Skip to content

Open nowPosted 16 hours ago

Principle Security Engineer

Jobgether4,394 open roles

Where
US
Work mode
Remote
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowPrinciple Security EngineerJobgether · US
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Jobgether's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.8% of postings close within 7 days. Measured by our own scanner across the market. Jobgether postings stay open a median of 4 days.

Share of postings closed within
  1. 1.6%1 day
  2. 3.4%3 days
  3. 7.8%7 days
  4. 14.3%14 days
  5. 33.7%30 days
This job: posted 16 hours ago

Jobgether median: 4 days open

The posting

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Principle Security Engineer based in United States.

The Principle Security Engineer will play a key role in building and operationalizing AI risk, security, and compliance capabilities within a regulated financial services environment. This role combines security engineering, governance, third-party risk management, and adversarial threat modeling for AI and machine learning systems. You will translate recognized AI risk management frameworks into practical, auditable controls and processes. The position will also address emerging AI threats, vendor dependencies, data provenance, and the security of AI-enabled technologies. Working across risk, security, legal, procurement, and engineering teams, you will help embed responsible AI practices throughout the organization. This is an opportunity to shape an evolving AI security and governance program while addressing complex and emerging cyber risks.

Accountabilities:

  • Operationalize AI governance controls aligned with recognized AI risk management frameworks, including control documentation, risk-control matrices, and audit evidence collection.
  • Lead third-party AI and ML risk management activities, including vendor due diligence, security and privacy assessments, contractual requirements, SLAs, fourth-party disclosures, and data provenance reviews.
  • Build and maintain inventories of third-party AI components, including models, datasets, APIs, and pre-trained or foundation models, documenting provenance, functionality, limitations, and associated controls.
  • Conduct recurring AI risk and compliance assessments covering system performance, data quality, algorithmic bias, security controls, model drift, SLA adherence, concentration risk, and vendor dependencies.
  • Design and execute AI/ML threat models using the MITRE ATLAS framework to identify adversarial techniques such as prompt injection, data and model poisoning, model evasion, model extraction, and ML supply-chain threats.
  • Coordinate red-team, adversarial testing, and penetration testing activities for AI/ML systems, incorporating current threat intelligence and lessons from previous incidents.
  • Integrate AI-specific vulnerabilities and security findings into enterprise vulnerability management processes and ensure appropriate prioritization and remediation.
  • Support the identification and assessment of unsanctioned or “shadow” AI usage and recommend appropriate remediation, risk acceptance, or approval pathways.
  • Partner with IT Risk, Cloud Security, Legal, Procurement, and Application/AI Engineering teams to embed AI risk requirements into technology intake, procurement, development, and deployment processes.
  • Develop and maintain AI risk standards, control narratives, procedures, and runbooks while supporting internal and external audits and regulatory activities.
  • 10+ years of experience in IT/cyber risk, governance, risk and compliance, security engineering, or a related discipline, with direct exposure to AI/ML systems.
  • Working knowledge of AI risk and control frameworks such as the NIST AI Risk Management Framework or comparable industry frameworks.
  • Strong familiarity with the OWASP Top 10 for LLMs and emerging AI security risks.
  • Practical experience with, or strong working knowledge of, AI/ML threat modeling methodologies, including MITRE ATT&CK and MITRE ATLAS.
  • Experience building or operating third-party and vendor risk management programs, including due diligence, contracting, SLAs, ongoing monitoring, and issue remediation.
  • Understanding of AI-specific attack techniques, including prompt injection, data/model poisoning, model evasion, and model extraction or inversion, along with relevant mitigations.
  • Ability to translate complex technical risk findings into clear control objectives, policies, standards, and audit-ready documentation.
  • Experience working in regulated environments, preferably within financial services or organizations subject to FINRA requirements.
  • Strong communication and collaboration skills, with the ability to work effectively across technical, security, risk, legal, compliance, and engineering stakeholders.
  • Experience with GRC platforms such as Archer or ServiceNow GRC is preferred.
  • Certifications such as CRISC, CISSP, CCSP, or IAPP AIGP are preferred.
  • Experience with AWS Bedrock or other cloud AI/ML platforms and cloud-native AI security is a plus.
  • Familiarity with model cards, data lineage and provenance tools, and AI Bill of Materials (AI-BOM) concepts is preferred.
  • Experience participating in red-team, purple-team, or adversarial testing exercises involving ML systems is a plus.
  • Exposure to AI governance committees or model risk management functions is desirable.
  • Opportunity to shape AI risk and security practices within a regulated financial services environment.
  • Exposure to emerging AI/ML security threats, governance frameworks, and adversarial testing methodologies.
  • Cross-functional collaboration with cybersecurity, IT risk, cloud security, legal, procurement, and AI engineering teams.
  • Opportunity to influence AI governance, third-party risk, vulnerability management, and security architecture practices.
  • Work focused on emerging technologies and evolving AI security challenges.
  • Opportunity to contribute to audit readiness, regulatory compliance, and enterprise-wide risk management initiatives.

How Jobgether works:

We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.

We appreciate your interest and wish you the best!

Why Apply Through Jobgether?

Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.

#LI-CL1

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Jobgether's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Jobgether's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Jobgether's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.