Skip to content

Open nowPosted 58 days ago

AI Security Engineer

Uw35 open roles

Pay
$87,624 a year
Where
Seattle, WA
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowAI Security EngineerUw · Seattle, WA
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Uw's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.8% of postings close within 7 days. Measured by our own scanner across the market. Uw postings stay open a median of 2 days.

Share of postings closed within
  1. 1.6%1 day
  2. 3.4%3 days
  3. 7.8%7 days
  4. 14.3%14 days
  5. 33.7%30 days
This job: posted 58 days ago

Uw median: 2 days open

The posting

Job Description

UW Information Technology has an outstanding opportunity for AI Security Engineer to join their team.

About this Opportunity

Reporting to Technology Manager, the AI Security Engineer will support the security, governance, and compliance of artificial intelligence (AI) initiatives at the university and its three campuses. The AI Security Engineer exists to secure the university's AI platforms, primarily Purple, built on Cloudforce nebulaONE and hosted in Azure AI Foundry, ensuring that AI services delivered to over 50,000 faculty, staff, and students across three campuses operate within a robust, compliant, and trustworthy security framework.

Key Responsibilities

[30%] Security Engineering

-Implement and maintain security controls for AI platforms within Microsoft Azure, including network security groups, firewalls, encryption, key management, and secure landing zones aligned with the Azure Well-Architected Framework (security pillar) and the Microsoft cloud security benchmark.

- Configure and manage identity and access management using Entra ID, RBAC, conditional access policies, and Zero Trust architecture principles across management-group and subscription hierarchies.

[20%] Security Automation & Infrastructure-as-Code (DevSecOps).

- Implement and maintain infrastructure-as-code (IaC) security using Bicep and/or Terraform, including policy-as-code enforcement (Azure Policy, Sentinel policies) and IaC scanning in CI/CD pipelines.

- Embed security into CI/CD pipelines (DevSecOps) using GitHub Advanced Security or equivalent, including SAST, DAST, SCA, container image scanning, and auto-remediation workflows.

- Develop security automation scripts and tools (Python, PowerShell, Bash) to streamline vulnerability scanning, configuration hardening, and compliance evidence collection.

[20%] AI Application Security & Red-Teaming

- Support the security of AI application-layer components specific to Purple and nebulaONE, including RAG data isolation, least-privilege tool/function-call authorization, agent action budgets and rate limits, output filtering, and secrets isolation.

- Participate in recurring red-team exercises against AI platforms mapped to the OWASP LLM Top 10, the OWASP Top 10 for Agentic Applications, and MITRE ATLAS, documenting findings and supporting remediation.

- Assess and help mitigate AI-specific security risks including prompt injection, jailbreak attacks, data leakage through model outputs, and adversarial attacks.

- Support implementation of guardrails for LLM and agent application patterns including RAG, tool/function calling, MCP (Model Context Protocol), and multi-agent orchestration workflows.

- Apply AI security governance practices aligned with the NIST AI Risk Management Framework (AI RMF), the NIST Generative AI Profile, and ISO/IEC 42001.

[15%] Compliance Evidence & Vendor Oversight

- Produce and maintain compliance evidence (not policy) for FERPA, HIPAA (where PHI is in scope, including areas outside UW Medicine), GLBA, NIST 800-171/CMMC, and SOC 2 as it relates to AI platforms and cloud infrastructure.

- Support vendor security oversight of Cloudforce and Microsoft, including HECVAT completion/review, VPAT assessment, SOC 2 report analysis, data processing agreement reviews, and security questionnaire management.

[10%] Incident Response & Security Monitoring

- Monitor AI platform security posture using Azure Sentinel (SIEM), writing and tuning KQL queries for detection rules, alert triage, and threat hunting.

- Maintain and execute incident response playbooks specific to AI platforms, including data breaches, unauthorized access, prompt injection attacks, model compromise, and agent misuse scenarios.

- Triage and investigate security incidents, coordinate response activities with UWIT Office of Information Security, and contribute to post-incident reports with root cause analysis.

[5%] Paved-Road Patterns, Documentation & Continuous Improvement

- Contribute to 'paved-road' security patterns -- reusable, pre-approved templates and configurations that make the secure path the easy path for developers and administrators.

- Develop and maintain security documentation, including architecture diagrams, runbooks, standard operating procedures, and incident response playbooks.

- Evaluate emerging security tools and technologies; make recommendations for adoption.

Required Qualifications

To be considered for this opportunity your application must demonstrate you meet both the minimum qualifications and additional qualifications listed below. Equivalent education and/or experience may substitute for minimum qualifications except when there are legal requirements, such as a license, certification, and/or registration.

Minimum Qualifications

-Bachelor's Degree in Cybersecurity, Information Security, Computer Science, Information Technology, or a related field, or equivalent combination of education and experience.

-3+ years of experience in cloud security engineering, DevSecOps, or infrastructure security with hands-on cloud platform experience.

- Hands-on experience with Azure security services such as: Defender for Cloud, Sentinel, Entra ID/RBAC, Azure Policy, Key Vault, and network security configurations. Candidates with equivalent depth in AWS or GCP who can demonstrate the ability to ramp on Azure are also encouraged to apply; Azure experience is strongly preferred.

- Understanding of Zero Trust architecture principles, identity governance, and conditional access.

- Experience with container or Kubernetes security concepts.

- Proficiency in Python, PowerShell, or Bash for security automation.

- Experience with SIEM tools (Azure Sentinel or equivalent) and incident response.

- Working knowledge of at least two compliance frameworks: FERPA, HIPAA, NIST 800-53/800-171, or SOC 2.

- Strong written and verbal communication skills with the ability to explain security concepts to both technical

Applicants who do not meet these qualifications WILL NOT be forwarded to the Hiring Manager.

Preferred Qualifications

-Microsoft Certified: Cloud and AI Security Engineer Associate

- SC-100 (Cybersecurity Architect Expert), SC-200 (Security Operations Analyst).

- HashiCorp Terraform Associate certification.

- Experience with infrastructure-as-code (Bicep and/or Terraform), including IaC scanning and policy-as-code concepts.

- Experience embedding security into CI/CD pipelines: SAST, DAST, SCA, or container scanning.

- CISSP or CISM (note: CISSP requires 5 years experience, which may be aspirational for mid-level candidates).

- Exposure to AI/ML application security risks: prompt injection defense, RAG data isolation, agent authorization, output filtering.

- Familiarity with OWASP LLM Top 10, OWASP Top 10 for Agentic Applications, or MITRE ATLAS.

- Knowledge of AI governance frameworks: NIST AI RMF, NIST Generative AI Profile, ISO/IEC 42001.

- Experience with the Azure Well-Architected Framework (security pillar) and Microsoft cloud security benchmark.

- Production multi-tenant SaaS or AI-platform operations experience.

- Azure cost-management and FinOps awareness.

- Experience in higher education or public sector IT.

- Experience with HECVAT, VPAT, and vendor security assessment processes.

- Familiarity with penetration testing methodologies and tools.

- Knowledge of Washington My Health My Data Act, GLBA, GDPR.

- Experience with Agile/Scrum methodologies and tools (Jira, Azure Boards).

Working Conditions

This is a hybrid position with two days in office per week (one required team day on Wednesday, one flex day chosen by the employee). Work is conducted in an open office environment with daily interactions with team members, subject matter experts, and stakeholders at all levels of the organization.

While the general working hours are Monday through Friday, 8:00 AM to 5:00 PM, the AI Security Engineer will participate in an on-call rotation for critical AI platform security incidents and may need to adjust hours to accommodate security events, business needs, and deadlines.

About the Team University of Washington is at the forefront of leveraging cutting-edge technologies to transform education, research and healthcare. UW Information Technology (UW-IT) is the central IT organization for the University of Washington, collaborating with partners across the University community to advance teaching, learning, innovation and discovery. UW-IT delivers critical IT services and support to all three campuses, UW medical centers and global research operations. Innovation and discovery are at the heart of what UW-IT does and drive the work in advancing the University of Washington's role and mission.

This role is pivotal in ensuring that AI platforms and services operate within a robust security framework that aligns with institutional policies, federal regulations, and industry best practices. As a core member of the AI Platforms team, the AI Security Engineer will be responsible for developing and enforcing security standards, conducting risk assessments, managing compliance requirements, and collaborating across teams to embed security into every phase of the AI lifecycle.

Compensation, Benefits and Position Details

Pay Range Minimum:

$87,624.00 annual

Pay Range Maximum:

$142,392.00 annual

Other Compensation:

-

Benefits:

For information about benefits for this position, visit https://www.washington.edu/jobs/benefits-for-uw-staff/

Shift:

First Shift (United States of America)

Temporary or Regular?

This is a regular position

FTE (Full-Time Equivalent):

100.00%

Union/Bargaining Unit:

Not Applicable

About the UW

Working at the University of Washington provides a unique opportunity to change lives – on our campuses, in our state and around the world.

UW employees bring their boundless energy, creative problem-solving skills and dedication to building stronger minds and a healthier world. In return, they enjoy outstanding benefits, opportunities for professional growth and the chance to work in an environment known for its diversity, intellectual excitement, artistic pursuits and natural beauty.

Our Commitment

The University of Washington is committed to fostering an inclusive, respectful and welcoming community for all. As an equal opportunity employer, the University considers applicants for employment without regard to race, color, creed, religion, national origin, citizenship, sex, pregnancy, age, marital status, sexual orientation, gender identity or expression, genetic information, disability, or veteran status consistent with UW Executive Order No. 81.

To request disability accommodation in the application process, contact the Disability Services Office at 206-543-6450 or [email protected].

Applicants considered for this position will be required to disclose if they are the subject of any substantiated findings or current investigations related to sexual misconduct at their current employment and past employment. Disclosure is required under Washington state law.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Uw's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Uw's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Uw's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.