Cloud & AI Security Engineer |New York, NY · $180,000 - $190,000
The Role
A global investment bank with a lean, high-caliber information security organization is looking for a senior Cloud & AI Security Engineer to take on one of the more substantive security engineering mandates in financial services right now. The firm operates in a heavily regulated environment, runs complex cloud infrastructure across AWS and Azure, and is actively expanding its use of generative AI and LLM-based tooling. That expansion needs guardrails, and this person builds them.
This is a hands-on engineering role. You will design and implement security controls, write automation, and do the technical work yourself. You will also partner closely with Infrastructure, Cloud, Development, Data, and Cybersecurity teams, so you need to be as comfortable in a design conversation with a senior stakeholder as you are in a terminal.
This is not a governance or GRC role, and it is not a role where technical execution gets delegated to someone else. If your recent work has been primarily advisory, policy-writing, or audit-facing, this is probably not the right fit.
What This Role Is, and Is Not
This role is:
- A senior, hands-on security engineering position inside a regulated financial-services environment
- The firm's primary owner of cloud security architecture and controls across AWS and Azure
- A lead voice on securing the firm's growing portfolio of generative AI, LLM, and AI agent applications
- A builder of security automation, detection capabilities, and DevSecOps integrations
- A cross-functional partner to engineering and infrastructure teams, not a gatekeeper sitting above them
This role is NOT:
- A manager or team lead position (there is no direct reporting structure attached to it)
- A compliance or audit role, though you will support regulatory and risk requirements
- An advisory or consulting engagement, you are embedded and accountable for outcomes
- A role where AI security is a side interest, it is a core part of the mandate from day one
- Entry-level or mid-career, the environment is too complex and the autonomy too high
Required Experience & Traits
- Five or more years in cybersecurity or security engineering, with meaningful, hands-on cloud security experience in AWS and/or Azure, not just familiarity
- Deep working knowledge of IAM, SSO, MFA, RBAC, privileged access, secrets management, and encryption in cloud environments
- Practical experience with CSPM or CNAPP platforms such as Wiz, Prisma Cloud, Microsoft Defender for Cloud, or a comparable tool
- Ability to secure containers, Kubernetes workloads, APIs, and cloud-native applications, including identifying and remediating misconfigurations and excessive permissions
- Strong scripting ability in Python and/or PowerShell, and real experience building security automation, not just using it
- Solid grasp of DevSecOps practices, CI/CD pipeline security, Git, and infrastructure-as-code (Terraform or equivalent)
- Hands‑on experience with generative AI or LLM applications and a working understanding of their security risks, including prompt injection, data leakage, insecure APIs, and model abuse
- Experience in financial services, investment banking, legal, or another heavily regulated enterprise setting is strongly preferred. A degree matters less than demonstrated execution in a comparable environment.
Key Responsibilities
Cloud Security Architecture & Controls
- Design, implement, and maintain security controls across AWS and Azure, covering workloads, SaaS applications, APIs, containers, and data platforms
- Develop and enforce cloud security architecture standards, Zero Trust principles, and least‑privilege access models
- Conduct security architecture reviews and risk assessments for new cloud services and applications before they reach production
AI & LLM Security
- Establish security controls, governance frameworks, and monitoring capabilities for the firm's use of generative AI, LLMs, AI agents, and machine‑learning workloads
- Evaluate AI applications for risks including prompt injection, jailbreaks, data leakage, excessive permissions, insecure APIs, and unauthorized model access
- Partner with application and engineering teams to securely integrate platforms such as Azure OpenAI, OpenAI, and AWS Bedrock, implementing guardrails and human‑in‑the‑loop controls where appropriate
- Develop AI‑specific data loss prevention, vector database security, and RAG pipeline controls as the firm's AI footprint grows
Security Automation & DevSecOps
- Integrate security controls into CI/CD pipelines and DevSecOps workflows across the engineering organization
- Build and maintain security automation using Python, PowerShell, and orchestration platforms such as Tines
- Identify and remediate cloud misconfigurations, vulnerability gaps, and exposed resources through automated detection and response workflows
Detection, Monitoring & Incident Response
- Build cloud and AI security monitoring and detection capabilities, integrating telemetry with the firm's SIEM and SOAR platforms
- Participate in incident response, threat modeling, and security investigations across cloud and AI environments
- Support vulnerability management programs and contribute to security investigations as needed
Compliance, Documentation & Stakeholder Partnership
- Support regulatory, audit, and risk requirements applicable to a global financial‑services organization, translating technical controls into documentation that auditors and risk teams can actually use
- Produce clear architecture documentation, security standards, procedures, and remediation plans
- Communicate findings, risks, and recommendations to both highly technical peers and senior non‑technical stakeholders, without losing precision in either direction
Compensation
- Base salary: $180,000 to $190,000
- Total compensation includes a bonus component, consistent with financial‑services norms for a role at this level
Why EqualAccess
EqualAccess partners with best‑in‑class organizations and supports candidates beyond placement. Every candidate we place receives 3 months of post‑hire coaching and career support, ensuring long‑term success and growth.