AI Security Engineer Lead

100 CRC Insurance Group, LLC

Charlotte (NC)

Hybrid

USD 140,000 - 200,000

Full time

3 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Medical, dental, vision benefits
401(k) with company match
Paid time off and holidays

Job summary

CRC Group seeks an AI Security Engineer Lead to own and advance the security controls for agentic AI across the enterprise. You will build reusable security patterns, partner with AI developers, and ensure secure operation of MCP servers, A2A interactions, and API gateways within an Azure-centric environment.

The role emphasizes strong communication with technical and executive stakeholders, and requires hands-on experience securing AI workloads in Microsoft Azure Foundry and APIM.

Qualifications

  • 5+ years in Cybersecurity with hands-on engineering and operations.
  • Experience developing security patterns for AI agent harnesses and supporting components.
  • Hands-on experience securing AI workloads in Microsoft Azure, including Foundry.
  • Experience engineering and operating Azure API Management (APIM) with policy authoring.
  • Designing and validating security controls for AI agents, MCP servers, and A2A interactions.
  • Strong knowledge of identity and access patterns (OAuth2.x, OIDC, Entra ID).
  • Familiarity with OWASP Top10 for LLM Applications, MITRE ATLAS, and NIST AI RMF.

Responsibilities

  • Lead AI security function, deliver service offerings, architectures, and a security roadmap.
  • Partner with architects, engineers, and developers to embed security into AI solutions.
  • Ensure compliance with CRC policy and regulatory obligations (NYDFS, etc.).
  • Report current state, risk posture, and progress in maturing AI security.
  • Develop and maintain secure design patterns for AI agent harnesses and gateways.
  • Define guardrails against prompt injection, tool misuse, and data leakage.
  • Secure agents on Microsoft Foundry and third-party harnesses (Anthropic Claude).
  • Operate Azure APIM and AI Gateway as policy enforcement for model, agent, MCP, and API traffic.
  • Integrate gateway telemetry with Microsoft Sentinel and Defender for Cloud.

Skills

Cybersecurity leadership
Security patterns
Azure Foundry
Azure APIM
AI security controls
OAuth/OIDC
OWASP Top10 for LLM
MITRE ATLAS
NIST AI RMF

Tools

Azure APIM
Microsoft Foundry
Claude Agent SDK

Job description

Regular or Temporary: Regular Language Fluency: English (Required) Work Shift: 1st Shift (United States of America) Please review the following job description: CRC is putting AI agents to work across the business, and we need a hands‑on leader to make sure they are built and run securely from day one. The AI Security Engineer Lead owns the engineering of security controls for agentic AI: the agent harnesses that house and orchestrate agents, tools, the MCP servers and APIs that agents call, agent-to-agent (A2A) interactions, and the AI and API gateways that sit in the path. This role designs reusable security patterns, builds and operates the controls that enforce them, and proves those controls actually work. This is a builder’s role with real influence. The ideal candidate partners closely with AI Innovation, Data Management and Analytics, Enterprise Architecture, and Application and AI Agent Developers to make the secure path the easy path, and communicates risk and progress clearly to both technical and executive stakeholders. Note: CRC is almost‑exclusively a Microsoft Azure shop, so the ideal candidate will be able to demonstrate their competence and successes securing AI workloads in Microsoft Foundry and Azure API Management (APIM). Anthropic control experience is also highly‑desirable.
Send an email to Accessibility (accommodation requests only; other inquiries won't receive a response).

Key Responsibilities
  • AI Security Leadership Lead the AI Security function, including development and delivery of AI Security Service Offerings, reference architectures, operational runbooks, and a roadmap for continual improvement.
  • Partner with Cybersecurity Architects and Engineers, IT Infrastructure Engineers, and Application and AI Agent Developers to embed security into AI solutions from design through production.
  • Partner with Project and Program Management to ensure that we’re executing the right work with the right priorities.
  • Partner with GRC to keep AI use compliant with CRC policy and regulatory obligations (including NYDFS, among others), and to remediate any findings or observations.
  • Maintain the ability to quickly report on current state, risk posture, and progress maturing this space.
  • Agent Harness Security Patterns Develop, publish, and maintain secure design patterns for AI agent harnesses, covering tool permissioning, sandboxing, human‑in‑the‑loop approvals, memory and context handling, and safe failure modes.
  • Define guardrails against prompt injection (direct and indirect), tool misuse, excessive agency, data leakage, and model or supply‑chain compromise, aligned to OWASP Top 10 for LLM Applications, OWASP Agentic AI guidance, and MITRE ATLAS.
  • Secure agents built on Microsoft Foundry (including Foundry Agent Service), and establish equivalent patterns for third‑party harnesses such as Anthropic’s Claude Agent SDK.
  • AI Gateway & API Security Engineer and operate Azure APIM and AI Gateway capabilities as the policy enforcement point for model, agent, MCP, and API traffic, including authentication, authorization, rate and token limits, content safety, logging, and routing.
  • Protect APIs consumed and exposed by agents with strong identity, schema validation, threat protection, and least‑privilege access.
  • Integrate gateway telemetry with Microsoft Sentinel and Defender for Cloud for monitoring, detection, and response.
  • MCP & Agent-to-Agent (A2A) Security Define and enforce standards for building, registering, and consuming MCP servers, including OAuth‑based authorization, server allow‑listing, tool and scope minimization, and supply‑chain vetting.
  • Establish trust, authentication, and authorization models for A2A interactions, including agent identity, delegation boundaries, and auditability of multi‑agent workflows.
  • Maintain an inventory of agents, MCP servers, and their connections so that exposure and blast radius are always known.
  • Identity & Secure Access Design secure access to agents, MCP servers, APIs, and data using Microsoft Entra ID, managed Identities, workload and agent identities, Conditional Access, and on‑behalf‑of flows.
  • Partner with the Data Security team to ensure agents only reach data they are entitled to, leveraging Microsoft Purview classification, DLP, and DSPM for AI.
  • Control Effectiveness & Assurance Define measurable control objectives and KPIs, and continuously validate that AI security controls are working as intended.
  • Lead AI red teaming, adversarial testing, and threat modeling of agentic systems before and after production release.
  • Build detections and automated response for AI‑specific threats, and continuously improve controls based on findings, incidents, and emerging threats.
Qualifications
Required
  • 5+ years in Cybersecurity, with hands‑on keyboard engineering and operational responsibilities.
  • Demonstrated experience developing security patterns for AI agent harnesses and their supporting components, including API and AI gateways.
  • Hands‑on experience securing AI workloads in Microsoft Azure, including Microsoft Foundry.
  • Hands‑on experience engineering and operating Azure API Management (APIM), including policy authoring.
  • Practical experience designing and validating security controls for AI agents, MCP servers, and A2A interactions.
  • Strong understanding of identity and access patterns for workloads and agents (OAuth2.x, OIDC, Microsoft Entra ID, managed identities).
  • Working knowledge of AI‑specific threats and frameworks such as OWASP Top10 for LLM Applications, MITRE ATLAS, and NIST AI RMF.
  • Ability to communicate clearly with technical and executive stakeholders, adapting messaging to the audience.
Preferred
  • Experience with Anthropic’s agent harness and related patterns (e.g., Claude Agent SDK, Claude Code, hooks, permissioning, and sub‑agents).
  • Experience with Azure AI Content Safety / Prompt Shields, Defender for Cloud AI threat protection, and Microsoft Purview DSPM for AI.
  • Scripting or development proficiency in Powershell, Python, or other scripting, plus infrastructure‑as‑code (Terraform or Bicep) and KQL.
  • Familiarity or experience with AI red teaming tools such as PyRIT, Garak, or similar.
  • Microsoft certifications such as AZ‑500, SC‑100, or AI‑102, or equivalent; AI security credentials (e.g., GIAC GOAA) an plus.
  • Familiarity with regulatory and governance frameworks such as NYDFS 23 NYCRR 500, ISO/IEC 42001, and NIST800‑53.
  • Experience in insurance or financial services.
Work Environment

Hybrid or on‑site depending on organizational needs. On‑call rotation may be required for critical incident response. Required flexibility to work nights, weekends and/or holiday shifts in the event of an incident response emergency.

Location

Charlotte, NC is the preferred location. However, we may be open to candidates in other locations based in the Eastern time zone.

General Description of Available Benefits for Eligible Employees of CRC Group
  • At CRC Group, we’re committed to supporting every aspect of teammates' well‑being – physical, emotional, financial, social, and professional. Our best‑in‑class benefits program is designed to care for the whole you, offering a wide range of coverage and support.
  • Eligible full‑time teammates enjoy access to medical, dental, vision, life, disability, and AD&D insurance; tax‑advantaged savings accounts; and a 401(k) plan with company match.
  • CRC Group also offers generous paid time off programs, including company holidays, vacation and sick days, new parent leave, and more.
  • Eligible positions may also qualify for restricted stock units and/or a deferred compensation plan.

CRC Group supports a diverse workforce and is an Equal Opportunity Employer that does not discriminate against individuals on the basis of race, gender, color, religion, citizenship or national origin, age, sexual orientation, gender identity, disability, veteran status or other classification protected by law.

CRC Group is a Drug Free Workplace.

EEO is the Law Pay Transparency Nondiscrimination Provision E-Verify Join CRC Group, a leader in specialty wholesale insurance, and take your career to new heights. We're a dynamic team dedicated to innovation, collaboration, and excellence.

Why CRC Group?
  • Growth: Advance your career with our learning and leadership development programs.
  • Innovation: Work in a forward‑thinking environment that values new ideas.
  • Community: Be part of a supportive team that celebrates success together.
  • Benefits: Enjoy competitive compensation, health benefits, and retirement plans.
Who We’re Looking For

We seek passionate individuals who thrive in a fast‑paced, collaborative environment. If you value integrity and are driven to succeed, CRC Group is the place for you.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior DevOps Engineer
Senior DevOps Engineer

100 CRC Insurance Group, LLC • Dallas (TX)

Hybrid
USD 140,000 - 190,000
Medical coverage
Dental coverage
Vision coverage
+2
Machine Learning Engineer
Machine Learning Engineer

100 CRC Insurance Group, LLC • Charlotte (NC)

On-site
USD 120,000 - 180,000
Medical insurance
401(k) with company match
Paid time off
Underwriter - Cyber, Technology, E&O & Miscellaneous Professional Liability
Underwriter - Cyber, Technology, E&O & Miscellaneous Professional Liability

200 CRC Insurance Svcs LLC • Dallas (TX)

On-site
USD 75,000 - 100,000
Medical insurance
Dental insurance
Vision insurance
+2
IT Strategy & Product Management Sr. Analyst
IT Strategy & Product Management Sr. Analyst

100 CRC Insurance Group, LLC • Charlotte (NC)

On-site
USD 80,000 - 110,000
Medical insurance
Dental insurance
Vision insurance
+2
CRC Benefits - Account Manager - Employee Benefits (Remote)
CRC Benefits - Account Manager - Employee Benefits (Remote)

CRC Insurance Services, Inc. • Portland (ME)

Remote
USD 60,000 - 80,000
Medical benefits
Dental benefits
Vision benefits
+2
Data Analyst
Data Analyst

100 CRC Insurance Group, LLC • Morrisville (NC)

On-site
USD 90,000 - 130,000
Medical, dental, vision insurance
401(k) plan with company match
Paid time off (holidays, vacation, and
+1
Data Analyst
Data Analyst

CRC Group • Morrisville (NC), Northern (KY)

On-site
USD 110,000 - 150,000
CRC Benefits - Senior Sales Support Representative (Remote)
CRC Benefits - Senior Sales Support Representative (Remote)

206 Centerstone Ins & Fin Svc • California (MO)

Hybrid
USD 75,000 - 85,000
Medical insurance
Dental insurance
Vision insurance
+2
Underwriting Team Lead
Underwriting Team Lead

200 CRC Insurance Svcs LLC • Bothell (WA)

On-site
USD 100,000 - 115,000
Medical and dental benefits
401(k) with company match
Paid time off
CRC Benefits - Sales Executive, Ancillary Benefits (Remote)
CRC Benefits - Sales Executive, Ancillary Benefits (Remote)

206 Centerstone Ins & Fin Svc • Town of Texas (WI)

Hybrid
USD 90,000 - 110,000