Cybersecurity AI Engineer III

American Credit Acceptance

Spartanburg (SC)

On-site

USD 120,000 - 160,000

Full time

2 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

American Credit Acceptance in Spartanburg, SC, seeks a Cybersecurity AI Engineer III to build and operate secure AI-enabled automations within our cybersecurity and AI platform architectures. This hands-on role collaborates across Security Operations, IAM, Application and Cloud Security, and Risk teams to accelerate AI adoption while upholding engineering standards.

You will design bounded AI workflows, APIs, and integrations, implement guardrails for security and governance, and contribute

Qualifications

  • 3-5 years of experience in cybersecurity engineering or related field.
  • Experience building automation using Python and REST APIs/SDKs.
  • Working knowledge of GenAI concepts including LLMs, tool calling, agents and RAG.
  • Strong security engineering fundamentals across IAM, cloud security, logging/monitoring, and incident response.
  • Ability to communicate risks, design tradeoffs, and control implications to engineers and risk stakeholders.

Responsibilities

  • Build and operate bounded AI/agentic cybersecurity workflows for triage, enrichment, investigation support, control validation, evidence collection, remediation coordination, and analyst decision support.
  • Develop reusable APIs, connectors, agent tools, plugins, event integrations, data transformations, and orchestration components to securely connect models and agents to cybersecurity and developer platforms.
  • Apply least privilege, secrets protection, policy enforcement, audit logging, and governed data handling across workflows.

Skills

Python
REST APIs/SDKs
CI/CD
Infrastructure-as-code
Secrets management
Auditing/logging
LLMs / GenAI concepts
Communication

Tools

Kubernetes

Job description

Description
Cybersecurity AI Engineer III
Department

Information Security

Role Type

Engineering - Individual Contributor

Reports To

Director of Information Security

Level

Mid-level

Position Summary

The Cybersecurity AI Engineer III is a hands-on engineering role responsible for building and operating secure AI-enabled automations, agentic workflows, integrations, orchestration services, and reusable components within established cybersecurity and AI platform architectures. The role partners across Security Operations, IAM, Application and Cloud Security, Vulnerability Management, GRC, Data Security, Threat Intelligence, Enterprise Architecture, AI/ML platforms, software engineering, and model/technology risk. This role enables accelerated AI adoption while applying established engineering standards, trust boundaries, resilience requirements, and evidence expectations for a financial institution.

Key Responsibilities: AI Automation, Agentic Workflows & Integration
  • Build, test, deploy, and operate bounded AI/agentic cybersecurity workflows for triage, enrichment, investigation support, control validation, evidence collection, remediation coordination, and analyst decision support using established architecture, design patterns, deterministic logic, workflow engines, LLMs, tool calling, RAG, and event-driven orchestration as appropriate.
  • Build and maintain reusable APIs, connectors, agent tools, plugins, event integrations, data transformations, and orchestration components for assigned use cases that securely connect approved models and agents to cybersecurity and developer platforms.
  • Apply established machine-to-machine and agent-to-tool patterns using least privilege, workload identity, short-lived credentials, scoped tokens, secrets protection, policy enforcement, network controls, encryption, versioned interfaces, comprehensive audit logging, and governed data handling/lineage.
AI-Powered Secure SDLC
  • Embed AI-assisted security into developer workflows, IDE/coding-assistant ecosystems, source control, engineering portals, and CI/CD to support secure design, threat modeling, code/configuration review, dependency and vulnerability triage, policy-as-code, remediation guidance, test generation, evidence capture, and release-risk summarization.
  • Implement and maintain approved controls for AI coding agents and autonomous development workflows, including repository permissions, branch protection, code-owner approvals, sandboxing, tool allowlists, secrets protection, artifact provenance, test gates, deployment authorization, and secure-by-default patterns for AI-generated code, infrastructure-as-code, tests, and agent-initiated changes.
AI Security, Trust, Reliability & Operations
  • Implement and maintain approved guardrails for prompt/indirect prompt injection, unsafe tool use, excessive agency, sensitive-data leakage, retrieval poisoning, insecure output handling, unauthorized cross-system actions, and model/tool misuse. Apply established patterns for agent identity, authorization, trust boundaries, context/memory controls, secure retrieval, transaction-level auditability, approval gates, segregation of duties, execution limits, rollback, fallback, and kill-switch mechanisms; elevate new or material design decisions to senior engineers or security architects.
  • Build and operate evaluation and red-team harnesses for jailbreaks, adversarial inputs, unsafe actions, hallucinated evidence, privilege escalation, exfiltration, and control bypass; implement approved model/agent routing and policy rules based on data sensitivity, use-case risk, geography, business context, and approved AI services.
  • Instrument services with metrics, traces, logs, decision/tool-call histories, latency, cost/token usage, quality/error measures, approval outcomes, policy violations, abnormal behavior, and integration health. Apply production engineering rigor including source control, automated testing, IaC, release pipelines, environment separation, SLOs, runbooks, rollback, and incident response.
Governance, Risk & Measurable Outcomes
  • Support senior engineers, architects, cybersecurity risk, technology/model risk, privacy, legal, compliance, records management, and audit in implementing technical controls derived from policy and maintaining architecture diagrams, data flows, threat models, control mappings, test evidence, operating procedures, risk assessments, exception/residual-risk records, and evidence supporting financial-services expectations for access, change, resilience, logging, data protection, third-party risk, and software supply chain.
  • Implement approved autonomous-action tiers from recommendation-only through approval-required and narrowly scoped autonomous execution. Measure and improve precision/recall, analyst trust, time saved, control friction, MTTD/MTTR/remediation time, and operating cost; contribute reusable components and patterns where appropriate.
Required Qualifications
  • 3-5 years of experience in cybersecurity engineering, security automation, platform engineering, DevSecOps, software engineering, or a closely related technical discipline with hands-on delivery responsibility.
  • Demonstrated ability to build production automation and integrations using Python and/or another modern language, REST APIs/SDKs, webhooks, queues/topics or event-driven architectures, CI/CD, infrastructure-as-code, service identities, secrets, and policy controls.
  • Working knowledge of modern GenAI concepts including LLMs, tool/function calling, agents, RAG, embeddings, context management, evaluation, prompt-injection risk, and AI observability.
  • Strong security engineering fundamentals across IAM/least privilege, application and cloud security, secure software delivery, secrets management, logging/monitoring, network trust boundaries, and incident response; experience applying automated testing, code review, versioning, dependency management, deployment pipelines, and production support.
  • Ability to communicate implementation approaches, technical risks, design tradeoffs, and control implications to engineers, security leaders, risk stakeholders, and auditors, with support from senior technical staff for material architecture decisions.
Preferred Qualifications
  • Experience building or operating agentic AI systems, orchestration frameworks, enterprise AI gateways/model-routing layers, or agent tool ecosystems, including AI-enabled SDLC environments, coding assistants, autonomous coding agents, AI-generated code, or AI-assisted CI/CD.
  • Experience in banking, payments, insurance, capital markets, fintech, or another highly regulated environment with strong technology, risks and audit expectations.
  • Familiarity with NIST CSF, NIST AI RMF, NIST SSDF, OWASP guidance for LLM/GenAI applications, MITRE ATT&CK, and relevant financial-services control frameworks.
  • Experience with containers/Kubernetes, cloud-native or serverless services, API gateways, secrets vaults, policy-as-code, and modern observability platforms.
Core Competencies & Operating Principles
  • Builder Mindset - Translates architecture and threat-modeling requirements into code, APIs, deployment, telemetry, and reliable day-to-day operations.
  • Security judgment - Applies established security standards and uses sound judgment within assigned scope; recognizes when material risks or design decisions require escalation.
  • Systems Thinking – Understands how assigned workflows interact across identity, data, applications, models, tools, networks, and human decision points, and incorporates established architectural and security requirements into implementation.
  • Control By Design – Implements established requirements for auditability, evidence, least privilege, resilience, policy enforcement, and decisioning/tool calls in assigned solutions.
  • Pragmatic Outcomes – Prioritizes measurable risk reduction, response-time improvement, reduced toil/control friction, reusable patterns, and sustainable operating cost over novelty.
  • Continuous Evaluation – Tests AI-enabled controls continuously for quality, safety, drift, abuse resistance, and operational value while partnering effectively across engineering, cybersecurity, architecture, risk, and business teams.

Please note this job description is not designed to cover or contain a comprehensive listing of activities, duties or responsibilities that are required of the employee for this job. Duties, responsibilities and activities may change at any time with or without notice.

EEO StatementACA provides equal employment opportunities (EEO) to all applicants for employment without regard to race, color, religion, gender, sexual orientation, gender identity or expression, national origin, age, disability, genetic information, marital status, amnesty, or status as a covered veteran in accordance with applicable federal, state and local laws. ACA complies with applicable state and local laws governing non-discrimination in employment in every location in which the company has facilities.

California Privacy Notice As an employer of California residents, we are dedicated to protecting your privacy rights. Any personal information you provide during the application process will be used solely for permitted internal purposes and will be handled in accordance with applicable privacy laws. By applying to this position, you consent to the collection, use, and disclosure of your personal information as described in our Employee Privacy Notice.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Applied AI Engineer, Cyber
Applied AI Engineer, Cyber

OpenAI • San Francisco (CA)

On-site
USD 180,000 - 240,000
Applied AI Engineer, Cyber
Applied AI Engineer, Cyber

OpenAI • New York (NY)

On-site
USD 150,000 - 230,000
Relocation support
AI Cyber Engineer
AI Cyber Engineer

Ampcus Inc • Chantilly (VA)

On-site
USD 120,000 - 160,000
AI Deployment Engineer, Cyber
AI Deployment Engineer, Cyber

Neura Market • San Francisco (CA)

On-site
USD 150,000 - 230,000
Relocation support
AI Security Analyst-- BHADC5698041
AI Security Analyst-- BHADC5698041

Compunnel Inc. • United States

On-site
USD 70,000 - 90,000
Principal AI Security Engineer
Principal AI Security Engineer

Capitolis • Atlanta (GA)

Hybrid
USD 120,000 - 150,000
AI Deployment Engineer, Cyber
AI Deployment Engineer, Cyber

OpenAI • San Francisco (CA)

On-site
USD 120,000 - 160,000
Artificial Intelligence Engineer
Artificial Intelligence Engineer

Synergy Business Consulting, Inc. • Town of Florida (NY)

On-site
USD 120,000 - 180,000
AI-Application Security Engineer
AI-Application Security Engineer

Stifel Financial Corp. • St. Louis (MO)

On-site
USD 90,000 - 120,000
Senior AI Engineer, Security Infrastructure
Senior AI Engineer, Security Infrastructure

artificial intelligence and robotics laboratory (itu air lab) • Arlington (VA)

Hybrid
USD 170,000 - 210,000