AI Security Engineer

Posted 3 days ago

tbg bachrach groupBrooklyn (NY)

SENIORITY

Lead

Apply

About the role

The Artificial Intelligence Security Engineer leads enterprise efforts to protect and govern machine learning systems, frontier models, and generative AI deployments. This practitioner is responsible for establishing technical defenses, continuously analyzing model behaviors, vetting external AI services, and ensuring all automated tools adhere strictly to client confidentiality mandates, statutory obligations, and cybersecurity governance standards.
Key Responsibilities: Comprehensive AI Risk Analysis: Lead pre-implementation security, governance, and privacy evaluations for commercial LLM platforms, specialized legal tech, retrieval-augmented workflows, and workplace assistants. Specialized Threat Hunting & Monitoring: Identify and neutralize novel machine learning attack vectors, including indirect prompt manipulation, training data poisoning, model-driven data loss, and unauthorized shadow AI implementations across the enterprise. Third-Party Model & Vendor Assurance: Execute technical due diligence on prospective AI partners, scrutinizing data retention policies, model training boundaries, geographic hosting criteria, and compliance attestations against frameworks like ISO/IEC 42001 and SOC 2 Type II.Information Protection & Governance: Work closely with legal, risk, and operational teams to enforce data boundaries that stop protected work product, attorney-client privileged materials, and sensitive personal data from entering public or unmonitored model architectures. Incident Handling & Forensics: Direct investigation, triage, and mitigation strategies for security events involving machine learning endpoints, compromised service credentials, and model exploitation. Adversarial AI Testing & Red Teaming: Design and run offensive security exercises against internal pipelines and external models, simulating jailbreak strategies, prompt extraction, membership inference, model inversion, and autonomous agent hijacking. Manage third-party penetration testing scopes and translate outcomes into concrete remediation plans. Workforce Enablement & Guidance: Formulate technical guidelines, best practices, and security awareness modules educating personnel on secure AI interaction and risk prevention. Regulatory Governance & Standards: Align internal AI security controls with developing legal and industry benchmarks, including the NIST AI Risk Management Framework, European Union AI legislation, state financial cyber standards, and bespoke client security addenda.
Required Qualifications: Minimum 5 years of professional experience in information security, including at least 2 dedicated to securing machine learning ecosystems, LLMs, or enterprise AI risk governance. Proven background conducting offensive AI testing, jailbreak research, and exploit prototyping, with deep familiarity using the MITRE ATLAS matrix and the OWASP Top 10 for Large Language Model Applications. Direct hands-on experience using automated adversarial assessment suites (such as Promptfoo, Microsoft PyRIT, NVIDIA Garak, Giskard, or proprietary testing scripts).Thorough architectural comprehension of transformer pipelines, retrieval-augmented generation (RAG) architectures, vector stores, and autonomous agent execution frameworks. Practical background securing modern workplace productivity assistants and cloud-hosted model APIs (such as Azure OpenAI Service, Claude enterprise environments, and Microsoft 365 Copilot ecosystems).Working proficiency with enterprise identity controls, data loss prevention (DLP), and content labeling systems (e.g., Microsoft Entra ID and Microsoft Purview).Bachelor of Science in Cybersecurity, Computer Science, Information Technology, or an equivalent discipline.
Required Certifications: Must hold at least one active credential: Certified Information Systems Security Professional (CISSP)Certified Information Security Manager (CISM)Desirable Experience Prior security engineering or governance background within legal organizations, investment management, banking, or similar high-scrutiny sectors. Documented engagement in public or private AI vulnerability disclosure programs, CTF competitions, or published defensive/offensive ML research.

Before you apply

Applying takes about a minute. These four things decide how fast it moves after that.

Your profile is current

It's what we read first. Occupations, seniority and locations matter more than a long history.

Two examples you can talk through

Not a portfolio — just two pieces of work where you can explain the decisions and what you'd change.

A number in mind

What you're on now and what would make you move. We negotiate better when we know both.

Your notice period

Employers plan around it, and it's the question that stalls offers most often.

Once you apply, someone reads it and calls you before anything reaches the employer — usually within two working days.

More like this