Sr. AI Security Engineer

McCarthy Holdings, Inc.

St. Louis (MO)

On-site

USD 140,000 - 190,000

Full time

9 days ago
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

McCarthy Holdings, Inc. is seeking a Sr. AI Security Engineer to secure design, deployment, and operation of AI-enabled products.

This role collaborates with AI, engineering, architecture, legal, and compliance teams to mature security controls and promote secure-by-design practices across the organization. The ideal candidate combines hands-on security engineering with production AI-security experience and the ability to explain risks clearly to both technical and non-technical stakeholders.

Qualifications

  • Bachelor’s degree in cybersecurity, computer science, information systems, engineering, or a related field, or equivalent professional experience.
  • Minimum five years of proven experience in an established security architecture, security engineering, architecture, or engineering role.
  • Working experience handling AI security in a production environment, including the assessment, governance, monitoring, or protection of AI applications, models, agents, or integrations.
  • Strong understanding of cybersecurity principles, including identity governance, least privilege, data protection, risk assessment, incident response, security architecture, and security governance.
  • Familiarity with OWASP LLM and AI risks, including prompt injection, indirect injection, jailbreaks, sensitive information disclosure, excessive agency, insecure output handling, and agent or tool‑use security.
  • Practical understanding of generative AI architectures, large language models, retrieval‑augmented generation, AI agents, APIs, and model or application lifecycle risks.
  • Ability to explain how risks such as indirect prompt injection or excessive agency would surface in a real agent workflow and how those risks could be detected, validated, and mitigated.
  • Experience evaluating security controls, technology vendors, data handling practices, privacy considerations, and third‑party risk.
  • Ability to develop clear standards and communicate complex technical risks to engineers, product teams, business leaders, and executives.
  • Strong analytical, written, verbal, collaboration, and problem‑solving skills.
  • Sound judgment, personal integrity, curiosity, and a demonstrated commitment to protecting confidential information.

Responsibilities

  • Develop and maintain enterprise AI security standards, control requirements, and risk‑based review processes.
  • Assess AI applications, models, agents, APIs, integrations, vendors, and data flows before and after deployment.
  • Define security requirements for AI systems across design, development, testing, deployment, operation, and retirement.
  • Evaluate identity, access, identity governance, data protection, privacy, logging, monitoring, retention, and human‑oversight controls.
  • Test AI systems and agent workflows for prompt injection, indirect injection, jailbreaks, data leakage, excessive agency, unsafe tool use, insecure integrations, and configuration drift.
  • Conduct threat modeling, architecture reviews, security assessments, and control validation for AI‑enabled solutions.
  • Establish processes for AI security findings, incident response, exception management, remediation, and executive reporting.
  • Review AI vendors, models, third parties, subprocessors, data handling practices, and material platform or configuration changes.
  • Configure, tune, validate, operate, and extend existing AI‑security, AI‑governance, application‑security, data‑security, and monitoring tools.
  • Support the evaluation and integration of additional capabilities where existing controls require enhancement.
  • Create practical security patterns, reference architectures, playbooks, standards, and guidance for engineering and product teams.
  • Monitor emerging AI threats, vulnerabilities, standards, regulations, and industry practices and translate them into actionable improvements.
  • Partner with development and platform teams to integrate security controls into AI development and deployment workflows.
  • Communicate technical risks, business impact, and recommended actions to both technical and non‑technical stakeholders.
  • Promote responsible AI adoption through measurable controls, clear accountability, and continuous improvement.

Skills

AI security
Security architecture
Threat modeling
Identity governance
Data protection
Incident response
Communication
Security governance
Vendor risk
Security tooling

Education

Bachelor's degree in cybersecurity, computer science, information systems, engineering, or related field

Tools

AI security tools
Security monitoring tools

Job description

POSITION SUMMARY

The Sr. AI Security Engineer will help secure the design, deployment, and operation of AI-enabled products and services. This role will help protect data, systems, users, and customers as generative AI, machine learning, and agentic technologies continue to evolve.


As a member of the Cybersecurity team, the engineer will work closely with AI, engineering, architecture, legal, and compliance teams. The organization has existing AI tools and controls in place, and this role will assess their effectiveness, recommend additional capabilities where needed, and mature the overall AI security toolset over time. Rather than building an AI-security stack from scratch, the engineer will configure, tune, validate, operate, and extend existing security solutions while helping teams apply practical secure-by-design practices.


The ideal candidate combines hands‑on security architecture or engineering experience, production AI‑security experience, and the ability to explain complex risks clearly to both technical and non‑technical audiences.


RESPONSIBILITIES


  • Develop and maintain enterprise AI security standards, control requirements, and risk‑based review processes.

  • Assess AI applications, models, agents, APIs, integrations, vendors, and data flows before and after deployment.

  • Define security requirements for AI systems across design, development, testing, deployment, operation, and retirement.

  • Evaluate identity, access, identity governance, data protection, privacy, logging, monitoring, retention, and human‑oversight controls.

  • Test AI systems and agent workflows for prompt injection, indirect injection, jailbreaks, data leakage, excessive agency, unsafe tool use, insecure integrations, and configuration drift.

  • Conduct threat modeling, architecture reviews, security assessments, and control validation for AI‑enabled solutions.

  • Establish processes for AI security findings, incident response, exception management, remediation, and executive reporting.

  • Review AI vendors, models, third parties, subprocessors, data handling practices, and material platform or configuration changes.

  • Configure, tune, validate, operate, and extend existing AI‑security, AI‑governance, application‑security, data‑security, and monitoring tools.

  • Support the evaluation and integration of additional capabilities where existing controls require enhancement.

  • Create practical security patterns, reference architectures, playbooks, standards, and guidance for engineering and product teams.

  • Monitor emerging AI threats, vulnerabilities, standards, regulations, and industry practices and translate them into actionable improvements.

  • Partner with development and platform teams to integrate security controls into AI development and deployment workflows.

  • Communicate technical risks, business impact, and recommended actions to both technical and non‑technical stakeholders.

  • Promote responsible AI adoption through measurable controls, clear accountability, and continuous improvement.


QUALIFICATIONS


  • Bachelor’s degree in cybersecurity, computer science, information systems, engineering, or a related field, or equivalent professional experience.

  • Minimum five years of proven experience in an established security architecture, security engineering, architecture, or engineering role.

  • Working experience handling AI security in a production environment, including the assessment, governance, monitoring, or protection of AI applications, models, agents, or integrations.

  • Strong understanding of cybersecurity principles, including identity governance, least privilege, data protection, risk assessment, incident response, security architecture, and security governance.

  • Familiarity with OWASP LLM and AI risks, including prompt injection, indirect injection, jailbreaks, sensitive information disclosure, excessive agency, insecure output handling, and agent or tool‑use security.

  • Practical understanding of generative AI architectures, large language models, retrieval‑augmented generation, AI agents, APIs, and model or application lifecycle risks.

  • Ability to explain how risks such as indirect prompt injection or excessive agency would surface in a real agent workflow and how those risks could be detected, validated, and mitigated.

  • Experience evaluating security controls, technology vendors, data handling practices, privacy considerations, and third‑party risk.

  • Ability to develop clear standards and communicate complex technical risks to engineers, product teams, business leaders, and executives.

  • Strong analytical, written, verbal, collaboration, and problem‑solving skills.

  • Sound judgment, personal integrity, curiosity, and a demonstrated commitment to protecting confidential information.


Preferred Qualifications


  • Experience with AI‑security, application‑security, cloud‑security, data‑security, DevSecOps, or security‑monitoring tools.

  • Experience performing AI red teaming, adversarial testing, penetration testing, threat modeling, or control validation.

  • Familiarity with the NIST AI Risk Management Framework or comparable AI‑governance frameworks.

  • Experience integrating security controls into software development, cloud engineering, or platform operations.

  • Familiarity with data classification, DLP, audit logging, security information and event management, and privacy‑by‑design practices.

  • Relevant certifications such as CISSP, Security+, or a portfolio demonstrating comparable practical experience.


McCarthy is proud to be an equal opportunity employer, including disability and protected veteran status.


AI Engineer II Information Technology — St. Louis, MO - Corporate Office

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

AI-Application Security Engineer
AI-Application Security Engineer

Stifel Financial Corp. • St. Louis (MO)

On-site
USD 90,000 - 120,000
AI Defense Engineer
AI Defense Engineer

Gravity IT Resources • Cincinnati (OH)

On-site
USD 140,000 - 210,000
AI Engineer — Security | Remote
AI Engineer — Security | Remote

Vertex Elites • United States

Remote
USD 140,000 - 210,000
AI-Application Security Engineer
AI-Application Security Engineer

Stifel Financial Corp. • Missouri

On-site
USD 90,000 - 120,000
Health insurance
Dental care
Vision care
+2
Senior AI Engineer, Security Infrastructure
Senior AI Engineer, Security Infrastructure

Air • Arlington (VA), Pittsburgh

On-site
USD 170,000 - 250,000
Senior Security Engineer - AI Focus
Senior Security Engineer - AI Focus

Euna Solutions • Atlanta (GA)

On-site
USD 140,000 - 210,000
Senior AI Engineer, Security Infrastructure
Senior AI Engineer, Security Infrastructure

artificial intelligence and robotics laboratory (itu air lab) • Arlington (VA)

On-site
USD 170,000 - 210,000
AI Security Analyst-- BHADC5698041
AI Security Analyst-- BHADC5698041

Compunnel Inc. • United States

On-site
USD 70,000 - 90,000
AI Cyber Engineer
AI Cyber Engineer

Ampcus Inc • Chantilly (VA)

On-site
USD 120,000 - 160,000
Information Security Application and Compliance Analyst
Information Security Application and Compliance Analyst

Vinson & Elkins • Mesquite (TX)

On-site
USD 95,000 - 125,000