AI Information Security Engineer

Tenable, Inc.

Boston, Columbia (MA, MD)

Hybrid

USD 170,000 - 230,000

Full time

48 hours ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Hybrid work model

Job summary

Tenable, Inc. is a leader in exposure management, hiring an AI Security Engineer to secure AI across products and the enterprise. This hybrid role supports Boston, MA, with collaboration across the Information Security team to define security controls and governance for AI features.

The candidate will design guardrails for AI systems, perform security assessments, and develop tooling to boost Tenable’s security posture in a rapidly evolving AI landscape.

Qualifications

  • 5+ years of professional experience in information security or application security
  • 1–2 years focused on securing AI/ML systems
  • Strong coding experience in Python and/or Go
  • Experience with security testing practices (SAST, DAST, SCA) and threat modeling

Responsibilities

  • Design, implement, and maintain end-to-end security controls across the AI/ML lifecycle.
  • Conduct AI safety research and threat modeling for AI/ML systems.
  • Design and implement security guardrails for LLMs, SLMs, and open-source models.
  • Collaborate with engineers to integrate security into AI development and deployment processes.
  • Drive SSDLC and DevSecOps practices for AI-powered products.
  • Create security guidance, documentation, and training for internal teams.

Skills

Communication
Cross-functional collaboration
Problem-solving
Independent work

Education

Master’s degree in Computer Science, Cybersecurity, Data Science, or related field

Tools

PyTorch
Hugging Face Transformers
TensorFlow
TransformerLens

Job description

US - Hybrid - Massachusetts - Boston , US - Headquarters - Maryland - Columbia

Who is Tenable?

Tenable® is the Exposure Management company. Over 40,000 organizations around the globe rely on Tenable to understand and reduce cyber risk. Our global employees support 65 percent of the Fortune 500, 50 percent of the Global 2000, and large government agencies. Come be part of our journey!

What makes Tenable such a great place to work?

Ask a member of our team and they’ll answer, “Our people!” We work together to build and innovate best-in-class cybersecurity solutions for our customers; all while creating a culture of belonging, respect, and excellence where we can be our best selves. When you’re part of our #OneTenable team, you can expect to partner with some of the most talented and passionate people in the industry, and have the support and resources you need to do work that truly matters. We deliver results that exceed expectations and we win together!

Applicants must be authorized to work for any employer in the U.S. without sponsorship. We are unable to provide sponsorship for work visas of any kind at the time of hire, or at any point during employment. This includes, but is not limited to: F1-OPT, F1-CPT, H-1B, TN, J-1, etc

Your Role:

As an AI Security Engineer on Tenable's Information Security team, you will help shape and mature our approach to securing AI both within Tenable's products and across the enterprise. AI introduces a new class of risk at the intersection of application security, cloud risk, and data governance, and you will be on the front lines of defining how we assess, test, and address it.

You will apply hands-on AI engineering experience alongside deep product security and application security skills to design security controls for AI systems, lead assessments, and help engineering teams ship AI features securely. You will establish security standards for responsible AI use, influence decisions across the organization, and build tooling that raises our security posture.

This role is ideal for a practitioner who has spent real time building with AI systems, looking under the hood of model internals, and wants to channel that experience into a security specialty.

  • Design, implement, and maintain end-to-end security controls across the AI/ML lifecycle.
  • Conduct safety research, inspecting model internals (e.g., detecting hidden deception, latent knowledge, or unwanted concepts across layers) as a core methodology.
  • Perform AI safety assessments and threat modeling for AI/ML systems, identifying risks such as data poisoning, model evasion, model extraction, adversarial inputs, and integrity attacks.
  • Design and implement robust security guardrails, controls, and boundary mechanisms for Large Language Models (LLMs), Small Language Models (SLMs), and open-source models.
  • Act as a subject matter expert in AI safety research by inspecting model internals to detect hidden deception, latent knowledge, or unwanted concepts, ensuring highly transparent and aligned AI outputs.
  • Continuously monitor the AI landscape for novel vulnerabilities and attack techniques, applying deep engineering experience to proactively defend enterprise AI deployments.
  • Develop security reference architectures for AI deployment patterns, including MCP servers and agentic AI workflows and harnesses.
  • Deploy controls to ensure model integrity, governance, and proper access control across models and feature stores.
  • Build AI-driven tooling to strengthen cybersecurity posture across identity, incident management, vulnerability management, third-party risk, and emerging AI threat vectors.
  • Perform AI safety, security assessments, threat modeling for AI/ML systems, identifying risks such as data poisoning, model evasion, model extraction, adversarial inputs, and integrity attacks.
  • Collaborate with software engineers, and product teams to integrate security best practices into AI development, training, validation, and deployment processes.
  • Drive Secure Software Development Lifecycle (SSDLC) and DevSecOps practices for AI-powered products, including threat modeling, security testing, penetration testing, and CI/CD pipeline security automation.
  • Create security guidance, documentation, and training for internal engineering and development teams; develop metrics that drive desired security behaviors and outcomes.
  • Research emerging trends in AI security and contribute to innovative solutions that support Tenable's AI initiatives.

What You'll Need:

  • 5 or more years of professional experience in information security or application security, with at least 1–2 years focused on securing AI/ML systems.
  • Master’s Degree in Computer Science, Cybersecurity, Data Science, or a related field preferred; advanced degree preferred.
  • Deep understanding of AI-specific security threats, including adversarial ML, data poisoning, prompt injection, model inversion, model evasion, and inference attacks.
  • Strong coding experience in Python and/or Go.
  • Experience with frameworks & libraries such as PyTorch, Hugging Face Transformers, TensorFlow or similar.
  • Experience using specialized interpretability and probing tools/libraries such as TransformerLens, NNsight, Captum, or LIT (Learning Interpretability Tool).
  • Familiarity with mechanistic & Architectural Concepts: inspecting internal model states, residual streams, attention patterns, activation steering, Sparse Autoencoders (SAEs), or feature attribution.
  • Strong understanding of the ML/AI lifecycle and the security risks associated with each stage.
  • Knowledge of cloud security platforms: AWS, Azure, or GCP including AI/ML-related services.
  • Knowledge of data security principles, including encryption, masking, and tokenization.
  • Knowledge of SSDLC, DevSecOps, and security testing practices, including SAST, DAST, SCA, and threat modeling.
  • Knowledge of application security architecture best practices and patterns, including modern web applications, Docker, and microservices.
  • Ability to work cross-functionally across engineering, product, and business teams.
  • Strong written and verbal comAAmunication skills; able to clearly translate complex AI security risks for both technical and non-technical audiences.
  • Strong problem-solving skills, attention to detail, and ability to lead projects with end-to-end ownership.
  • Self-motivated and effective working independently and across distributed teams.

And Ideally:

  • Hands-on experience with AI red teaming, adversarial prompt testing, or LLM security assessments.
  • Familiarity of AI security frameworks and standards, including OWASP LLM Top 10 and the NIST AI Risk Management Framework.
  • Experience with application security assessment tools (Burp Suite, ZAP, Tenable WAS, etc).
  • Familiarity with AI governance frameworks (EU AI Act, NIST AI RMF, etc).
  • Background in cloud security or large-scale SaaS product environments.
  • Security certifications: CISSP, CSSLP, SANS GIAC, CEH, or AI-focused security certifications are a plus, but not necessary.

This is a hybrid position that requires you to work from either our Headquarters in Columbia, MD or in Boston, MA.

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey.Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiringprocess or thereafter. Any information that you do provide will be recorded and maintained in aconfidential file.

As set forth in Tenable, Inc.’s Equal Employment Opportunity policy,we do not discriminate on the basis of any protected group status under any applicable law.

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection.As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measurethe effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categoriesis as follows:

A \"disabled veteran\" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A \"recently separated veteran\" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An \"active duty wartime or campaign badge veteran\" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An \"Armed forces service medal veteran\" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

We use Greenhouse's AI-powered Talent Matching tool to compare your application against our job requirements.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

AI Security Engineer
AI Security Engineer

Remote Jobs • Boston (MA), Columbia (MD)

Hybrid
USD 123,000 - 163,000
Associate Services Architect
Associate Services Architect

Tenable, Inc. • Columbia (MD)

Hybrid
USD 65,000 - 87,000
Medical, Dental, Vision
401(k) with company match
Stock purchase plan
+6
AI Defense Engineer
AI Defense Engineer

Gravity IT Resources • Cincinnati (OH)

On-site
USD 140,000 - 210,000
Security Operations AI Engineer, Contract New Remote, United States
Security Operations AI Engineer, Contract New Remote, United States

66degrees • Northern (KY)

Hybrid
USD 83,000 - 165,000
Senior AI Security Engineer
Senior AI Security Engineer

World Wide Technology, Inc. • Northern (KY)

Hybrid
USD 140,000 - 210,000
IT Security Analyst
IT Security Analyst

Fortegra • Jacksonville (FL)

On-site
USD 85,000 - 120,000
Staff Security Engineer
Staff Security Engineer

Topaz Labs • Emeryville (CA)

On-site
USD 130,000 - 160,000
100% covered medical/dental/vision
15 days annual PTO
401k matching
AI Security Engineer
AI Security Engineer

TEKsystems • Bolingbrook (IL)

Hybrid
USD 103,000 - 110,000
Medical, dental & vision
401(k) Retirement Plan
Life Insurance
Senior Engineer, Application Security
Senior Engineer, Application Security

Cvent • Virginia (MN)

Hybrid
USD 120,000 - 160,000
Hybrid work model
Competitive benefits package
Security Architect - Artificial Intelligence
Security Architect - Artificial Intelligence

Tyler Technologies, Inc. • Orono (ME)

On-site
USD 150,000 - 157,000
Competitive benefits for health and financial wellness