AI Application Security Architect

ACV Auctions

United States

Remote

USD 180,000 - 240,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

ACV Auctions is seeking a Principal Architect, Product Security to define target-state secure architecture for AI/ML systems and oversee secure design across engineering. You will own security controls for AI-assisted development, guarding against adversarial inputs while enabling developer velocity.

The role requires deep GenAI/LLM security experience, hands-on coding, and the ability to translate policy into enforceable technical controls.

Qualifications

  • Bachelor's degree or commensurate experience with security focus
  • 12+ years' of security experience, 15+ years without degree
  • Hands-on GenAI/LLM security work demonstrated by production or verifiable work
  • 2+ years of production AI security experience preferred
  • Security architecture ownership for AI systems and applications
  • Knowledge of OWASP Top 10 for LLM/Agentic Applications and MITRE ATLAS

Responsibilities

  • Define target-state secure architecture for AI/ML systems and reference patterns
  • Protect integrity of vision-based condition and pricing pipelines against adversarial inputs
  • Set secure-by-default standards adopted across engineering for AI development
  • Threat model and review high-risk AI and application designs
  • Stand up AI security testing capability including adversarial testing and red-teaming
  • Advise on multi-year AI security strategy and translate policy into technical controls
  • Scale AI security expertise across engineering and mentor senior engineers
  • Represent ACV's AI security architecture externally

Skills

AI security
Security architecture
Threat modeling
Cloud security
Python coding
Security tooling

Education

Bachelor's degree or commensurate experience

Tools

Garak
PyRIT
promptfoo

Job description

Who we are looking for:

ACV Auctions is hiring an Principal Architect, Product Security to secure how we build and ship AI, as part of the Product Security team. ACV's marketplace runs on AI that customers stake real money on: computer vision models that grade vehicle condition, pricing models that inform lending decisions, and LLM features across our products. You will define how that surface gets protected, and how our engineers use AI coding assistants and agents without trading away security. You will help engineering deliver secure applications across ACV's marketplace, protecting sensitive dealer, consumer, vehicle, and payment data.

Company-wide security architect for AI systems and the applications built around them. Defines ACV's target-state secure architecture, reference architectures, and standards for machine learning and LLM-powered systems, and guides the highest-risk AI and application designs across engineering. A P6 architecture-track role alongside Principal Engineer on the Product Security Career Ladder. Company / multi-year scope; owns AI and application security architecture and standards; sets direction on the most consequential design decisions.

Focus areas: this role spans AI/ML security and application security. It is a technical architecture role. ACV's AI Governance function owns policy, risk registers, and regulatory alignment; this role owns the technical controls and architecture that make those policies real in production systems.

What you will do:
  • Actively and consistently support all efforts to simplify and enhance the customer experience.
  • Define ACV's target-state secure architecture and reference patterns for AI/ML systems: LLM features, retrieval pipelines, agentic workflows, and the computer vision models behind vehicle condition and pricing.
  • Protect the integrity of ACV's vision-based condition and pricing pipeline against adversarial inputs and manipulated or AI-generated imagery, partnering with fraud and inspection teams on detection and image-provenance controls.
  • Set secure-by-default standards adopted across engineering for AI development: prompt injection defense, output handling, tool and agent permissioning, and model and training-data supply chain security.
  • Threat model and review the highest-risk AI and application designs, applying frameworks such as MITRE ATLAS and the OWASP Top 10 lists for LLM and Agentic Applications.
  • Own the security architecture for AI-assisted engineering: coding assistants, MCP servers, and autonomous agents, with guardrails that preserve developer velocity across an API-first engineering organization.
  • Stand up ACV's AI security testing capability: adversarial testing and red-teaming of models and LLM features, evaluation harnesses, and runtime guardrails, making deliberate build-vs-buy decisions.
  • Advise engineering and security leadership on multi-year AI security strategy, and partner with AI governance to translate policy into enforceable technical controls.
  • Scale AI security expertise across engineering, including through ACV's Security Champions program; mentor Staff and Principal engineers; and represent ACV's AI security architecture externally.
  • Perform additional duties as assigned.
What you will need:
  • Ability to read, write, speak and understand English.
  • Bachelor's degree in a related field, or commensurate experience.
  • 12+ years' of security experience, 15+ years' without degree, including deep application security architecture.
  • Hands-on GenAI/LLM security work required, demonstrated through production experience or a verifiable body of work: AI red-team engagements, published research or tooling, open-source contributions, or AI security competition results.
  • 2+ years of production AI security experience preferred.
  • Security architecture: owns the enterprise secure-architecture vision for AI systems and application security.
  • AI/ML security depth: LLM application threats (prompt injection, insecure output handling, data leakage through retrieval, excessive agency in agents and tools) and model-level threats (poisoning, evasion, extraction, malicious pre-trained models).
  • Hands-on technical fluency: reads and writes code (Python preferred) and has personally used AI security tooling (e.g., Garak, PyRIT, promptfoo, or equivalent) rather than only evaluating vendors.
  • Frameworks: working fluency with the OWASP Top 10 for LLM Applications, the OWASP Top 10 for Agentic Applications, MITRE ATLAS, and NIST AI RMF, and the ability to turn them into standards engineers actually follow.
  • Standards and patterns: defines reference architectures and paved-road standards, including for AI-assisted development.
  • Influence: aligns engineering and ML leadership to the target architecture.
  • Application security (commensurate with level): OWASP Top 10, secure code review, threat modeling, and SAST/DAST/SCA tooling (e.g., Snyk, Checkmarx, GitHub Advanced Security, Burp Suite).
  • Cloud security (commensurate with level): cloud-native security on AWS, Kubernetes, and infrastructure-as-code; familiarity with ML platforms and inference infrastructure (e.g., SageMaker, Bedrock) a plus.
  • Comfort working in a fast-paced, cloud-native environment with clear written and verbal communication.
  • Illustrative credentials (a plus, not required): SABSA or equivalent architecture credentials, CCSP or a cloud security specialty. A demonstrated body of AI security work (research, tooling, red-team findings, AI CTF results, open-source contributions) carries more weight than any certification; the AI security credential market is not yet mature.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

AI Security Architect
AI Security Architect

TechDigital Group • Bolingbrook (IL)

On-site
USD 160,000 - 230,000
AI Security Engineer
AI Security Engineer

TBG | The Bachrach Group • New York (NY)

Hybrid
USD 150,000 - 230,000
Application & AI Security Engineer
Application & AI Security Engineer

Hydrogen Group • United States

On-site
USD 140,000 - 190,000
AI Security Architect for Secure ML/LLM Systems
AI Security Architect for Secure ML/LLM Systems

ACV Auctions • United States

Remote
USD 180,000 - 240,000
AI-Application Security Engineer
AI-Application Security Engineer

Stifel Financial Corp. • St. Louis (MO)

On-site
USD 90,000 - 120,000
Security Architect
Security Architect

Maganti IT Resources, LLC • Dallas (TX)

On-site
USD 180,000 - 260,000
Staff Security Engineer (Enterprise AI)
Staff Security Engineer (Enterprise AI)

Affirm • New York (NY)

Remote
USD 150,000 - 210,000
Remote-first
Spending wallets
Supportive communities
+7
AI Information Security Engineer
AI Information Security Engineer

Tenable • Boston (MA)

Hybrid
USD 150,000 - 230,000
Health insurance
Hybrid or remote opportunities
Professional development and tuition
Senior Security Engineer - AI Focus
Senior Security Engineer - AI Focus

Euna Solutions • Atlanta (GA)

On-site
USD 140,000 - 210,000
Senior Engineer, Application Security
Senior Engineer, Application Security

Cvent • Virginia (MN)

On-site
USD 120,000 - 160,000
Hybrid work model
Competitive benefits package