Senior Security Engineer, AI Enablement
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+5 more
Job description
The Senior Security Engineer, AI Enablement is Securityâs embedded, full-time representative on JLLâs Falcon team, owning the productâs security architecture for agents, MCP integrations, and identity end-to-end rather than reviewing it after the fact-advancing APEX + 2030âs mandate that AI products are built securely by design, not secured after launch. Reporting to the Head of AI Security while sitting day-to-day with Falconâs engineers, this role requires the technical depth to write and review production code, architect agentic identity and permissioning, and represent Falconâs security posture credibly to the broader Cybersecurity organization., Embedded Product Security Partnership
-
Sit inside the Falcon team as securityâs full-time technical representative, participating in planning, design reviews, and sprint work rather than reviewing finished features after the fact.
-
Serve as the primary point of contact between Falcon and the broader Cybersecurity organization-translating security requirements into product decisions the team can act on immediately.
-
Build enough trust and technical credibility with Falconâs engineers that security is treated as a design input, not a release gate.
Agent, MCP & Identity Architecture
-
Own the security architecture for Falconâs use of agents, MCP servers, and tool integrations, defining permission boundaries, trust boundaries, and blast radius for every agent-to-tool and agent-to-agent interaction.
-
Review and harden the identity model underpinning Falconâs agentic components, including:
-
Service-to-service and agent-to-tool authentication
-
Scoped, least-privilege credentials for every MCP server and tool connection
-
Session and delegation boundaries when agents act on a userâs behalf
-
Audit logging sufficient to reconstruct what an agent did and why
-
Design secure patterns for prompt handling, tool-calling, and data flow specific to Falconâs product surface, informed by how the Claude Agent SDK and MCP actually work under the hood.
-
Partner with the Head of AI Security to align Falconâs architecture with enterprise AI security standards without slowing product velocity.
Product Enablement Ownership
-
Own the security component of Falconâs product enablement work end-to-end, from threat modeling new features to defining the guardrails that ship with them.
-
Write and maintain the security requirements, configuration standards, and secure-by-default patterns that Falconâs engineers build against, rather than producing a review checklist after the fact.
-
Define what âsecure enough to shipâ means for each Falcon release-balancing genuine risk against the teamâs delivery timeline.
Cross-Functional Technical Input
-
Represent Falconâs security posture and roadmap to the broader Cybersecurity organization, including the Head of AI Security and other AI Security team members.
-
Provide deep technical input into cross-functional security discussions, including third-party risk assessments and enterprise AI governance decisions where Falconâs architecture is relevant.
-
Collaborate with identity, cloud security, and application security teams to ensure Falconâs agentic components meet the same bar as any other production system.
Software Engineering Craft & Technical Depth
-
Write and review code directly, contributing to Falconâs codebase where security-critical components such as auth, permissioning, and agent orchestration are involved, rather than advising from the sidelines.
-
Maintain hands-on fluency with the Claude Agent SDK, MCP, and modern identity protocols, including OAuth, OIDC, and workload identity standards, as Falconâs architecture evolves., For candidates in the United States, please see a full copy of our Equal Employment Opportunity policy here.
Jones Lang LaSalle (âJLLâ) is an Equal Opportunity Employer and is committed to working with and providing reasonable accommodations to individuals with disabilities. If you need a reasonable accommodation because of a disability for any part of the employment process - including the online application and/or overall selection process - you may email us at HRSCLeaves@jll.com. This email is only to request an accommodation. Please direct any other general recruiting inquiries to our Contact Us page > I want to work for JLL.
Pursuant to the Arizona Civil Rights Act, criminal convictions are not an absolute bar to employment.
Pursuant to Illinois Law, applicants are not obligated to disclose sealed or expunged records of conviction or arrest.
Pursuant to Columbia, SC ordinance, this position is subject to a background check for any convictions directly related to its duties and responsibilities. Only job-related convictions will be considered and will not automatically disqualify the candidate.
California Residents only
If you are a California resident as defined in the California Consumer Privacy Act (CCPA) please view ourSupplemental Privacy Statement which describes your rights and disclosures about your personal information.If you are viewing this on a mobile device you may want to view the CCPA version on a larger device.
Pursuant to the Los Angeles Fair Chance Initiative for Hiring Ordinance, JLL will consider for employment all qualified Applicants, including those with Criminal Histories, in a manner consistent with the requirements of applicable state and local laws, including the City of Los Angelesâ Fair Chance Initiative for Hiring Ordinance.
Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.
Requirements
-
6+ years of security engineering experience, including meaningful time embedded directly within a software product or engineering team rather than in a purely advisory security function.
-
Strong software engineering skills, with the fluency to read, write, and review production code alongside the engineers youâre partnered with.
-
Hands-on experience with agentic AI architectures, including MCP servers, tool-calling, and the Claude Agent SDK or a comparable agent framework.
-
Deep working knowledge of identity and access concepts, including OAuth/OIDC, service-to-service authentication, and least-privilege credential design for both human and non-human identities.
-
Demonstrated ability to operate as a technical peer to software engineers, not just a reviewer, earning influence through credibility rather than process authority.
-
Excellent cross-functional communication skills-able to represent a single product teamâs architecture accurately to the broader security organization and vice versa.
PREFERRED QUALIFICATIONS
-
Bachelorâs degree in Computer Science, Engineering, or a related field, or equivalent practical experience.
-
Prior experience as an embedded or product security engineer within an agile product team.
-
Direct experience securing multi-agent systems, RAG pipelines, or MCP-based tool integrations in production.
-
Familiarity with the OWASP LLM Top 10, MITRE ATLAS, or comparable agentic and AI threat frameworks.
-
Experience with workload identity frameworks, such as SPIFFE/SPIRE, or modern non-human identity management.
-
Certifications such as CISSP, OSCP, or GIAC credentials focused on application or cloud security.
This position does not provide visa sponsorship. Candidates must be authorized to work in the United States without sponsorship.
Benefits & conditions
This range is an estimate and actual compensation may differ. Final compensation packages are determined by various considerations including but not limited to candidate qualifications, location, market conditions, and internal considerations., JLL recognizes the impact that the workplace can have on your wellness, so we offer a supportive culture and comprehensive benefits package that prioritizes mental, physical and emotional health. Some of these benefits may include:
- 401(k) plan with matching company contributions
- Comprehensive Medical, Dental & Vision Care
- Paid parental leave at 100% of salary
- Paid Time Off and Company Holidays
- Early access to earned wages through Daily Pay
About the company
Our people at JLL are shaping the future of real estate for a better world by combining world class services, advisory and technology for our clients. We are committed to hiring the best, most talented peopleand empowering them tothrive, grow meaningful careers and to find a place where they belong. Whether youâve got deep experience in commercial real estate, skilled trades or technology, or youâre looking to apply your relevant experience to a new industry, join our team as we help shape a brighter way forward., Jones Lang LaSalle (JLL), together with its subsidiaries and affiliates, is a leading global provider of real estate and investment management services. We take our responsibility to protect the personal information provided to us seriously. Generally the personal information we collect from you are for the purposes of processing in connection with JLLâs recruitment process. We endeavour to keep your personal information secure with appropriate level of security and keep for as long as we need it for legitimate business or legal reasons. We will then delete it safely and securely.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on diversityjobs.comGood distractions
Talks and stories from around this role â technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Dev Digest 210: AI Agents Are Go! Is MCP Dead? LLMs Crack Anonymity
Dev Digest 196: AI Killed DevOps, LLM Political Bias & AI Security
Dev Digest 164: AI Agents, AI Blindspots and MCP security problems
Got AI ideas but no money? Here are 10 free ways to level up your AI skills with Google Cloud