Cybersecurity AI Engineer III

American Credit Acceptance, LLC

Spartanburg (SC)

On-site

USD 120,000 - 170,000

Full time

13 days ago
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Restaurant d'entreprise

Job summary

American Credit Acceptance, LLC is seeking a Cybersecurity AI Engineer III to build and operate secure AI-enabled automations and agentic workflows within established cybersecurity and AI platform architectures. You will partner across Security Operations, IAM, Cloud Security, and risk teams to accelerate AI adoption while upholding engineering standards and audit requirements.

In this mid-level role you will implement bounded AI workflows, integration patterns, secure SDLC practices, and

Qualifications

  • 3–5 years in cybersecurity engineering or related field.
  • Build automation and integrations using Python, REST APIs/SDKs, CI/CD, and IaC.
  • Knowledge of GenAI concepts: LLMs, tool calling, RAG, embeddings.
  • Strong security fundamentals across IAM, cloud security, and incident response.
  • Ability to communicate risks and design tradeoffs to engineers and auditors.

Responsibilities

  • Build, test, deploy, and operate AI-powered cybersecurity workflows.
  • Create reusable APIs, connectors, and integrations to connect AI models to platforms.
  • Enforce least privilege, secrets protection, audit logging, and secure data handling.
  • Embed AI security into SDLC, CI/CD, and release governance.
  • Support risk, architecture, and compliance stakeholders with evidence and controls.

Skills

Cybersecurity engineering
Python automation
GenAI concepts
IAM and Cloud Security
Communication to stakeholders

Tools

REST APIs/SDKs
CI/CD
IaC
Kubernetes

Job description

Description

Cybersecurity AI Engineer III

Department: Information Security

Role Type: Engineering - Individual Contributor

Reports To: Director of Information Security

Level: Mid-level

Position Summary

The Cybersecurity AI Engineer III is a hands‑on engineering role responsible for building and operating secure AI‑enabled automations, agentic workflows, integrations, orchestration services, and reusable components within established cybersecurity and AI platform architectures. The role partners across Security Operations, IAM, Application and Cloud Security, Vulnerability Management, GRC, Data Security, Threat Intelligence, Enterprise Architecture, AI/ML platforms, software engineering, and model/technology risk. This role enables accelerated AI adoption while applying established engineering standards, trust boundaries, resilience requirements, and evidence expectations for a financial institution.

AI Automation, Agentic Workflows & Integration
  • Build, test, deploy, and operate bounded AI/agentic cybersecurity workflows for triage, enrichment, investigation support, control validation, evidence collection, remediation coordination, and analyst decision support using established architecture, design patterns, deterministic logic, workflow engines, LLMs, tool calling, RAG, and event‑driven orchestration as appropriate.
  • Build and maintain reusable APIs, connectors, agent tools, plugins, event integrations, data transformations, and orchestration components for assigned use cases that securely connect approved models and agents to cybersecurity and developer platforms.
  • Apply established machine-to-machine and agent-to-tool patterns using least privilege, workload identity, short‑lived credentials, scoped tokens, secrets protection, policy enforcement, network controls, encryption, versioned interfaces, comprehensive audit logging, and governed data handling/lineage.
AI-Powered Secure SDLC
  • Embed AI‑assisted security into developer workflows, IDE/coding‑assistant ecosystems, source control, engineering portals, and CI/CD to support secure design, threat modeling, code/configuration review, dependency and vulnerability triage, policy‑as‑code, remediation guidance, test generation, evidence capture, and release‑risk summarization.
  • Implement and maintain approved controls for AI coding agents and autonomous development workflows, including repository permissions, branch protection, code‑owner approvals, sandboxing, tool allowlists, secrets protection, artifact provenance, test gates, deployment authorization, and secure‑by‑default patterns for AI‑generated code, infrastructure‑as‑code, tests, and agent‑initiated changes.
AI Security, Trust, Reliability & Operations
  • Implement and maintain approved guardrails for prompt/indirect prompt injection, unsafe tool use, excessive agency, sensitive‑data leakage, retrieval poisoning, insecure output handling, unauthorized cross‑system actions, and model/tool misuse. Apply established patterns for agent identity, authorization, trust boundaries, context/memory controls, secure retrieval, transaction‑level auditability, approval gates, segregation of duties, execution limits, rollback, fallback, and kill‑switch mechanisms; **escalate** new or material design decisions to senior engineers or security architects.
  • Build and operate evaluation and red‑team harnesses for jailbreaks, adversarial inputs, unsafe actions, hallucinated evidence, privilege escalation, exfiltration, and control bypass; implement approved model/agent routing and policy rules based on data sensitivity, use‑case risk, geography, business context, and approved AI services.
  • Instrument services with metrics, traces, logs, decision/tool‑call histories, latency, cost/token usage, quality/error measures, approval outcomes, policy violations, abnormal behavior, and integration health. Apply production engineering rigor including source control, automated testing, IaC, release pipelines, environment separation, SLOs, runbooks, rollback, and incident response.
Governance, Risk & Measurable Outcomes
  • Support senior engineers, architects, cybersecurity risk, technology/model risk, privacy, legal, compliance, records management, and audit in implementing technical controls derived from policy and maintaining architecture diagrams, data flows, threat models, control mappings, test evidence, operating procedures, risk assessments, exception/residual‑risk records, and evidence supporting financial‑services expectations for access, change, resilience, logging, data protection, third‑party risk, and software supply chain.
  • Implement approved autonomous‑action tiers from recommendation‑only through approval‑required and narrowly scoped autonomous execution. Measure and improve precision/recall, analyst trust, time saved, control friction, MTTD/MTTR/remediation time, and operating cost; contribute reusable components and patterns where appropriate.
Required Qualifications
  • 3-5 years of experience in cybersecurity engineering, security automation, platform engineering, DevSecOps, software engineering, or a closely related technical discipline with hands‑on delivery responsibility.
  • Demonstrated ability to build production automation and integrations using Python and/or another modern language, REST APIs/SDKs, webhooks, queues/topics or event‑driven architectures, CI/CD, infrastructure‑as‑code, service identities, secrets, and policy controls.
  • Working knowledge of modern GenAI concepts including LLMs, tool/function calling, agents, RAG, embeddings, context management, evaluation, prompt‑injection risk, and AI observability.
  • Strong security engineering fundamentals across IAM/least privilege, application and cloud security, secure software delivery, secrets management, logging/monitoring, network trust boundaries, and incident response; experience applying automated testing, code review, versioning, dependency management, deployment pipelines, and production support.
  • Ability to communicate implementation approaches, technical risks, design tradeoffs, and control implications to engineers, security leaders, risk stakeholders, and auditors, with support from senior technical staff for material architecture decisions.
Preferred Qualifications
  • Experience building or operating agentic AI systems, orchestration frameworks, enterprise AI gateways/model‑routing layers, or agent tool ecosystems, including AI‑enabled SDLC environments, coding assistants, autonomous coding agents, AI‑generated code, or AI‑assisted CI/CD.
  • Experience in banking, payments, insurance, capital markets, fintech, or another highly regulated environment with strong technology, risks and audit expectations.
  • Familiarity with NIST CSF, NIST AI RMF, NIST SSDF, OWASP guidance for LLM/GenAI applications, MITRE ATTCK, and relevant financial‑services control frameworks.
  • Experience with containers/Kubernetes, cloud‑native or serverless services, API gateways, secrets vaults, policy‑as‑code, and modern observability platforms.
Core Competencies & Operating Principles
  • Builder Mindset - Translates architecture and threat‑modeling requirements into code, APIs, deployment, telemetry, and reliable day‑to‑day operations.
  • Security judgment - Applies established security standards and uses sound judgment within assigned scope; recognizes when material risks or design decisions require escalation.
  • Systems Thinking – Understands how assigned workflows interact across identity, data, applications, models, tools, networks, and human decision points, and incorporates established architectural and security requirements into implementation.
  • Control By Design – Implements established requirements for auditability, evidence, least privilege, resilience, policy enforcement, and decisioning/tool calls in assigned solutions.
  • Pragmatic Outcomes – Prioritizes measurable risk reduction, response‑time improvement, reduced toil/control friction, reusable patterns, and sustainable operating cost over novelty.
  • Continuous Evaluation – Tests AI‑enabled controls continuously for quality, safety, drift, abuse resistance, and operational value while partnering effectively across engineering, cybersecurity, architecture, risk, and business teams.

Please note this job description is not designed to cover or contain a comprehensive listing of activities, duties or responsibilities that are required of the employee for this job. Duties, responsibilities and activities may change at any time with or without notice.

EEO Statement ACA provides equal employment opportunities (EEO) to all applicants for employment without regard to race, color, religion, gender, sexual orientation, gender identity or expression, national origin, age, disability, genetic information, marital status, amnesty, or status as a covered veteran in accordance with applicable federal, state and local laws. ACA complies with applicable state and local laws governing non‑discrimination in employment in every location in which the company has facilities.

California Privacy Notice

As an employer of California residents, we are dedicated to protecting your privacy rights. Any personal information you provide during the application process will be used solely for permitted internal purposes and will be handled in accordance with applicable privacy laws. By applying to this position, you consent to the collection, use, and disclosure of your personal information as described in our Employee Privacy Notice.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity AI Engineer III
Cybersecurity AI Engineer III

American Credit Acceptance • Spartanburg (SC)

On-site
USD 120,000 - 160,000
AI Cyber Engineer
AI Cyber Engineer

Ampcus Inc • Chantilly (VA)

On-site
USD 120,000 - 160,000
Security Operations AI Engineer, Contract
Security Operations AI Engineer, Contract

Talanto • Northern (KY)

Hybrid
USD 120,000 - 150,000
Applied AI Engineer, Cyber
Applied AI Engineer, Cyber

OpenAI • New York (NY)

On-site
USD 150,000 - 230,000
Relocation support
AI Automation Engineering - Security Operations
AI Automation Engineering - Security Operations

CEI • Philadelphia, Northern (KY)

Hybrid
USD 115,000 - 123,000
Principal AI Security Engineer
Principal AI Security Engineer

Capitolis • Atlanta (GA)

Hybrid
USD 120,000 - 150,000
Applied AI Engineer, Cyber
Applied AI Engineer, Cyber

OpenAI • San Francisco (CA)

On-site
USD 180,000 - 240,000
AI Security Analyst-- BHADC5698041
AI Security Analyst-- BHADC5698041

Compunnel Inc. • United States

On-site
USD 70,000 - 90,000
AI-Application Security Engineer
AI-Application Security Engineer

Stifel Financial Corp. • St. Louis (MO)

On-site
USD 90,000 - 120,000
AI Deployment Engineer, Cyber
AI Deployment Engineer, Cyber

Neura Market • San Francisco (CA)

On-site
USD 150,000 - 230,000
Relocation support