Security Engineer, AI Platforms & Infrastructure

Carlyle Group

Northern, New York (KY, NY)

Hybrid

USD 160,000 - 180,000

Full time

4 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Health insurance
Retirement benefits
Paid time off
Paid holidays
Life insurance
Disability insurance
Family planning benefits
Wellness programs

Job summary

The Carlyle Group seeks a Security Engineer for AI Platforms & Infrastructure to secure AI adoption across the firm. You’ll own security controls over AI systems, integrate tooling, and automate security operations while extending identity, network, and logging capabilities.

Responsibilities cover AI platforms, automation, network security, and observability with emphasis on guardrails, MCP-based reviews, and SIEM integration. Hybrid work in DC/NYC outlines the role’s location flexibility.

Qualifications

  • Bachelor’s degree required; concentration in cybersecurity, CS, information systems, engineering or related field preferred.
  • Minimum 5-7 years of relevant technical experience; 3+ years in information security/cybersecurity engineering.
  • Hands-on experience securing platforms and agent/tool-based systems with authentication, authorization, guardrails, and usage monitoring.
  • Experience with MCP, agent frameworks, tool integrations, or comparable integration patterns; reviewing third-party integrations for security risk.
  • Experience with privileged access management and secrets management for service accounts and automation.
  • Experience with network security technologies including next-gen firewalls, SASE/ZTNA, WAF, and modern enterprise networking.
  • Linux administration skills to harden servers and assess AI-generated scripts.

Responsibilities

  • Secure and operate AI platforms and AI gateway, including authentication, authorization, guardrails, and usage governance.
  • Build automation using APIs to reduce manual security operations and support privileged access management.
  • Secure network paths across the security stack (SD-WAN, firewall, SASE/ZTNA, WAF) and assist with related engineering tasks.
  • Design and build logging and telemetry infrastructure; route security logs to SIEM and ensure data quality and enrichment.
  • Develop dashboards, alerts, and health checks to monitor security posture and reliability across capabilities.

Skills

Automation scripting
Linux administration
Identity & access management
Security monitoring
Cloud security
Networking security

Education

Bachelor’s degree in cybersecurity / related field

Tools

MCP (Model Context Protocol)
SASE/ZTNA
WAF
SIEM
Privileged access management tools
Secrets management

Job description

## Security Engineer, AI Platforms & InfrastructureApply: Hybrid: New York, NY: Washington, DC: Full time: Posted Yesterday: R-00286**Company Profile**The Carlyle Group (NASDAQ: CG) is a global investment firm with $485 billion of assets under management, across 678 investment vehicles as of June 30, 2026. Founded in 1987 in Washington, DC, Carlyle has grown into one of the world's largest and most successful investment firms, with more than 2,500 professionals operating in 28 offices in North America, Europe, the Middle East, Asia and Australia.Carlyle’s purpose is to connect people, ideas, and capital to fuel growth for companies and performance for investors, which range from public and private pension funds to wealthy individuals and families to sovereign wealth funds, unions and corporations. Carlyle invests across three segments – Global Private Equity, Global Credit and Carlyle AlpInvest – and has deep expertise across industries, markets, and geographies.At Carlyle, we believe that a wide spectrum of experiences and viewpoints drives performance and success. Our CEO, Harvey Schwartz, has stated that, \"To build better businesses and create value for all of our stakeholders, we are focused on assembling leadership teams with the strongest insights from a range of perspectives.\" Reflecting this view, emphasis is placed on development, retention and inclusion through our internal processes and seven Employee Resource Groups (ERGs). We cultivate a culture where ideas are openly shared and challenged, connecting diverse expertise and perspectives to drive enduring value.**Position Summary**The Security Engineer is a hands-on technical role that strengthens how Carlyle secures its adoption of AI. This role secures AI platforms and agentic tooling as they’re adopted across the firm and extends core security engineering practices into the identity, network, and logging capabilities that support them. This role owns the implementation and continuous improvement of security controls protecting AI systems throughout their lifecycle, from onboarding and integration review through ongoing monitoring and retirement and brings strong automation to bear as the firm’s technology footprint evolves.**In-Office Requirement:** 4 days per week**Primary Responsibilities****AI Platforms, Gateway – 30%*** Secure and operate the AI gateway that brokers access between users, agents, and downstream model providers and connected services, including authentication, authorization, guardrails, and usage governance.* Review and harden AI agent and tool integrations for excessive scope, credential handling, and data-exfiltration risk before and after deployment.* Define and enforce security guardrails for model inputs, outputs, and tool usage. Partner with platform owners to pilot new guardrail configurations and measure their effectiveness.**Automation, Identity & Privileged Access – 25%*** Build automation using supported APIs, reducing manual and error-prone security operations.* Support privileged access management across the environment.**Network, Endpoint & Infrastructure Security – 25%*** Secure network paths across the security stack, including SD-WAN, firewall, SASE/ZTNA, and WAF policies for API and platform traffic.* Support broader network and endpoint security engineering work as capacity allows, including firewall migrations, SSL inspection tuning, and device-posture troubleshooting.**Logging, Telemetry & Observability – 20%*** Design and build logging and telemetry infrastructure to support security monitoring across the environment.* Evaluate and integate telemetry pipeline technologies to route security logs reliably and cost-effectively to the SIEM.* Work with data retention, normalization, and enrichment standards for logs so analysts and automation can act on them; identify and close logging and data-quality gaps.* Build dashboards, alerts, and health checks to monitor availability, security posture, performance, and reliability across assigned capabilities.**Requirements****Education & Certificates*** Bachelor’s degree, required* Concentration in cybersecurity, computer science, information systems, engineering, or a related discipline strongly preferred, or equivalent relevant professional experience.* Relevant certifications in security engineering, cloud security, identity, or AI/ML security are preferred.**Professional Experience*** Minimum 5-7 years of overall relevant technical experience, required* Minimum 3 years of experience information security or cybersecurity engineering experience, required* Hands-on experience securing platforms and agent or tool-based systems, including authentication, authorization, guardrails, and usage monitoring.* Experience with Model Context Protocol (MCP), agent frameworks, tool integrations, or comparable integration patterns, including reviewing third-party integrations for security risk.* Experience with privileged access management platforms and secrets management for service accounts and automation.* Experience with network security technologies, including next-generation firewalls, SASE/ZTNA, web application firewalls, and modern enterprise networking.* Enough Linux administration skills to harden servers and to evaluate AI-generated scripts and configurations across various distributions.* Experience building automation with a general-purpose language (Python, Bash, or similar) and integrating systems through APIs and structured data formats.* Experience building or operating logging and telemetry pipelines and integrating with SIEM platforms.* Experience with identity platforms and endpoint security tooling is preferred.**Benefits/Compensation**The compensation range for this role is specific to Washington, DC, and New York, NY and takes into account a wide range of factors including but not limited to the skill sets required/preferred; prior experience and training; licenses and/or certifications.The anticipated base salary range for this role is $160,000 to $180,000.In addition to the base salary, the hired professional will enjoy a comprehensive benefits package spanning retirement benefits, health insurance, life insurance and disability, paid time off, paid holidays, family planning benefits and various wellness programs. Additionally, the hired professional may also be eligible to participate in an annual discretionary incentive program, the award of which will be dependent on various factors, including, without limitation, individual and organizational performance.Due to the high volume of candidates, please be advised that only candidates selected to interview will be contacted by Carlyle.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead Engineer, AI & Process Automation
Lead Engineer, AI & Process Automation

Carlyle • Washington

On-site
USD 170,000 - 190,000
Health insurance
Retirement benefits
Paid time off
+2
Engineer, AI & Process Automation
Engineer, AI & Process Automation

Carlyle • Washington

On-site
USD 160,000 - 180,000
Manager, Threat Detection Engineer
Manager, Threat Detection Engineer

Carlyle Group • Washington

Hybrid
USD 160,000 - 180,000
Incident Response Analyst - Americas
Incident Response Analyst - Americas

Carlyle Group • Washington, Northern (KY)

Hybrid
USD 140,000 - 160,000
Health insurance
Retirement benefits
Life insurance
+5
Data & AI Engineer
Data & AI Engineer

Carlyle • Washington

On-site
USD 160,000 - 180,000
Data & AI Engineer
Data & AI Engineer

Carlyle • New York (NY)

On-site
USD 160,000 - 180,000
Lead Engineer, AI & Process Automation
Lead Engineer, AI & Process Automation

1P284 THE CARLYLE GROUP EMPLOYEE CO., LLC • Washington

On-site
USD 170,000 - 190,000
Comprehensive benefits
Engineer, AI & Process Automation
Engineer, AI & Process Automation

1P284 THE CARLYLE GROUP EMPLOYEE CO., LLC • Washington

On-site
USD 160,000 - 180,000
Forward Deployed Product Engineer
Forward Deployed Product Engineer

Carlyle • Washington

Hybrid
USD 210,000 - 220,000
Data Architect, Corporate Services
Data Architect, Corporate Services

Carlyle • Washington

Hybrid
USD 170,000 - 190,000
Retirement benefits
Health insurance
Life insurance
+5