Lead Information Security Engineer

Envestnet

Berwyn (PA)

Hybrid

USD 139,000 - 173,000

Full time

3 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical insurance
PTO
401k match
Parental leave
Education reimbursement
Disability coverage
Wellness support

Job summary

Envestnet is seeking an experienced Information Security Engineer to shape the security posture of our AI-enabled wealth tech platforms. You’ll assess risks across cloud and on-prem environments, integrate automated controls, and guide cross-functional teams on AI governance and model security.

Collaboration with product and security stakeholders will be essential to ensure resilient, scalable defenses. The role emphasizes securing AI-assisted development, risk assessment across agent

Qualifications

  • Progressive experience in security engineering, architecture, cloud security, application security, or identity/security platform engineering in enterprise cybersecurity roles.
  • Hands-on experience securing AI/ML systems, AI-enabled applications, and agentic ecosystems with AI governance and LLM integrations.
  • Experience with authentication, authorization and trust models across complex enterprise and AI environments.
  • Knowledge of AI-specific threat vectors: prompt injection, model/data exfiltration, data poisoning, insecure output handling.
  • Experience securing AI-powered development and product-line AI implementations across the software lifecycle.

Responsibilities

  • Assess security landscape using automation to validate controls and uncover risks.
  • Integrate security controls into cloud/on-prem workloads and ensure effective mitigations.
  • Provide security engineering support across broad company areas and lead projects.
  • Analyze risks to information systems and recommend innovative risk mitigations.
  • Advise teams on changes to procedures and systems to strengthen security.

Skills

Security engineering
Security architecture
Cloud security
Application security
Identity/security platform engineering
AI governance
LLM integrations
Governing AI tools
Security for AI platforms
Threat modeling

Education

Bachelor’s degree in CS/InfoSec/Engineering
Security certifications (CISSP/CCSP/CSSLP/GIAC)

Tools

GitHub Copilot
AWS Bedrock
Kiro

Job description

Description

The application window will close November 1st, 2026.

Job Location

The primary work location for this role is Berwyn with a hybrid work model.

About Envestnet

Envestnet is an adaptiveWealthTechcompany that isredefining the future of wealth management byhelpingadvisors meet the moment with its comprehensive technology, actionable insights, and industry leading support.Backed byover25 years of experience and approximately$7.0 trillionin platform assets, Envestnet is trusted by over one third of financial advisors across leading banks, wealth managers, brokerages, and RIAs.

For a deeper look at how Envestnet is shaping the future of financial advice, visitwww.envestnet.com.

The Team You’ll Join

You will join Envestnet’s Technology team, where we design, build, and maintain scalable, secure, and robust WealthTech solutions that power the future of financial advice. The team collaborates closely with product, operations, and business stakeholders to drive innovation, enhance efficiency, and enable sustainable growth. Guided by modern engineering practices and a commitment to domain excellence, technical rigor, and collaboration, the Technology team ensures our platforms remain resilient, adaptable, and aligned with evolving business needs making it a core driver of Envestnet’s long term success.

How You’ll Contribute

Continuously assesses the organization’s security landscape, utilizing cutting-edge automation and offensive security techniques to validate controls and uncover potential areas of risk. Utilizes architecture and engineering insights into major cloud and on-premise workloads to integrate continuous monitoring, automated validation and offensive security into a cohesive strategy and strengthen the overall security posture. Works cross-organizationally to ensure that security controls are effective, risks are understood and mitigations properly addressed and validated.

  • Provides Information Security Engineering support for broad areas of the company.
  • Develops and executes security controls and reports, defenses and countermeasures to detect, analyze, investigate and respond to internal or external attacks and infiltration attempts.
  • Leads or provides direction for Information Security Engineering projects.
  • Provides complex analysis of potential risks to information systems security and recommends innovative solutions.
  • Recommends and implements changes to procedures and systems to enhance information systems security.
  • Integrates network security controls into an environment to identify risks and reduce their impact.
  • Provides guidance and advice to less experienced team members.
  • Secure AI platforms, agents, MCP integrations, plugins, toolchains, and agent-to-agent workflows through architecture reviews, risk assessments, and control validation.
  • Implement and enhance AI security controls, including data protection, model governance, source code safeguards, and AI-specific risk mitigation capabilities.
  • Develop and maintain AI security monitoring, detection, investigation, and incident response capabilities to identify and respond to threats across AI environments.
  • Conduct and participate in adversarial testing, threat assessments, and red/purple team exercises involving AI systems, while evaluating emerging AI technologies, attack techniques, and security risks to enable secure adoption.
What You’ll Need to Bring
  • Candidates should demonstrate the relevant experience, skills, and capabilities needed to successfully perform in the role. Relevant experience may be gained through current responsibilities, prior roles, project work, leadership opportunities, or other comparable experiences.
  • Progressive experience in security engineering, security architecture, cloud security, application security, or identity/security platform engineering in enterprise cybersecurity roles.
  • Hands-on experience securing AI/ML systems, AI-enabled applications, and agentic ecosystems — including AI governance, agent frameworks, RAG architectures, and LLM integrations — with experience leading the security architecture, implementation, and assessment of AI platforms such as AWS Bedrock, Claude, Microsoft Copilot, GitHub Copilot, Kiro, and MCP integrations. Broad familiarity with the evolving agentic landscape, including plugins, skills, routines, desktop integrations, agent marketplaces, tool-invocation frameworks, and orchestration platforms.
  • Demonstrated experience securing and assessing authentication, authorization, and trust models across complex enterprise and AI environments, including delegated access, workload identities, service principals/accounts, API keys, OAuth/OIDC flows, token delegation, agent impersonation, consent models, permissions, delegated workflows, data access controls, autonomous actions, and cross-system trust relationships.
  • AI-specific threat knowledge - experience identifying and mitigating AI-specific attack vectors: prompt injection, jailbreaking, model/data exfiltration, data poisoning, and insecure output handling in LLM-integrated systems.
  • Securing AI-assisted development and product-line AI implementation - experience assessing risks AI tools and AI-driven features introduce across the software lifecycle, from code generation to production deployment.
  • Strong analytical, troubleshooting, and problem-solving skills, with the ability to assess complex security risks and communicate recommendations to technical and business stakeholders.
Nice-to-Haves
  • Experience developing automation to validate security controls, detect configuration drift, and improve visibility into AI usage, security posture, and risk.
  • Familiarity with cloud-native security controls, detection engineering, incident response, and security operations within AI-enabled environments.
  • Experience with AI red-teaming or adversarial testing of LLM- and agent-based systems.
  • Experience assessing third-party AI vendors or SaaS tools for data handling and security risk.
  • Bachelor’s degree in computer science, Information Security, Engineering, or a related field, or equivalent combination of education and relevant experience.
  • Relevant security certifications (e.g., CISSP, CCSP, CSSLP, GIAC) and/or AI/ML, application security, cloud, or identity-focused certifications demonstrating hands-on experience securing modern AI-enabled systems.
Why You’ll Enjoy Working at Envestnet

Help shape the future of WealthTech. At Envestnet you’ll gain hands-on experience and collaborate with some of the industry’s brightest minds to deliver meaningful, innovative solutions that make a real difference.

We value flexibility in how and where work gets done, and we recognize strong performance with meaningful rewards- because your contributions should drive both business success and your own personal growth. If you’re looking for a place where your work has impact, your development is supported, and your contributions are truly valued, Envestnet is where you can build your future.

The opportunity is now!

Sponsorship

This position is not open to candidates requiring visa sponsorship.

Our Investment in You

This role offers a base salary range of $138,500 to $173,100. The range listed represents a good-faith estimate of base salary compensation for this position and does not include incentive compensation, equity or benefits. Individual pay will be determined based on factors including, but not limited to, relevant experience, skills, education, certifications, and geographic location, in accordance with applicable pay transparency laws. This role is eligible for an additional incentive component as part of the total rewards package.

We provide a comprehensive suite of benefits - subject to Envestnet’s plan eligibility rules - that support your overall well-being including, medical insurance, paid time off (PTO), 401k company match, paid parental leave, education reimbursement, disability coverage and mental health & wellness support. Our investment in you means supporting you professionally, financially, and personally at every stage of your journey with us. Please visit our benefits page on our career site to learn more.

Our Commitment to Inclusion & Belonging

Envestnet is an Equal Opportunity Employer and is committed to creating an inclusive environment for all employees and applicants. We welcome and value individuals of all backgrounds and do not discriminate based on race, color, religion, creed, sex (including pregnancy or related medical conditions), gender identity or expression, sexual orientation, national origin, ancestry, age, disability, genetic information, military or veteran status, citizenship status, or any other status protected by applicable law. We encourage individuals from all backgrounds to apply. We strive to provide an inclusive application and interview process. If you are a candidate with a disability and require reasonable accommodation, please contact us at [email protected]. Please include your full name, the title of the role you are applying for, and the accommodation necessary to assist you with the recruiting process.

Recruitment Fraud

At Envestnet, safeguarding the trust and safety of job seekers is a top priority. We are aware that scammers may impersonate Envestnet recruiters or create fake job opportunities to deceive candidates. Review the information on our recruitment fraud awareness page to help you recognize and avoid recruitment fraud.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead Information Security Engineer
Lead Information Security Engineer

Envestnet • All (MO)

Hybrid
USD 139,000 - 173,000
Competitive compensation
Hybrid work model
Comprehensive benefits
Lead Information Security Engineer
Lead Information Security Engineer

Envestnet • United States

Hybrid
USD 139,000 - 173,000
Lead Information Security Engineer
Lead Information Security Engineer

Envestnet • Chesterbrook (PA)

Hybrid
USD 139,000 - 173,000
Product Security Engineering Director
Product Security Engineering Director

Envestnet • United States

Hybrid
USD 184,000 - 224,000
Product Strategy Director
Product Strategy Director

Envestnet • United States

Hybrid
USD 152,300 - 190,400
Medical insurance
Paid time off
401(k) company match
+1
Lead Data Engineer
Lead Data Engineer

Envestnet • Raleigh (NC)

Hybrid
USD 100,000 - 130,000
Competitive compensation
Medical insurance
Paid time off (PTO)
+2
Lead Product Manager - AI
Lead Product Manager - AI

Envestnet • Devon (PA)

Hybrid
USD 140,000 - 190,000
Client Service Associate - Advisor
Client Service Associate - Advisor

Envestnet • Berwyn (PA)

Hybrid
USD 49,000 - 61,000
Medical insurance
Paid time off
401k company match
+4
Portfolio Services Associate
Portfolio Services Associate

Envestnet • Chesterbrook (PA)

Hybrid
USD 49,000 - 61,000
Medical insurance
Paid time off (PTO)
401k company match
+4
Data Analyst II
Data Analyst II

Envestnet • Seattle (WA)

Hybrid
USD 71,000 - 88,800