins, Georgia, United States · $99K–$225K/yr
-
Cybersecurity, Engineering, and Technology Implementation Support Engineer
Booz Allen Hamilton North Charleston, South Carolina, United States · $87K–$198K/yr