Principle Security Engineer
Quick Summary
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Principle Security Engineer based in United States.
The Principle Security Engineer will play a key role in building and operationalizing AI risk, security, and compliance capabilities within a regulated financial services environment. This role combines security engineering, governance, third-party risk management, and adversarial threat modeling for AI and machine learning systems. You will translate recognized AI risk management frameworks into practical, auditable controls and processes. The position will also address emerging AI threats, vendor dependencies, data provenance, and the security of AI-enabled technologies. Working across risk, security, legal, procurement, and engineering teams, you will help embed responsible AI practices throughout the organization. This is an opportunity to shape an evolving AI security and governance program while addressing complex and emerging cyber risks.
- Operationalize AI governance controls aligned with recognized AI risk management frameworks, including control documentation, risk-control matrices, and audit evidence collection.
- Lead third-party AI and ML risk management activities, including vendor due diligence, security and privacy assessments, contractual requirements, SLAs, fourth-party disclosures, and data provenance reviews.
- Build and maintain inventories of third-party AI components, including models, datasets, APIs, and pre-trained or foundation models, documenting provenance, functionality, limitations, and associated controls.
- Conduct recurring AI risk and compliance assessments covering system performance, data quality, algorithmic bias, security controls, model drift, SLA adherence, concentration risk, and vendor dependencies.
- Design and execute AI/ML threat models using the MITRE ATLAS framework to identify adversarial techniques such as prompt injection, data and model poisoning, model evasion, model extraction, and ML supply-chain threats.
- Coordinate red-team, adversarial testing, and penetration testing activities for AI/ML systems, incorporating current threat intelligence and lessons from previous incidents.
- Integrate AI-specific vulnerabilities and security findings into enterprise vulnerability management processes and ensure appropriate prioritization and remediation.
- Support the identification and assessment of unsanctioned or “shadow” AI usage and recommend appropriate remediation, risk acceptance, or approval pathways.
- Partner with IT Risk, Cloud Security, Legal, Procurement, and Application/AI Engineering teams to embed AI risk requirements into technology intake, procurement, development, and deployment processes.
- Develop and maintain AI risk standards, control narratives, procedures, and runbooks while supporting internal and external audits and regulatory activities.
Requirements
~2 min read- 10+ years of experience in IT/cyber risk, governance, risk and compliance, security engineering, or a related discipline, with direct exposure to AI/ML systems.
- Working knowledge of AI risk and control frameworks such as the NIST AI Risk Management Framework or comparable industry frameworks.
- Strong familiarity with the OWASP Top 10 for LLMs and emerging AI security risks.
- Practical experience with, or strong working knowledge of, AI/ML threat modeling methodologies, including MITRE ATT&CK and MITRE ATLAS.
- Experience building or operating third-party and vendor risk management programs, including due diligence, contracting, SLAs, ongoing monitoring, and issue remediation.
- Understanding of AI-specific attack techniques, including prompt injection, data/model poisoning, model evasion, and model extraction or inversion, along with relevant mitigations.
- Ability to translate complex technical risk findings into clear control objectives, policies, standards, and audit-ready documentation.
- Experience working in regulated environments, preferably within financial services or organizations subject to FINRA requirements.
- Strong communication and collaboration skills, with the ability to work effectively across technical, security, risk, legal, compliance, and engineering stakeholders.
- Experience with GRC platforms such as Archer or ServiceNow GRC is preferred.
- Certifications such as CRISC, CISSP, CCSP, or IAPP AIGP are preferred.
- Experience with AWS Bedrock or other cloud AI/ML platforms and cloud-native AI security is a plus.
- Familiarity with model cards, data lineage and provenance tools, and AI Bill of Materials (AI-BOM) concepts is preferred.
- Experience participating in red-team, purple-team, or adversarial testing exercises involving ML systems is a plus.
- Exposure to AI governance committees or model risk management functions is desirable.
What We Offer
~2 min readLocation & Eligibility
Listing Details
- Posted
- October 2, 2026
- First seen
- October 2, 2026
- Last seen
- October 2, 2026
Posting Health
- Days active
- 0
- Repost count
- 0
- Trust Level
- 68%
- Scored at
- October 2, 2026
Signal breakdown
Similar Security Engineer jobs
View all →Browse Similar Jobs
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
No spam. Unsubscribe at any time.