AI Security Engineer

MetLife
Clarks Summit, PA, United States
about 1 month ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$120,000.0 - $180,000.0
Working hours
Regular working hours
Job source

Tech stack

Kubernetes Security Application Programming Interfaces (APIs) Artificial Intelligence Cloud Computing Cloud Computing Security Cloud Engineering Cyber Security Data Security Distributed Systems Identity and Access Management Intrusion Detection and Prevention Key Management
+14 more
Network Segmentation Open Web Application Security Role-Based Access Control Software Deployment Data Logging Data Classification Spring Cloud Large Language Models Generative AI Kubernetes Infrastructure Automation Frameworks Machine Learning Operations Devsecops Security Orchestration, Automation & Response

Job description

As part of MetLife’s Global Security team, you’ll work alongside world-class experts to protect MetLife, our customers and our colleagues. The team is responsible for managing cybersecurity, IT risks and vulnerabilities, physical security, and more. In this fast-paced, mission-driven environment, you’ll join outstanding teammates to expand your skills, collaborate across the organization and implement innovative approaches to safeguard MetLife when it matters most. Ready to make an impact? Join us if you want to embrace the rapidly evolving environment and use transformative technology to integrate and build security into the foundation of key initiatives across MetLife.

The Opportunity

The Senior Engineer - AI Security Engineering will serve as a senior individual contributor focused on the design, build, deployment, and continuous improvement of security controls for AI systems across the enterprise.

This is a hands-on engineering role for a technically strong practitioner who can partner across security, cloud, platform, and application teams to secure AI use cases at scale.

Core Focus Areas

  • Engineer and operationalize security controls for AI systems, services, and supporting infrastructure

  • Accelerate safe adoption of AI capabilities across business and technology teams

  • Evaluate, pilot, and implement AI security tooling and control frameworks

  • Improve visibility, detection, and risk reduction for enterprise AI usage

  • Provide technical guidance and implementation patterns for secure AI deployment, 1. AI Security Engineering & Platform Controls, * Contribute to the design and implementation of reusable AI security capabilities across enterprise environments

Requirements

  • 5+ years of experience in security engineering, cloud security, platform engineering, or a related technical discipline

  • Experience delivering enterprise-scale security engineering solutions in complex environments

  • Demonstrated success in a senior individual contributor role requiring strong technical ownership and cross-functional collaboration

Core Technical Expertise

  • Strong knowledge of cloud security fundamentals, one or more of the following,

  • IAM

  • Network segmentation

  • Encryption

  • Secrets management

  • Logging and monitoring

  • Least privilege and workload isolation

  • Experience with modern application, platform, and infrastructure security practices

  • Working knowledge of AI/ML systems, one or more of the following:

  • Generative AI and LLM-based services

  • Agentic workflows and AI integrations

  • Model access patterns, APIs, and orchestration layers

  • AI-related architectural risks including MCP and A2A interaction patterns

AI Security Knowledge

  • Understanding of AI security risks, one or more of the following:

  • Prompt injection

  • Sensitive data exposure

  • Insecure or untrusted output handling

  • Model misuse and excessive privilege

  • Third-party and supply chain risks

  • Familiarity with:

  • OWASP Top 10 for LLM Applications

  • Secure AI engineering practices

  • AI risk and governance concepts

Hands-On Engineering Capability

  • Experience in one or more of the following:

  • DevSecOps

  • Platform engineering

  • Infrastructure automation

  • Security engineering for cloud-native applications

  • Working knowledge of:

  • Kubernetes and container security

  • Pods, RBAC, secrets, and network controls

  • Policy enforcement and configuration validation

  • Ability to write or review scripts and automation in support of validation, telemetry, or operational efficiency

Data Security

  • Experience helping secure sensitive data in modern application or AI contexts, one or more of the following:

  • Data classification

  • Access controls

  • Privacy boundaries

  • Retention concepts

  • DLP-related requirements

Mindset

  • Strong curiosity and adaptability in a rapidly evolving technical landscape

  • Practical problem solver with strong engineering judgment

  • Effective communicator able to work across technical and non-technical stakeholders

Preferred Qualifications

  • Experience:

  • Hardening Kubernetes and cloud-native environments at scale

  • Securing software or container supply chains, including SBOM, signing, or integrity validation

  • Implementing runtime security controls and policy enforcement

  • Familiarity with AI ecosystem components such as:

  • Model pipelines and inference services

  • Vector databases and RAG systems

  • AI gateways, proxy layers, and prompt orchestration frameworks

  • Exposure to:

  • Detection engineering and alert tuning

  • Incident triage in cloud-native or distributed environments

  • Security automation for operational efficiency

  • Certifications (Preferred)

  • CCSP or equivalent cloud security certification

  • Microsoft SC-100

  • CKA or CKS

  • AI-related certifications (e.g., AI-900 or similar)

Location Expectation: This is a hybrid role requiring a minimum of 3 days per week in office.

Benefits & conditions

The expected salary range for this position is $120,000- $180,000. This role may also be eligible for annual short-term incentive compensation and stock-based long-term incentives. All incentives and benefits are subject to the applicable plan terms.

Benefits We Offer

Our U.S. benefits address holistic well-being with programs for physical and mental health, financial wellness, and support for families. We offer a comprehensive health plan that includes medical/prescription drug and vision, dental insurance, and no-cost short- and long-term disability. We also provide company-paid life insurance and legal services, a retirement pension funded entirely by MetLife and 401(k) with employer matching, group discounts on voluntary insurance products including auto and home, pet, critical illness, hospital indemnity, and accident insurance, as well as Employee Assistance Program (EAP) and digital mental health programs, parental leave, paid time off, paid holidays, volunteer time off, tuition assistance and much more!

About MetLife

Recognized on Fortune magazine’s list of the ā€œWorld’s Most Admired Companiesā€, Fortune World’s 25 Best Workplaces , as well as the Fortune 100 Best Companies to Work ForĀ®, MetLife, through its subsidiaries and affiliates, is one of the world’s leading financial services companies; providing insurance, annuities, employee benefits and asset management to individual and institutional customers. With operations in more than 40 markets, we hold leading positions in the United States, Latin America, Asia, Europe, and the Middle East.

Our purpose is simple - to help our colleagues, customers, communities, and the world at large create a more confident future. United by purpose and guided by our core values - Win Together, Do the Right Thing, Deliver Impact Over Activity, and Think Ahead - we’re inspired to transform the next century in financial services. At MetLife, it’s [1] #AllTogetherPossible. Join us!

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.juju.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil Ā· LIVE

2:28 min

Understanding Kubernetes architecture and core cluster components

Marc Nimmerrichter Ā· WWC 2022

2:07 min

Implementing business logic leveraging the Spring Cloud framework

Ingo Weichsel Ā· WWC 2023

1:45 min

Addressing active AI incident remediation and broad ecosystem support

Matthew Brady Matthew Brady Ā· WWC Europe 2026

2:09 min

Shifting security left using the DevSecOps approach

Aarno Aukia Ā· LIVE

1:34 min

Transitioning from traditional software development to artificial intelligence consulting

Patrick Schnell Patrick Schnell Ā· Coffee With Developers

Videos

See all

Related articles

See all