Jobgether

Principle Security Engineer

Jobgether United States

Internet Marketplace Platforms · 11-50 employees

19 h ago
Remote security Principal (10+ yrs) Full-time United States
Create a free account to apply — email only, no card. You can also save this posting or score it against your profile with AI.

About the role

The Principle Security Engineer will operationalize AI risk, security, and compliance capabilities within a regulated financial services environment. This role involves leading third-party risk management, executing adversarial threat modeling, and embedding responsible AI practices across the organization.

What they look for

Security Engineering AI Risk Management Governance Third-party Risk Management Adversarial Threat Modeling Compliance MITRE ATLAS MITRE ATT&CK Vulnerability Management Cloud Security Risk Assessment Data Provenance Model Risk Management Cybersecurity Regulatory Compliance GRC Platforms

Requirements

Candidates must have 10+ years of experience in IT/cyber risk, governance, or security engineering with direct exposure to AI/ML systems. Proficiency in AI risk frameworks, threat modeling methodologies, and regulatory environments is essential.

Benefits

Opportunity to shape AI risk and security practices Exposure to emerging AI/ML security threats Cross-functional collaboration Influence on security architecture practices Work on emerging technologies Contribution to regulatory compliance

Full description

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Principle Security Engineer based in United States.

The Principle Security Engineer will play a key role in building and operationalizing AI risk, security, and compliance capabilities within a regulated financial services environment. This role combines security engineering, governance, third-party risk management, and adversarial threat modeling for AI and machine learning systems. You will translate recognized AI risk management frameworks into practical, auditable controls and processes. The position will also address emerging AI threats, vendor dependencies, data provenance, and the security of AI-enabled technologies. Working across risk, security, legal, procurement, and engineering teams, you will help embed responsible AI practices throughout the organization. This is an opportunity to shape an evolving AI security and governance program while addressing complex and emerging cyber risks.

\n

Accountabilities:

  • Operationalize AI governance controls aligned with recognized AI risk management frameworks, including control documentation, risk-control matrices, and audit evidence collection.
  • Lead third-party AI and ML risk management activities, including vendor due diligence, security and privacy assessments, contractual requirements, SLAs, fourth-party disclosures, and data provenance reviews.
  • Build and maintain inventories of third-party AI components, including models, datasets, APIs, and pre-trained or foundation models, documenting provenance, functionality, limitations, and associated controls.
  • Conduct recurring AI risk and compliance assessments covering system performance, data quality, algorithmic bias, security controls, model drift, SLA adherence, concentration risk, and vendor dependencies.
  • Design and execute AI/ML threat models using the MITRE ATLAS framework to identify adversarial techniques such as prompt injection, data and model poisoning, model evasion, model extraction, and ML supply-chain threats.
  • Coordinate red-team, adversarial testing, and penetration testing activities for AI/ML systems, incorporating current threat intelligence and lessons from previous incidents.
  • Integrate AI-specific vulnerabilities and security findings into enterprise vulnerability management processes and ensure appropriate prioritization and remediation.
  • Support the identification and assessment of unsanctioned or “shadow” AI usage and recommend appropriate remediation, risk acceptance, or approval pathways.
  • Partner with IT Risk, Cloud Security, Legal, Procurement, and Application/AI Engineering teams to embed AI risk requirements into technology intake, procurement, development, and deployment processes.
  • Develop and maintain AI risk standards, control narratives, procedures, and runbooks while supporting internal and external audits and regulatory activities.

Requirements:

  • 10+ years of experience in IT/cyber risk, governance, risk and compliance, security engineering, or a related discipline, with direct exposure to AI/ML systems.
  • Working knowledge of AI risk and control frameworks such as the NIST AI Risk Management Framework or comparable industry frameworks.
  • Strong familiarity with the OWASP Top 10 for LLMs and emerging AI security risks.
  • Practical experience with, or strong working knowledge of, AI/ML threat modeling methodologies, including MITRE ATT&CK and MITRE ATLAS.
  • Experience building or operating third-party and vendor risk management programs, including due diligence, contracting, SLAs, ongoing monitoring, and issue remediation.
  • Understanding of AI-specific attack techniques, including prompt injection, data/model poisoning, model evasion, and model extraction or inversion, along with relevant mitigations.
  • Ability to translate complex technical risk findings into clear control objectives, policies, standards, and audit-ready documentation.
  • Experience working in regulated environments, preferably within financial services or organizations subject to FINRA requirements.
  • Strong communication and collaboration skills, with the ability to work effectively across technical, security, risk, legal, compliance, and engineering stakeholders.
  • Experience with GRC platforms such as Archer or ServiceNow GRC is preferred.
  • Certifications such as CRISC, CISSP, CCSP, or IAPP AIGP are preferred.
  • Experience with AWS Bedrock or other cloud AI/ML platforms and cloud-native AI security is a plus.
  • Familiarity with model cards, data lineage and provenance tools, and AI Bill of Materials (AI-BOM) concepts is preferred.
  • Experience participating in red-team, purple-team, or adversarial testing exercises involving ML systems is a plus.
  • Exposure to AI governance committees or model risk management functions is desirable.

Benefits:

  • Opportunity to shape AI risk and security practices within a regulated financial services environment.
  • Exposure to emerging AI/ML security threats, governance frameworks, and adversarial testing methodologies.
  • Cross-functional collaboration with cybersecurity, IT risk, cloud security, legal, procurement, and AI engineering teams.
  • Opportunity to influence AI governance, third-party risk, vulnerability management, and security architecture practices.
  • Work focused on emerging technologies and evolving AI security challenges.
  • Opportunity to contribute to audit readiness, regulatory compliance, and enterprise-wide risk management initiatives.

\nHow Jobgether works:

We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.

We appreciate your interest and wish you the best!

Why Apply Through Jobgether?

Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.

#LI-CL1

Similar roles