AI Security Engineer III
RealPage, Inc. Hyderabad, Telangana, India
Software Development · 5,001-10,000 employees
About the role
The AI Security Engineer III designs and builds agentic AI solutions to automate GRC services, including risk register maintenance and policy governance. They are responsible for implementing human-in-the-loop controls, guardrails, and observability frameworks to ensure secure and compliant AI operations.
What they look for
Requirements
Candidates must have a bachelor's degree in a technical field and at least 4 years of experience in software or AI engineering. Proficiency in Python and hands-on experience with LLM-powered applications, agentic orchestration, and AI risk frameworks are required.
Full description
Overview
This role reports into Director/Sr. Manager within Technology GRC and is the technical builder behind the function's agentic AI transformation. The AI Security Engineer III designs, builds, and operates the AI agents and automations that deliver GRC services - with primary focus on the GRC Tool platform, Technology Risks, Threats and Controls Library, the Risk Register, and Policy Governance - all operating under a human-in-the-loop model supervised by the responsible GRC leader. The role bridges GRC domain requirements and engineering execution, prototyping control automations, evidence collectors, and governance tooling that reduce manual effort and enable the team to scale without proportional headcount growth. Responsibilities
GRC Tool & Automation Engineering
- Build and integrate agentic AI solutions and automations within the enterprise GRC platform to standardize workflows, automate evidence collection, and improve reporting.
- Develop control automations, evidence collectors, and governance tooling, reducing dependence on the broader engineering backlog.
Risk Register Automation
- Engineer AI-assisted workflows to populate, maintain, and reconcile the enterprise Risk Register across technology domains.
- Automate linkage between risk entries, controls, and remediation tracking.
Policy Governance Automation
- Build AI-assisted tooling for policy drafting, framework crosswalks, annual review cadence, and exception workflows.
Agent Design, Safety & Operations (Human-in-the-Loop)
- Design agentic workflows using RAG, function/tool calling, and Model Context Protocol (MCP), with appropriate guardrails for accuracy, confidentiality, and IP boundaries.
- Implement human-in-the-loop checkpoints and monitoring so GRC leaders can supervise and validate agent outputs.
- Apply AI risk controls aligned to OWASP Top 10 for LLM Applications, NIST AI RMF, ISO/IEC 42001, and MITRE ATLAS.
Agent Evaluation, Observability & Guardrails
- Build evaluation harnesses and observability for deployed agents - measuring grounding, accuracy, and consistency while minimizing hallucinations across GRC use cases.
- Implement guardrails, deployment gates, and immutable audit trails/logging so non-compliant or low-confidence outputs are caught before use.
- Maintain model documentation (model cards, data provenance) to support AI governance and regulatory defensibility.
Qualifications
- Bachelor's degree in Computer Science, Software Engineering, Data Science, or a related field; equivalent practical experience considered.
- Minimum 4+ years in software/AI engineering, with hands-on experience building LLM-powered applications and agentic workflows.
- Proficiency in Python (or comparable) and modern AI development tooling (e.g., Claude Code, Cursor, GitHub Copilot).
- Hands-on experience with LLM application patterns - prompt engineering, RAG, function/tool calling, agentic orchestration, and MCP.
- Familiarity with leading LLMs (Anthropic Claude, OpenAI GPT/o-series, Google Gemini, Meta Llama, Mistral) and model selection trade-offs (reasoning depth, context window, cost, latency, data residency).
- Working knowledge of the AI/LLM risk landscape: OWASP Top 10 for LLM Applications, NIST AI RMF, ISO/IEC 42001, MITRE ATLAS, and emerging regulation (EU AI Act, NYDFS AI guidance).
- Experience integrating with enterprise platforms and APIs; familiarity with GRC tooling (e.g., ServiceNow IRM, Archer, AuditBoard) a plus.
- Ability to translate GRC domain requirements into well-governed, production-grade automations with human-in-the-loop controls.
- Strong collaboration skills and the ability to partner with non-technical GRC stakeholders.
- Experience building agent evaluation frameworks, guardrails, prompt/version management, and observability/logging for production LLM systems.
- Familiarity with cloud ML platforms (AWS Bedrock/SageMaker, Azure AI, GCP Vertex) and CI/CD-integrated deployment gates.
- AI governance certification a plus (e.g., IAPP AIGP), including agentic architecture concepts.
- Preferred experience in the Property Management, Multifamily Housing, SaaS, FinTech, or PropTech industries.
Similar roles
-
Information Security Engineer - Cloud Security
Ryanair Group Holdings Wrocław, Lower Silesian Voivodeship, Poland
-
Cybersecurity Threat Analyst - English(US)
Welocalize Arlington, Texas, United States · $112K/yr
-
Cybersecurity Threat Analyst - English(Philippines)
Welocalize Manila, Metro Manila, Philippines · $19K/yr
-
Cybersecurity Threat Analyst - English(India)
Welocalize Delhi, India · $21K/yr
-
Cloud Security Engineer, Product Security
Recorded Future Gothenburg, Västra Götaland County, Sweden
-
Cybersecurity Risk Analyst
Inetum Porto, Portugal