Dereck Davis - Senior AI Security Engineer (Artificial Intelligence Security Posture Management (AiSPM)

Truist Financial

Charlotte (NC)

On-site

USD 140,000 - 170,000

Full time

6 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical insurance
Dental coverage
Vision care
Life insurance
Disability
AD&D insurance
Tax-advantaged accounts
401k plan
Vacation days
Sick days
Paid holidays
Pension plan
RSUs
Deferred compensation

Job summary

Truist Financial in the Atlanta or Charlotte offices is seeking a Senior AI Security Engineer to identify and reduce AI-related security risk across approved, emerging, and unapproved AI usage patterns. You will use CrowdStrike, Wiz, Zscaler, and governance workflows to analyze AI exposure, validate ownership, support remediation, and maintain audit-ready evidence.

Strong candidates will translate complex AI risks into clear actions for engineering, security, and governance teams, helping

Qualifications

  • Bachelor's degree or equivalent education, training, and work-related experience.
  • Minimum of 7 years of experience in security engineering or related cybersecurity roles.
  • Deep specialized knowledge in cybersecurity principles, theories, and concepts.
  • Proven experience in software development lifecycle security practices.
  • Deep knowledge of threat modeling, security testing, and penetration testing.
  • Experience implementing and managing complex information security technologies.

Responsibilities

  • Identify, evaluate, document, and reduce security risk from enterprise AI usage.
  • Investigate Shadow AI observations using CrowdStrike, Wiz, and Zscaler.
  • Perform AI Security Reviews for proposed or existing AI use cases.
  • Partner with engineering, security, and business teams to confirm AI ownership and controls.
  • Document review evidence, risk gaps, and action items for audit-ready governance.
  • Analyze telemetry and inventories to identify AI usage trends and risks.
  • Develop and refine AI security review procedures and playbooks.
  • Escalate high-risk AI observations to Security Operations and risk stakeholders.
  • Communicate findings in plain language to stakeholders.
  • Stay aware of emerging AI security risks and tooling to improve AiSPM.

Skills

AI security
Cloud security
Threat modeling
Security governance
Penetration testing
Secure SDLC
Python/PowerShell

Education

Bachelor's degree

Tools

CrowdStrike
Wiz
Zscaler

Job description

Please review the following job description:

This role is 5 days a week in the Atlanta or Charlotte Office

Regular or Temporary:

Regular

Language Fluency: English (Required)

Work Shift: 1st shift (United States of America)

The Artificial Intelligence Security Posture Management (AiSPM) function supports two core areas: Shadow Artificial Intelligence (Shadow AI) risk reduction and AI Security Review/Governance for enterprise AI use cases.

This Senior AI Security Engineer will help identify, evaluate, document, and reduce AI-related security risk across approved, emerging, and unapproved AI usage patterns.

The role uses security and governance tooling such as CrowdStrike, Wiz, Zscaler, and supporting enterprise workflows to analyze AI exposure, validate ownership, support remediation, and maintain repeatable review evidence.

Strong candidates will understand cloud security, software security, data protection, security governance, and enterprise risk management, with the ability to translate technical AI risks into clear actions for engineering, security, and .

ESSENTIAL DUTIES AND RESPONSIBILITIES
  • Supports the Artificial Intelligence Security Posture Management function by identifying, evaluating, documenting, and reducing security risk associated with enterprise AI usage.

  • Investigates Shadow Artificial Intelligence observations from tools such as CrowdStrike, Wiz, and Zscaler, validating usage context, ownership, business purpose, and potential exposure.

  • Performs AI Security Reviews for proposed or existing AI use cases, reviewing intake details, data sensitivity, model or service interactions, control coverage, and residual risk.

  • Partners with application, infrastructure, business, and security teams to confirm AI asset ownership, assess risk, identify required controls, and track remediation or governance outcomes.

  • Documents review evidence, risk gaps, action items, and decision rationale in a clear, repeatable, and audit-ready manner aligned to established security guidance and governance processes.

  • Analyzes telemetry, alerts, inventories, and workflow records to identify trends in AI usage, prioritize risk reduction, and support executive or operational reporting.

  • Contributes to the development and refinement of AI security review procedures, intake checklists, escalation paths, knowledge articles, and operational playbooks.

  • Supports escalation of higher-risk AI observations to appropriate security partners, including Security Operations Center teams, incident response partners, and risk or governance stakeholders when warranted.

  • Communicates technical and governance findings in plain language, helping stakeholders understand AI risk, required controls, remediation expectations, and approval dependencies.

  • Maintains awareness of emerging AI security risks, detection methods, governance practices, and tooling capabilities to improve the effectiveness of the AiSPM program over time.

Required Qualifications
  • Bachelors degree or equivalent education, training, and work-related experience.

  • Minimum of 7 years of experience in security engineering or related cybersecurity roles.

  • Deep specialized knowledge in cybersecurity principles, theories, and concepts.

  • Proven experience in software development lifecycle security practices.

  • Deep knowledge of threat modeling, security testing, and penetration testing.

  • Experience implementing and managing complex information security technologies.

Preferred Qualifications
  • Working knowledge of AI security, cloud security, data protection, and governance frameworks, including:

    • National Institute of Standards and Technology Artificial Intelligence Risk Management Framework (NIST AI RMF)

    • National Institute of Standards and Technology Special Publication 800-53 (NIST SP 800-53)

    • Open Worldwide Application Security Project Machine Learning Top 10 (OWASP ML Top 10)

    • Open Worldwide Application Security Project Large Language Model Top 10 (OWASP LLM Top 10)

    • Federal Financial Institutions Examination Council (FFIEC) guidance applicable to regulated financial services environments

    • Cloud Security Alliance guidance related to AI, cloud, and third-party technology risk

  • Experience reviewing AI use cases, machine learning services, large language model applications, or AI-enabled business workflows for security, privacy, governance, or compliance risks.

  • Experience using CrowdStrike, Wiz, Zscaler, or similar security tools to investigate endpoint, cloud, network, software, or SaaS-related risk signals.

  • Experience with security review, risk assessment, exception management, evidence validation, or control mapping in a regulated enterprise environment.

  • Proficiency or familiarity with Python, PowerShell, Structured Query Language (SQL), or similar scripting and analysis methods used to normalize data, support investigations, and improve repeatable reporting.

  • Relevant security certifications such as Certified Information Systems Security Professional (CISSP), Certified Cloud Security Professional (CCSP), Security+, or similar credentials.

  • Experience in financial services, cybersecurity, regulated enterprise environments, or platforms with high audit and control requirements.

  • Familiarity with secure tool-calling patterns, application programming interface (API) protections, model or prompt change validation, and runtime traceability for AI systems.

  • Working knowledge of cloud-native security patterns, telemetry analysis, governance workflows, and deployment gating for modern engineering teams.

General Description of Available Benefits for Eligible Employees of Truist Financial Corporation
  • medical
  • dental
  • vision
  • life insurance
  • disability
  • accidental death and dismemberment
  • tax-preferred savings accounts
  • 401k plan
  • 10 days of vacation (prorated based on date of hire and by full-time or part-time status) during their first year of employment
  • 10 sick days (also prorated)
  • paid holidays
  • Truists defined benefit pension plan
  • restricted stock units
  • deferred compensation plan

As you advance through the hiring process, you will also learn more about the specific benefits available for any non-temporary position for which you apply, based on full-time or part-time status, position, and division of work.

Truist is an Equal Opportunity Employer that does not discriminate on the basis of race, gender, color, religion, citizenship or national origin, age, sexual orientation, gender identity, disability, veteran status, or other classification protected by law. Truist is a Drug Free Workplace.

EEO is the Law E-Verify IER Right to Work

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead AI Security Engineer
Lead AI Security Engineer

Truist • Charlotte (NC)

On-site
USD 180,000 - 280,000
Medical Insurance
401k
Paid time off
Senior AI & Data Consultant- Data Governance
Senior AI & Data Consultant- Data Governance

Fayette Chamber of Commerce • Atlanta (GA)

On-site
USD 130,000 - 190,000
Medical insurance
Dental insurance
Vision insurance
+4
AI & Data Director - Data Lifecycle Management
AI & Data Director - Data Lifecycle Management

Truist • Raleigh (NC)

On-site
USD 180,000 - 240,000
401k plan
Paid time off
AI & Data Director - Data Lifecycle Management
AI & Data Director - Data Lifecycle Management

Truist • Charlotte (NC)

On-site
USD 180,000 - 240,000
Medical insurance
Dental insurance
Vision insurance
+4
Sn. Infrastructure Engineer
Sn. Infrastructure Engineer

Fayette Chamber of Commerce • Atlanta (GA)

On-site
USD 120,000 - 170,000
Medical, dental, vision insurance
401(k) plan
Senior Software Engineer
Senior Software Engineer

Habitat For Humanity Of Durham • Raleigh (NC)

On-site
USD 140,000 - 180,000
Medical, dental, vision
10 vacation days in first year
10 sick days and paid holidays
Senior Director Data Governance and Legacy Data Platforms
Senior Director Data Governance and Legacy Data Platforms

Truist • Atlanta (GA)

On-site
USD 210,000 - 290,000
Medical insurance
Dental insurance
Vision insurance
+2
Senior Director Data Governance and Legacy Data Platforms
Senior Director Data Governance and Legacy Data Platforms

Truist • Charlotte (NC)

On-site
USD 140,000 - 190,000
Medical insurance
Dental insurance
Vision insurance
+3
Wholesale Business Data Steward Manager
Wholesale Business Data Steward Manager

Fayette Chamber of Commerce • Atlanta (GA)

On-site
USD 120,000 - 190,000
Medical
Dental
Vision
+7
Senior Director Data Governance and Legacy Data Platforms
Senior Director Data Governance and Legacy Data Platforms

Truist • Raleigh (NC)

On-site
USD 180,000 - 270,000
Medical Insurance
Dental Insurance
Vision Insurance
+7