AI Security Engineer

tms

Chicago (IL)

Hybrid

USD 110,000 - 140,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Generous medical, dental, vision benefits
401(k) with company match
Tuition reimbursement
15 days paid time off plus holidays
Inclusive employee resource groups

Job summary

tms is seeking an AI Security Engineer to shape the security landscape for renowned brands. This role blends traditional security engineering and AI tooling, demanding expertise in secure software development and SaaS governance.

The AI Security Engineer will evaluate AI tools for security risks, develop security standards for AI-assisted workflows, and lead third-party SaaS application security assessments. A minimum of 5 years of experience is required. The position offers a hybrid work model and comprehensive benefits.

Qualifications

  • Minimum of 5 years of hands-on experience in information technology, focused on risk management and compliance.
  • Excellent understanding of compliance frameworks like ISO 27001, SOC 2, and GDPR.
  • Proficiency in secure coding practices in languages such as Python and JavaScript.

Responsibilities

  • Evaluate AI tools for security risks, including prompt injection and data leakage.
  • Develop security standards for AI-assisted development workflows.
  • Lead SaaS application security assessments and evaluate vendor security posture.

Skills

Risk management
Compliance frameworks
Secure coding
AI security
Analytical skills
Communication skills

Education

5+ years in IT focused on security
Relevant certifications (CSSLP, CEH)

Tools

Rapid7
ZenGRC
SAST/DAST tools

Job description

AI Security Engineer

tms seeks an AI Security Engineer to shape the security landscape for world‑renowned brands in a culture that values innovation, authenticity, and inclusion. The role blends traditional security engineering with AI‑driven tooling, requiring expertise in secure software development, AI platform security, and SaaS governance.

Responsibilities
AI Engineering Security
  • Evaluate AI tools, models, and platforms for security risk, including prompt injection vulnerabilities, data leakage, model output integrity, and supply chain risks.
  • Develop and enforce security standards for AI‑assisted development workflows, including LLM‑integrated CI/CD pipelines and code generation tools.
  • Assess AI API integrations and third‑party model usage for data handling compliance, authorization controls, and audit logging.
  • Participate in the design and review of AI‑powered internal tooling and automation, ensuring security requirements are embedded from inception.
  • Stay current on evolving AI security threats including adversarial prompting, model poisoning, and emerging OWASP LLM Top 10 guidance.
Secure Coding & Application Security
  • Conduct secure code reviews across multiple languages and frameworks, with an emphasis on Python, JavaScript/TypeScript, and cloud‑native applications.
  • Apply OWASP principles and industry‑standard secure development lifecycle (SDLC) practices to engineering workflows.
  • Perform static and dynamic application security testing (SAST/DAST) and triage findings with development teams through to remediation.
  • Collaborate with software engineers to embed security controls into code pipelines, authentication flows, and data handling routines.
SaaS Application Security Reviews
  • Lead third‑party SaaS application security assessments, evaluating vendor security posture, data handling practices, access control models, and contractual compliance.
  • Maintain a SaaS application inventory and risk register, conducting periodic reviews and ensuring ongoing controls alignment.
  • Evaluate browser‑based plugins, marketplace extensions, and integrations for privilege scope, data exfiltration risk, and policy adherence.
  • Partner with Procurement and Legal during the vendor onboarding process to communicate security requirements and assess residual risk.
Marketing Technology Security
  • Assess the security posture of marketing platforms including CRMs, CDPs, ad tech stacks, campaign automation tools, and analytics platforms.
  • Evaluate data flows between marketing systems and core enterprise infrastructure, identifying excessive data sharing, weak authentication, and shadow IT exposure.
  • Support the review and governance of marketing API keys, OAuth tokens, and webhook configurations.
  • Partner with Marketing and Digital teams to align platform configuration with data privacy requirements (GDPR, CCPA) and organizational policy.
Architecture & Standards
  • Participate in architecture review boards (ARB) to assess new systems and integration patterns for security risk.
  • Develop and maintain security reference architectures for SaaS integrations, AI platform connections, and plugin frameworks.
  • Contribute to security policies, standards, and playbooks relevant to AI security, SaaS governance, and third‑party risk.
  • Support threat modeling exercises for new platform deployments and significant system changes.
Required Experience
  • Minimum of 5 years of hands‑on experience in information technology, focused on risk management and compliance.
  • Comprehensive knowledge of industry market structures and regulatory compliance frameworks (ISO 27001, SOC 2, NIST, NIS2, GDPR).
  • Demonstrated expertise in identity management standards, cloud‑based storage, and disaster recovery strategies.
  • Proficiency in utilizing security assessment tools, including Rapid7.
  • Familiarity with Governance, Risk, and Compliance (GRC) platforms such as ZenGRC, OneTrust, and Archer.
  • Documented success coordinating and executing multiple risk and compliance initiatives.
  • Proven ability to manage third‑party audits, compiling evidence and organizing comprehensive responses.
  • Exceptional attention to detail and accuracy.
  • Strong written and verbal communication skills, with the ability to collaborate across cross‑functional teams.
  • Well‑developed analytical and problem‑solving skills, driving initiatives that support organizational objectives.
Preferred Qualifications
  • 3–5 years of progressive experience in security engineering, application security, or a related role.
  • Hands‑on experience with secure coding in one or more languages (Python, JavaScript/TypeScript, Go).
  • Knowledge of OWASP Top 10, OWASP LLM Top 10, and common application security vulnerabilities.
  • Experience conducting SaaS application security reviews or third‑party vendor security assessments.
  • Familiarity with AI/ML platforms, LLM integrations, or AI‑assisted development tooling from a security perspective.
  • Understanding of OAuth 2.0, SAML, API security patterns, and modern identity and access management concepts.
  • Experience with SAST, DAST, or SCA tooling (Semgrep, Checkmarx, Snyk, Burp Suite).
  • Strong written and verbal communication skills, conveying technical risk to non‑technical stakeholders.
Additional Preferred Experience
  • Experience securing marketing technology platforms such as Salesforce, HubSpot, Adobe Experience Cloud.
  • Familiarity with browser extension security, plugin frameworks, and marketplace governance.
  • Exposure to cloud security principles on AWS, Azure, or GCP relevant to SaaS and AI workloads.
  • Relevant certifications (CSSLP, CEH, GWAPT, AWS Security Specialty, or equivalent).
  • Experience contributing to security architecture review processes or developing reference security patterns.
  • Knowledge of data privacy regulations (GDPR, CCPA, HIPAA) as they apply to marketing and analytics platforms.

Starting salary: $110,000–$140,000

Benefits
  • Generous medical, dental, vision, and other benefits.
  • Paid parental and medical leave programs.
  • 401(k) with company match and profit sharing.
  • 15 days paid time off plus company holidays.
  • Hybrid work model.
  • Tuition reimbursement and student loan repayment assistance.
  • Inclusive employee resource groups.

We are an equal opportunity employer, committed to diversity. We do not discriminate on the basis of race, religion, color, national origin, sex, gender, sexual orientation, age, marital status, veteran status, or disability status. We provide reasonable accommodations for applicants with disabilities.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

AI Security Engineer
AI Security Engineer

tms (USA) • Chicago (IL)

Hybrid
USD 110,000 - 140,000
Medical, dental, and vision benefits
401(k) with company match
15 days paid time off
+2
AI Security Engineer
AI Security Engineer

Morgan Street Holdings • Chicago (IL)

Hybrid
USD 110,000 - 140,000
Generous medical, dental, and vision benefits
401(k) with company match
Paid parental and medical leave
+2
Security Solutions Principal - AI Security
Security Solutions Principal - AI Security

World Wide Technology • New Home (MO)

On-site
USD 153,000 - 192,000
Health and Wellbeing
Profit Sharing
401k Matching
+2
Senior Security Engineer, Platforms & AI
Senior Security Engineer, Platforms & AI

Triwill Group • United States

On-site
USD 140,000 - 200,000
Remote-first
Competitive salary
Unlimited PTO
+2
Director, Application Security Austin, TX
Director, Application Security Austin, TX

Webai • Austin (TX)

On-site
USD 180,000 - 280,000
Competitive salary
Health benefits (medical/dental/vision
401(k) match
+7
Director, Application Security
Director, Application Security

ProducePay • Austin (TX)

On-site
USD 180,000 - 230,000
Competitive salary
Health, dental, and vision benefits
401(k) match (U.S.-based)
+5
IT Security Analyst
IT Security Analyst

Fortegra • Jacksonville (FL)

On-site
USD 85,000 - 120,000
AI Security Architect
AI Security Architect

Cadence • San Jose (CA)

On-site
USD 164,000 - 306,000
Paid vacation and holidays
401(k) plan with employer match
Employee stock purchase plan
+1
Application Security Engineer
Application Security Engineer

Pantera Capital • Palo Alto (CA)

On-site
USD 100,000 - 258,000
Equity
Medical coverage
401(k)
Security Engineer - Member of Technical Staff
Security Engineer - Member of Technical Staff

Doist • San Francisco (CA)

On-site
USD 200,000 - 400,000
Equity grants
Comprehensive medical, dental, and vision coverage
Flexible time off policies