Lead AI Security Engineer

Truist

Charlotte (NC)

On-site

USD 180,000 - 280,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical Insurance
401k
Paid time off

Job summary

Truist Financial Corporation is seeking a Lead AI Security Engineer to design and implement security controls for AI-enabled applications, agents, and delivery pipelines across the full lifecycle.

You will partner with product, engineering, platform, data, risk, and security teams to translate AI security requirements into practical guardrails, monitoring, and deployment gates, ensuring safe, traceable, resilient, and governed enterprise AI capabilities.

Qualifications

  • Bachelor’s degree or equivalent education, training, and work-related experience.
  • Minimum of 10 years of experience in security engineering or related cybersecurity roles.
  • Deep specialized knowledge in cybersecurity principles, theories, and concepts.
  • Extensive experience in software development lifecycle security practices.
  • Expertise in threat modeling, security testing, and penetration testing.
  • Proven experience implementing and managing complex information security technologies.

Responsibilities

  • Lead design and implementation of security controls for AI-enabled apps, agents, model integrations, orchestration layers, and AI delivery pipelines.
  • Perform AI threat modeling across prompts, context windows, retrieval flows, tools, APIs, permissions, memory, model access, data movement, and runtime execution paths.
  • Implement and validate guardrails for prompt-injection resistance, unsafe output handling, tool-use abuse, sensitive data exposure, privilege escalation, model misuse, and policy-violating behavior.
  • Build and maintain monitoring, alerting, and detection logic for AI systems, including anomalous prompts, abnormal agent actions, suspicious tool invocation, unsafe model responses, and control degradation.
  • Embed security requirements into AI design reviews, acceptance criteria, validation plans, CI/CD or LLMOps workflows, model or prompt change controls, and release-readiness gates.
  • Validate that AI solutions meet required security, governance, traceability, and evidence standards before release and continue to meet them after deployment.
  • Support AI-related incident investigation, root-cause analysis, remediation planning, and operational response for suspicious behavior, control failures, data exposure, or unsafe system outcomes.
  • Maintain control documentation, implementation guidance, runbooks, validation evidence, engineering patterns, and operating procedures for AI security engineering activities.
  • Continuously improve AI security automation, validation workflows, detection content, guardrail logic, and deployment controls as models, agents, workflows, and attack techniques evolve.

Skills

Security engineering
Threat modeling
Penetration testing
Cloud security
AI security
CI/CD security
LLMOps
Incident response
Documentation

Education

Bachelor’s degree or equivalent

Tools

Azure/Azure AI

Job description

Regular or Temporary

Regular

Language Fluency

English (Required)

Work Shift

1st shift (United States of America)

Please review the following job description
  • The Lead AI Security Engineer is a senior hands-on security engineer responsible for designing, implementing, and advancing controls that protect AI-enabled applications, agentic workloads, model integrations, and AI delivery pipelines across the full software and AI lifecycle.
  • This role focuses on securing agent behavior, prompt and context flows, tool invocation, data access, model interaction, pipeline integrity, runtime execution, observability, and deployment readiness in a regulated enterprise environment.
  • The engineer leads implementation of AI-specific security patterns including prompt-injection defenses, guardrails, output filtering, secure tool-use boundaries, identity and permission controls, evidence capture, logging, monitoring, and detection content for AI-enabled systems.
  • The work spans architecture review, threat modeling, adversarial test readiness, control validation, automation, detection engineering, deployment gating, production monitoring, and incident response support for AI and agentic solutions.
  • Daily work includes partnering with product, engineering, platform, data, risk, and security teams to translate AI security requirements into implementable controls that enable safe, traceable, resilient, and governed deployment of enterprise AI capabilities.
Essential Duties And Responsibilities
  • Lead the design and implementation of security controls for AI-enabled applications, agents, model integrations, orchestration layers, and AI delivery pipelines.
  • Perform AI and agentic threat modeling across prompts, context windows, retrieval flows, tools, APIs, permissions, memory, model access, data movement, and runtime execution paths.
  • Implement and validate guardrails for prompt-injection resistance, unsafe output handling, tool-use abuse, sensitive data exposure, privilege escalation, model misuse, and policy-violating behavior.
  • Build and maintain monitoring, alerting, and detection logic for AI systems, including anomalous prompts, abnormal agent actions, suspicious tool invocation, unsafe model responses, and control degradation.
  • Embed security requirements into AI design reviews, acceptance criteria, validation plans, CI/CD or LLMOps workflows, model or prompt change controls, and release-readiness gates.
  • Validate that AI solutions meet required security, governance, traceability, and evidence standards before release and continue to meet them after deployment.
  • Support AI-related incident investigation, root-cause analysis, remediation planning, and operational response for suspicious behavior, control failures, data exposure, or unsafe system outcomes.
  • Maintain control documentation, implementation guidance, runbooks, validation evidence, engineering patterns, and operating procedures for AI security engineering activities.
  • Continuously improve AI security automation, validation workflows, detection content, guardrail logic, and deployment controls as models, agents, workflows, and attack techniques evolve.
Required Qualifications
  • Bachelor’s degree or equivalent education, training, and work-related experience.
  • Minimum of 10 years of experience in security engineering or related cybersecurity roles.
  • Deep specialized knowledge in cybersecurity principles, theories, and concepts.
  • Extensive experience in software development lifecycle security practices.
  • Expertise in threat modeling, security testing, and penetration testing.
  • Proven experience implementing and managing complex information security technologies.
Additional Requirements
  • Minimum of 10 years of experience in security engineering, application security, product security, cloud security, cybersecurity operations, or related technical cybersecurity roles.
  • Demonstrated experience leading complex security engineering efforts across modern software, API, cloud-native, automation, or platform environments.
  • Strong understanding of AI, LLM, or agentic security risks, including prompt injection, insecure tool use, data exposure, model misuse, pipeline compromise, and unsafe output handling.
  • Experience with threat modeling, security testing, control validation, detection engineering, logging, monitoring, or incident response for production systems.
  • Ability to translate security requirements into implementable engineering controls, validation criteria, deployment gates, documentation, and operational runbooks.
  • 3+ years of experience in a lead security engineering, application security, AI security, cybersecurity operations, or closely related technical discipline.
  • Hands-on experience implementing controls for enterprise software, APIs, cloud-native services, workflow automation, model integrations, or agentic applications.
  • Working knowledge of LLM and agentic security concepts such as prompt injection, indirect prompt injection, insecure tool use, excessive agency, sensitive data exposure, model misuse, and control boundary enforcement.
  • Experience securing CI/CD, DevSecOps, MLOps, LLMOps, model, prompt, or configuration-change pipelines through validation, approvals, evidence capture, and release controls.
  • Experience with telemetry, logging, alerting, monitoring, or detection content for identifying suspicious, anomalous, or policy-violating behavior in applications or AI workflows.
  • Understanding of identity, access control, secrets handling, least privilege, secure integration design, API protections, sandboxing, and environment-based deployment controls.
  • Ability to partner with engineering teams to convert AI security risks into practical guardrails, tests, detections, monitoring requirements, and deployment-readiness controls.
  • Strong written documentation and communication skills, especially for control designs, validation results, remediation evidence, technical guidance, and audit-ready operating procedures.
Preferred Qualifications
  • Experience securing AI agents, autonomous workflows, tool-calling systems, retrieval-augmented generation patterns, or LLM-enabled enterprise applications.
  • Experience with Microsoft, Azure, Copilot, Copilot Studio, Azure AI, or other enterprise AI and automation platforms.
  • Familiarity with AI security guidance and frameworks such as OWASP LLM risks, OWASP agentic application risks, NIST AI RMF, MITRE ATLAS, or related industry practices.
  • Experience with adversarial testing, AI red teaming support, misuse-case validation, model or prompt evaluation, or safety monitoring for AI-enabled systems.
  • Experience in financial services, cybersecurity, regulated enterprise environments, or platforms with high audit, risk, privacy, and control expectations.
  • Working knowledge of secure tool-calling patterns, API protections, prompt and model change validation, runtime traceability, and observability for AI systems.
General Description of Available Benefits for Eligible Employees of Truist Financial Corporation

All regular teammates (not temporary or contingent workers) working 20 hours or more per week are eligible for benefits, though eligibility for specific benefits may be determined by the division of Truist offering the position. Truist offers medical, dental, vision, life insurance, disability, accidental death and dismemberment, tax-preferred savings accounts, and a 401k plan to teammates. Teammates also receive no less than 10 days of vacation (prorated based on date of hire and by full-time or part-time status) during their first year of employment, along with 10 sick days (also prorated), and paid holidays. For more details on Truist’s generous benefit plans, please visit our Benefits site. Depending on the position and division, this job may also be eligible for Truist’s defined benefit pension plan, restricted stock units, and/or a deferred compensation plan. As you advance through the hiring process, you will also learn more about the specific benefits available for any non-temporary position for which you apply, based on full-time or part-time status, position, and division of work.

Truist is an Equal Opportunity Employer that does not discriminate on the basis of race, gender, color, religion, citizenship or national origin, age, sexual orientation, gender identity, disability, veteran status, or other classification protected by law. Truist is a Drug Free Workplace.

EEO is the Law E-Verify IER Right to Work

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior AI Security Engineer
Senior AI Security Engineer

Truist • Atlanta (GA)

On-site
USD 150,000 - 190,000
Medical insurance
Dental insurance
Vision insurance
+3
Head of AI Enablement - Truist Protection Services
Head of AI Enablement - Truist Protection Services

Truist Financial • Charlotte (NC)

On-site
USD 200,000 - 320,000
Medical, dental, vision insurance
401(k) plan
Paid vacation and sick days
Development, AI Delivery Lead
Development, AI Delivery Lead

Truist • Town of Charlotte (NY)

On-site
USD 180,000 - 260,000
Senior AI Platform Engineer (Data and Analytics Cloud Engineer)
Senior AI Platform Engineer (Data and Analytics Cloud Engineer)

Truist • Charlotte (NC)

On-site
USD 100,000 - 130,000
Medical insurance
Dental insurance
Vision insurance
+2
Senior AI & Data Consultant- Data Governance
Senior AI & Data Consultant- Data Governance

Fayette Chamber of Commerce • Atlanta (GA)

On-site
USD 130,000 - 190,000
Medical insurance
Dental insurance
Vision insurance
+4
AI Readiness/Embedded Governance Strategy Lead
AI Readiness/Embedded Governance Strategy Lead

Truist • Charlotte (NC)

On-site
USD 140,000 - 190,000
Medical, dental, vision
401k plan
Paid vacation and sick days
+1
Security Engineer
Security Engineer

Truist • Atlanta (GA)

On-site
USD 120,000 - 160,000
Health insurance
Dental insurance
Vision insurance
+5
Senior AI Agentic Engineer
Senior AI Agentic Engineer

Truist • Charlotte (NC)

On-site
USD 140,000 - 175,000
Medical insurance
Dental insurance
Vision insurance
+3
Security Engineering Senior Manager - IAM AuthN Automation
Security Engineering Senior Manager - IAM AuthN Automation

Information Technology Senior Management Forum • Atlanta (GA)

On-site
USD 140,000 - 190,000
Senior Director Data Governance and Legacy Data Patforms
Senior Director Data Governance and Legacy Data Patforms

Truist • Raleigh (NC)

On-site
USD 180,000 - 270,000
Medical Insurance
Dental Insurance
Vision Insurance
+7