Senior Security Engineer

Cetera Financial Group Inc

Dallas (TX)

On-site

USD 140,000 - 190,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Cetera Financial Group Inc. is seeking an AI Risk and Compliance Engineer to operationalize AI governance controls, manage AI-related third-party and vendor risk, and lead adversarial threat modeling for AI/ML systems using the MITRE ATLAS framework.

This role bridges IT Risk, Cloud Security, Legal/Procurement, and AI/ML Engineering within a regulated financial services environment. The candidate will coordinate audits, develop control narratives, and embed AI risk requirements into intake,

Qualifications

  • 8-10+ years in IT/cyber risk, GRC, security engineering, or a related discipline with direct exposure to AI/ML systems
  • Knowledge of AI risk frameworks (e.g., NIST AI RMF) and OWASP Top 10 for LLMs
  • Practical experience with threat modeling methodologies for AI/ML systems, including familiarity with MITRE ATT&CK and MITRE ATLAS
  • Experience building or operating third-party/vendor risk management processes—due diligence, contracting/SLAs, ongoing monitoring, and remediation
  • Ability to translate technical risk findings into control objectives, policy language, and audit-ready documentation
  • Experience in regulated environments (financial services or FINRA preferred)
  • Strong communication skills across technical, risk, legal, and compliance stakeholders

Responsibilities

  • Operationalize AI governance controls across AI risk management frameworks and evidence collection for audits
  • Lead AI third-party risk management, evaluating AI tools and vendors against security, privacy, and compliance criteria
  • Maintain AI/vendor risk inventories documenting provenance, functionality, and limitations
  • Run ongoing AI risk assessments covering performance, data quality, bias, and security controls
  • Perform AI threat modeling to identify adversarial tactics and risks across the ML lifecycle
  • Coordinate red-teaming, adversarial testing, and penetration testing of AI/ML systems
  • Integrate AI-specific vulnerabilities into enterprise vulnerability management processes
  • Identify unsanctioned AI usage and recommend remediation or approval pathways
  • Partner across IT Risk, Cloud Security, Legal, Procurement, and Engineering to embed AI risk requirements
  • Support governance and audits by producing control evidence tied to the AI risk management framework

Skills

IT risk management
GRC
Security engineering
AI risk management
Threat modeling
Vendor risk management
Regulated environments
Cross-functional communication

Tools

MITRE ATLAS
NIST AI RMF
OWASP Top 10 for LLMs
Archer
ServiceNow GRC
AWS Bedrock

Job description

At Cetera, our Information Security organization protects employees, advisors, and clients from evolving cyber threats across cloud, SaaS, and emerging AI-enabled technologies. As artificial intelligence capabilities expand across the enterprise, Cetera is building a formal AI risk and compliance program - grounded in industry-recognized AI risk management frameworks - to ensure innovation aligns with regulatory, security, and third-party risk expectations.

We are seeking an AI Risk and Compliance Engineer to operationalize AI governance controls, manage AI-related third-party and vendor risk, and lead adversarial threat modeling for AI/ML systems using the MITRE ATLAS framework. This role serves as a key bridge across IT Risk, Cloud Security, Legal/Procurement, and AI/ML Engineering teams, translating AI risk management framework requirements into practical, auditable processes within a regulated financial services environment.

What will you do:
  • Operationalize AI governance controls: Implement and maintain controls aligned to recognized AI risk management frameworks (spanning governance, mapping, measurement, and management of AI risk), including control documentation, risk-control matrices (RCM), and evidence collection to support audits and regulatory exams.
  • Lead AI third-party risk management: Evaluate and onboard third-party AI/ML tools and vendors against security, privacy, and compliance criteria; document AI-specific vendor and contract requirements, SLAs, and fourth-party disclosures; support due diligence for AI vendors and data provenance reviews.
  • Maintain AI/vendor risk inventories: Build and maintain documentation of third-party AI components (models, datasets, APIs, pre-trained/foundation models) covering provenance, functionality, and known limitations, and map internal controls to those components.
  • Run ongoing AI risk assessments: Conduct recurring vendor risk and compliance assessments covering AI system performance, data quality, algorithmic bias, and security controls; monitor pre-trained/foundation model drift and SLA adherence; assess concentration and dependency risk across AI vendors.
  • Perform AI threat modeling: Design and execute threat models for AI/ML systems using the MITRE ATLAS framework to identify adversarial tactics and techniques - including prompt injection, data/model poisoning, model evasion, model extraction, and supply-chain risk in ML pipelines - across the AI development and deployment lifecycle.
  • Coordinate adversarial testing: Plan and coordinate red-teaming, adversarial testing, and penetration testing of AI/ML systems, and drive ongoing threat assessments informed by current threat intelligence and prior incidents.
  • Integrate AI into vulnerability management: Ensure AI-specific vulnerabilities and security findings are captured, prioritized, and remediated through existing enterprise vulnerability management processes.
  • Identify and assess unsanctioned AI usage: Support discovery and risk assessment of unsanctioned (shadow) AI tool usage across the enterprise and recommend remediation or approval pathways.
  • Partner cross-functionally: Work closely with IT Risk, Cloud Security, Legal, Procurement, and Application/AI Engineering teams to embed AI risk and compliance requirements into intake, procurement, and development processes.
  • Support governance and audit activities: Develop and maintain AI risk standards, control narratives, and runbooks; support internal and external audits and regulatory compliance activities (e.g., FINRA) by producing control evidence tied to the organization’s AI risk management framework.
What you will have:
  • 8-10+ years of experience in IT/cyber risk, GRC, security engineering, or a related discipline, with direct exposure to AI/ML systems
  • Working knowledge of AI risk and control frameworks (e.g., NIST AI RMF or similar industry AI risk management frameworks) and OWASP Top 10 for LLMs
  • Practical experience with, or strong working knowledge of, threat modeling methodologies for AI/ML systems, including familiarity with MITRE ATT&CK and MITRE ATLAS
  • Experience building or operating third-party/vendor risk management processes - due diligence, contracting/SLAs, ongoing monitoring, and issue remediation
  • Understanding of AI-specific attack techniques (prompt injection, data/model poisoning, model evasion, model extraction/inversion) and associated mitigations
  • Ability to translate technical risk findings into control objectives, policy language, and audit-ready documentation
  • Experience in regulated environments (financial services or FINRA preferred)
  • Strong communication skills across technical, risk, legal, and compliance stakeholders
Preferred Qualifications:
  • Experience with GRC platforms (e.g., Archer, ServiceNow GRC) for control and risk-register management
  • Certifications such as CRISC, CISSP, CCSP, or IAPP AIGP (AI Governance Professional)
  • Experience with AWS Bedrock or other cloud AI/ML platforms and cloud-native AI security
  • Familiarity with model cards, data lineage/provenance tooling, and AI bill-of-materials (AI-BOM) concepts
  • Prior participation in red team, purple team, or adversarial testing exercises involving ML systems
  • Exposure to AI governance committees or model risk management (MRM) functions
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cloud Security Engineer
Cloud Security Engineer

Cetera Financial Group Inc • Dallas (TX)

On-site
USD 120,000 - 180,000
AI Risk & Compliance Engineer
AI Risk & Compliance Engineer

Cetera Financial Group Inc • Dallas (TX)

On-site
USD 140,000 - 190,000
Principal AI Security Engineer
Principal AI Security Engineer

Capitolis • Atlanta (GA)

On-site
USD 120,000 - 150,000
AI Security Engineer
AI Security Engineer

TBG | The Bachrach Group • New York (NY)

Hybrid
USD 150,000 - 230,000
AI Security Specialist
AI Security Specialist

Milbank LLP • New York (NY)

On-site
USD 140,000 - 180,000
Senior AI Risk Analyst
Senior AI Risk Analyst

Summit Tech Partners LLC • Easton

On-site
USD 110,000 - 170,000
Senior Security Engineer - AI Focus
Senior Security Engineer - AI Focus

Euna Solutions • Atlanta (GA)

On-site
USD 140,000 - 210,000
AI Governance Manager
AI Governance Manager

Madison-Davis, LLC • New York (NY)

On-site
USD 180,000 - 240,000
AI Risk and Governance Lead
AI Risk and Governance Lead

Lincoln Electric • Kentucky

On-site
USD 150,000 - 210,000
Program Manager, Security Risk Program
Program Manager, Security Risk Program

Meta • Menlo Park (CA)

On-site
USD 190,000 - 260,000