Skip to content

Open nowPosted 51 days ago

AI Application Security Architect

acv187 open roles

Where
Buffalo, NY, USA
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowAI Application Security Architectacv · Buffalo, NY, USA
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on acv's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.8% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.6%1 day
  2. 3.4%3 days
  3. 7.8%7 days
  4. 14.3%14 days
  5. 33.7%30 days
This job: posted 51 days ago

The posting

Who we are looking for: ACV Auctions is hiring an Principal Architect, Product Security to secure how we build and ship AI, as part of the Product Security team. ACV's marketplace runs on AI that customers stake real money on: computer vision models that grade vehicle condition, pricing models that inform lending decisions, and LLM features across our products. You will define how that surface gets protected, and how our engineers use AI coding assistants and agents without trading away security. You will help engineering deliver secure applications across ACV's marketplace, protecting sensitive dealer, consumer, vehicle, and payment data. Company-wide security architect for AI systems and the applications built around them. Defines ACV's target-state secure architecture, reference architectures, and standards for machine learning and LLM-powered systems, and guides the highest-risk AI and application designs across engineering. A P6 architecture-track role alongside Principal Engineer on the Product Security Career Ladder. Company / multi-year scope; owns AI and application security architecture and standards; sets direction on the most consequential design decisions. Focus areas: this role spans AI/ML security and application security. It is a technical architecture role. ACV's AI Governance function owns policy, risk registers, and regulatory alignment; this role owns the technical controls and architecture that make those policies real in production systems. What you will do:

Actively and consistently support all efforts to simplify and enhance the customer experience. Define ACV's target-state secure architecture and reference patterns for AI/ML systems: LLM features, retrieval pipelines, agentic workflows, and the computer vision models behind vehicle condition and pricing. Protect the integrity of ACV's vision-based condition and pricing pipeline against adversarial inputs and manipulated or AI-generated imagery, partnering with fraud and inspection teams on detection and image-provenance controls. Set secure-by-default standards adopted across engineering for AI development: prompt injection defense, output handling, tool and agent permissioning, and model and training-data supply chain security. Threat model and review the highest-risk AI and application designs, applying frameworks such as MITRE ATLAS and the OWASP Top 10 lists for LLM and Agentic Applications. Own the security architecture for AI-assisted engineering: coding assistants, MCP servers, and autonomous agents, with guardrails that preserve developer velocity across an API-first engineering organization. Stand up ACV's AI security testing capability: adversarial testing and red-teaming of models and LLM features, evaluation harnesses, and runtime guardrails, making deliberate build-vs-buy decisions. Advise engineering and security leadership on multi-year AI security strategy, and partner with AI governance to translate policy into enforceable technical controls. Scale AI security expertise across engineering, including through ACV's Security Champions program; mentor Staff and Principal engineers; and represent ACV's AI security architecture externally. Perform additional duties as assigned.

What you will need:

Ability to read, write, speak and understand English. Bachelor's degree in a related field, or commensurate experience. 12+ years' of security experience, 15+ years' without degree, including deep application security architecture. Hands-on GenAI/LLM security work required, demonstrated through production experience or a verifiable body of work: AI red-team engagements, published research or tooling, open-source contributions, or AI security competition results. 2+ years of production AI security experience preferred. Security architecture: owns the enterprise secure-architecture vision for AI systems and application security. AI/ML security depth: LLM application threats (prompt injection, insecure output handling, data leakage through retrieval, excessive agency in agents and tools) and model-level threats (poisoning, evasion, extraction, malicious pre-trained models). Hands-on technical fluency: reads and writes code (Python preferred) and has personally used AI security tooling (e.g., Garak, PyRIT, promptfoo, or equivalent) rather than only evaluating vendors. Frameworks: working fluency with the OWASP Top 10 for LLM Applications, the OWASP Top 10 for Agentic Applications, MITRE ATLAS, and NIST AI RMF, and the ability to turn them into standards engineers actually follow. Standards and patterns: defines reference architectures and paved-road standards, including for AI-assisted development. Influence: aligns engineering and ML leadership to the target architecture. Application security (commensurate with level): OWASP Top 10, secure code review, threat modeling, and SAST/DAST/SCA tooling (e.g., Snyk, Checkmarx, GitHub Advanced Security, Burp Suite). Cloud security (commensurate with level): cloud-native security on AWS, Kubernetes, and infrastructure-as-code; familiarity with ML platforms and inference infrastructure (e.g., SageMaker, Bedrock) a plus. Comfort working in a fast-paced, cloud-native environment with clear written and verbal communication. Illustrative credentials (a plus, not required): SABSA or equivalent architecture credentials, CCSP or a cloud security specialty. A demonstrated body of AI security work (research, tooling, red-team findings, AI CTF results, open-source contributions) carries more weight than any certification; the AI security credential market is not yet mature.

#LI-AM3

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against acv's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on acv's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    acv's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.