Principle Security Engineer

Cybersecurity Jobs

Portland (OR)

On-site

USD 160,000 - 260,000

Full time

3 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Health insurance
Mental health benefits
PTO and holidays
401(k) with company contributions
Parental leave
HSA/FSA options
Employee Assistance Program (EAP)

Job summary

Cetera Financial Group is seeking an experienced Principle Security Engineer to help operationalize AI risk and compliance in a regulated financial services environment. This role focuses on embedding AI governance controls, managing AI third-party and vendor risk, and leading adversarial threat modeling for AI/ML systems using MITRE ATLAS.

Based in Oregon (onsite), this position will translate technical findings into audit-ready documentation while partnering across IT Risk, Cloud Security,

Qualifications

  • Minimum 10+ years of IT/cyber risk, GRC, security engineering, or related discipline with AI/ML exposure.
  • Experience with AI risk management frameworks and risk documentation for audits/regulatory exams.
  • Proficient in threat modeling methodologies for AI/ML systems, including MITRE ATT&CK and MITRE ATLAS.

Responsibilities

  • Operationalize AI governance controls and produce control documentation, RCMS, and evidence for audits.
  • Lead third-party AI/ML risk management, evaluating vendors, SLAs, and data provenance.
  • Maintain AI risk inventories, documenting models, datasets, APIs, and provenance.

Skills

AI risk knowledge
Communication
IT/cyber risk
GRC

Tools

MITRE ATLAS
MITRE ATT&CK
NIST AI RMF
OWASP Top 10 for LLMs
FINRA
Archer
ServiceNow GRC
GRC platforms
AWS Bedrock

Job description

Cetera Financial Group is seeking an experienced Principle Security Engineer to help operationalize AI risk and compliance in a regulated financial services environment. This role focuses on embedding AI governance controls, managing AI third-party and vendor risk, and leading adversarial threat modeling for AI/ML systems using MITRE ATLAS.

Based in Oregon (onsite), this position will translate technical findings into audit-ready documentation while partnering across IT Risk, Cloud Security, Legal, Procurement, and Application/AI Engineering to strengthen end-to-end AI intake, procurement, and development processes.

Responsibilities
  • Operationalize AI governance controls by implementing and maintaining controls mapped to recognized AI risk management frameworks, including governance, mapping, measurement, and management of AI risk. Produce control documentation, risk-control matrices (RCM), and evidence to support audits and regulatory exams.
  • Lead AI third-party risk management by evaluating and onboarding third-party AI/ML tools and vendors against security, privacy, and compliance criteria. Document AI-specific vendor and contract requirements, SLAs, and fourth-party disclosures, and support due diligence and data provenance reviews.
  • Maintain AI and vendor risk inventories by documenting third-party AI components such as models, datasets, APIs, and pre-trained or foundation models, including provenance, functionality, and known limitations. Map internal controls to these components.
  • Run ongoing AI risk assessments by conducting recurring reviews for vendor and compliance risks, including AI system performance, data quality, algorithmic bias, and security controls. Monitor pre-trained or foundation model drift and SLA adherence, and assess concentration and dependency risk across AI vendors.
  • Perform AI threat modeling using the MITRE ATLAS framework to identify adversarial tactics and techniques across the AI development and deployment lifecycle, including prompt injection, data and model poisoning, model evasion, model extraction, and supply-chain risk in ML pipelines.
  • Coordinate adversarial testing by planning and driving red-teaming, adversarial testing, and penetration testing of AI/ML systems, using threat intelligence and prior incidents to inform ongoing threat assessments.
  • Integrate AI into vulnerability management by ensuring AI-specific vulnerabilities and security findings are captured, prioritized, and remediated through existing enterprise vulnerability management processes.
  • Identify and assess unsanctioned AI usage by supporting discovery and risk assessment of shadow AI tool usage across the enterprise, with recommendations for remediation or approval pathways.
  • Partner cross-functionally to embed AI risk and compliance requirements into intake, procurement, and development processes.
  • Support governance and audit activities by developing and maintaining AI risk standards, control narratives, and runbooks, and producing control evidence tied to the organization’s AI risk management framework for internal and external audits and regulatory compliance activities (including FINRA).
Requirements
  • 10+ years of experience in IT/cyber risk, GRC, security engineering, or a related discipline, with direct exposure to AI/ML systems.
  • Working knowledge of AI risk and control frameworks (for example, NIST AI RMF or similar) and OWASP Top 10 for LLMs.
  • Practical experience with threat modeling methodologies for AI/ML systems, including familiarity with MITRE ATT&CK and MITRE ATLAS.
  • Experience building or operating third-party/vendor risk management processes, including due diligence, contracting and SLAs, ongoing monitoring, and issue remediation.
  • Understanding of AI-specific attack techniques (prompt injection, data and model poisoning, model evasion, model extraction and inversion) and associated mitigations.
  • Ability to translate technical risk findings into control objectives, policy language, and audit-ready documentation.
  • Experience in regulated environments (financial services or FINRA preferred).
  • Strong communication skills across technical, risk, legal, and compliance stakeholders.
Technologies
  • MITRE ATLAS, MITRE ATT&CK
  • NIST AI RMF, OWASP Top 10 for LLMs
  • FINRA
  • Archer, ServiceNow GRC
  • GRC platforms
  • AWS Bedrock
  • Red team, purple team, penetration testing
  • Model cards, data lineage/provenance tooling
  • AI bill-of-materials (AI-BOM)
Benefits
  • Inclusive health, dental, vision, and life insurance plans
  • Easy access to mental health benefits
  • 20+ days of paid time off (PTO), paid holidays, and 2 paid wellness days
  • 401(k) savings plan with a generous company contribution (up to 5%)
  • Paid parental leave to support all team members with birth, adoption, and fostering
  • Health Savings and Flexible Spending Account options
  • Employee Assistance Program (EAP), LifeLock, pet insurance, and more
  • Paid caregiver leave
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Principal - Cybersecurity Audit, Risk & Governance Architect – AI & Emerging Tech
Principal - Cybersecurity Audit, Risk & Governance Architect – AI & Emerging Tech

Cybersecurity Jobs • Ashburn (VA)

Hybrid
USD 121,000 - 231,000
Medical, Dental, Vision
Matched 401(k) savings plan
Paid parental leave
+2
AI Security Engineer
AI Security Engineer

Cybersecurity Jobs • Denver (CO)

On-site
USD 145,000 - 190,000
Generous holiday policies
Health and wellbeing benefits
Paid volunteer time
+1
Security Solutions Principal - AI Security
Security Solutions Principal - AI Security

World Wide Technology • New Home (MO)

On-site
USD 153,200 - 191,500
Health and Wellbeing
Profit Sharing
401k Matching
+2
Principal AI Security Engineer
Principal AI Security Engineer

Capitolis • Atlanta (GA)

On-site
USD 120,000 - 150,000
AI Security Specialist
AI Security Specialist

Milbank LLP • New York (NY)

On-site
USD 140,000 - 180,000
AI Security Engineer — Governance & Risk (Oregon Onsite)
AI Security Engineer — Governance & Risk (Oregon Onsite)

Cybersecurity Jobs • Portland (OR)

On-site
USD 160,000 - 260,000
Health insurance
Mental health benefits
PTO and holidays
+4
AI Security Engineer
AI Security Engineer

PRECISE SOFTWARE SOLUTIONS INCORPORATED • Washington

On-site
USD 140,000 - 190,000
Health benefits
Flexible PTO
Retirement plan with matching
+6
Sr. Security Engineer - GRC Frameworks & AI Governance
Sr. Security Engineer - GRC Frameworks & AI Governance

Xai • New York (NY)

On-site
USD 100,000 - 228,000
Equity
Comprehensive medical, vision, and dental coverage
401(k) retirement plan
+2
Principal AI Engineer
Principal AI Engineer

Phizenix • New York (NY)

On-site
USD 180,000 - 260,000
AI Security Enablement - Strategy and Standards Lead
AI Security Enablement - Strategy and Standards Lead

Bank of America • Washington

On-site
USD 140,000 - 220,000