Principal Architect, Product Security

ACV, Inc.
Buffalo, United States
4 days ago
Apply on www.dice.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
2 years minimum
Working hours
Regular working hours
Languages
English
Job source

Tech stack

Artificial Intelligence Amazon Web Services Computer Vision Burp Suite Cloud Computing Security Cyber Security Information Leak Prevention Github Information Systems Security Architecture Professional Python (Programming Language) Machine Learning Open Web Application Security
+15 more
Azure Machine Learning Sherwood Applied Business Security Architecture Secure Coding Large Language Models Multi-Agent Systems Sonatype Software Security Containerization Kubernetes Free and Open-Source Software Machine Learning Operations Checkmarx Api Design Static Application Security Testing Dynamic Application Security Testing

Job description

Company-wide security architect for AI systems and the applications built around them. Defines ACV’s target-state secure architecture, reference architectures, and standards for machine learning and LLM-powered systems, and guides the highest-risk AI and application designs across engineering. A P6 architecture-track role alongside Principal Engineer on the Product Security Career Ladder. Company / multi-year scope; owns AI and application security architecture and standards; sets direction on the most consequential design decisions.

Focus areas: this role spans AI/ML security and application security. It is a technical architecture role. ACV’s AI Governance function owns policy, risk registers, and regulatory alignment; this role owns the technical controls and architecture that make those policies real in production systems.

What you will do:

  • Actively and consistently support all efforts to simplify and enhance the customer experience.
  • Define ACV’s target-state secure architecture and reference patterns for AI/ML systems: LLM features, retrieval pipelines, agentic workflows, and the computer vision models behind vehicle condition and pricing.
  • Protect the integrity of ACV’s vision-based condition and pricing pipeline against adversarial inputs and manipulated or AI-generated imagery, partnering with fraud and inspection teams on detection and image-provenance controls.
  • Set secure-by-default standards adopted across engineering for AI development: prompt injection defense, output handling, tool and agent permissioning, and model and training-data supply chain security.
  • Threat model and review the highest-risk AI and application designs, applying frameworks such as MITRE ATLAS and the OWASP Top 10 lists for LLM and Agentic Applications.
  • Own the security architecture for AI-assisted engineering: coding assistants, MCP servers, and autonomous agents, with guardrails that preserve developer velocity across an API-first engineering organization.
  • Stand up ACV’s AI security testing capability: adversarial testing and red-teaming of models and LLM features, evaluation harnesses, and runtime guardrails, making deliberate build-vs-buy decisions.
  • Advise engineering and security leadership on multi-year AI security strategy, and partner with AI governance to translate policy into enforceable technical controls.
  • Scale AI security expertise across engineering, including through ACV’s Security Champions program; mentor Staff and Principal engineers; and represent ACV’s AI security architecture externally.
  • Perform additional duties as assigned., Compensation: The compensation range for this position is listed in the “Job Details” section at the bottom of this posting. Please note that final compensation will be determined based upon the applicant’s relevant experience, skill set, location, business needs, market demands, and other factors as permitted by law.

Requirements

  • Ability to read, write, speak and understand English.
  • Bachelor’s degree in a related field, or commensurate experience.
  • 12+ years’ of security experience, 15+ years’ without degree, including deep application security architecture.
  • Hands-on GenAI/LLM security work required, demonstrated through production experience or a verifiable body of work: AI red-team engagements, published research or tooling, open-source contributions, or AI security competition results.
  • 2+ years of production AI security experience preferred.
  • Security architecture: owns the enterprise secure-architecture vision for AI systems and application security.
  • AI/ML security depth: LLM application threats (prompt injection, insecure output handling, data leakage through retrieval, excessive agency in agents and tools) and model-level threats (poisoning, evasion, extraction, malicious pre-trained models).
  • Hands-on technical fluency: reads and writes code (Python preferred) and has personally used AI security tooling (e.g., Garak, PyRIT, promptfoo, or equivalent) rather than only evaluating vendors.
  • Frameworks: working fluency with the OWASP Top 10 for LLM Applications, the OWASP Top 10 for Agentic Applications, MITRE ATLAS, and NIST AI RMF, and the ability to turn them into standards engineers actually follow.
  • Standards and patterns: defines reference architectures and paved-road standards, including for AI-assisted development.
  • Influence: aligns engineering and ML leadership to the target architecture.
  • Application security (commensurate with level): OWASP Top 10, secure code review, threat modeling, and SAST/DAST/SCA tooling (e.g., Snyk, Checkmarx, GitHub Advanced Security, Burp Suite).
  • Cloud security (commensurate with level): cloud-native security on AWS, Kubernetes, and infrastructure-as-code; familiarity with ML platforms and inference infrastructure (e.g., SageMaker, Bedrock) a plus.
  • Comfort working in a fast-paced, cloud-native environment with clear written and verbal communication.
  • Illustrative credentials (a plus, not required): SABSA or equivalent architecture credentials, CCSP or a cloud security specialty. A demonstrated body of AI security work (research, tooling, red-team findings, AI CTF results, open-source contributions) carries more weight than any certification; the AI security credential market is not yet mature.

LI-AM3

Benefits & conditions

If you are looking for a career at a dynamic company with a people-first mindset and a deep culture of growth and autonomy, ACV is the right place for you! Competitive compensation packages and learning and development opportunities, ACV has what you need to advance to the next level in your career. We will continue to raise the bar every day by investing in our people and technology to help our customers succeed. We hire people who share our passion, bring innovative ideas to the table, and enjoy a collaborative atmosphere., At ACV we focus on the Health, Physical, Financial, Social and Emotional Wellness of our Teammates and, to support this, we offer:

  • Multiple medical plans including a high deductible, low cost health plan
  • Company-sponsored (paid) Short-Term Disability, Long-Term Disability, and Life Insurance
  • Comprehensive optional benefits such as Dental, Vision, Supplemental Life/AD&D, Legal/ID Protection, and Accident and Critical Illness Insurance
  • Generous paid time off options, including uncapped vacation days, the greater of 3 paid sick days or in accordance with the applicable state or local paid sick leave law, 6 paid company holidays, 2 floating holidays, parental leave, bereavement leave, jury duty leave, voting leave, and other forms of paid leave as required by applicable law or regulation
  • Employee Stock Purchase Program with additional opportunities to earn stock in the Company
  • Retirement planning through the Company’s 401(k)

About the company

ACV is a technology company that has revolutionized how dealers buy and sell cars online. We are transforming the automotive industry. ACV Auctions Inc. (ACV), has applied innovation and user-designed, data driven applications and solutions. We are building the most trusted and efficient digital marketplace with data solutions for sourcing, selling and managing used vehicles with transparency and comprehensive insights that were once unimaginable. We are disruptors of the industry and we want you to join us on our journey. Our network of brands include ACV Auctions, ACV Transportation, ClearCar, MAX Digital and ACV Capital within its Marketplace Products, as well as, True360 and Data Services.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:12 min

Navigating technical clarity as a global black belt

Chris Heilmann +2 · LIVE

4:37 min

Executing verified publishing workflows on Sonatype Maven Central

Johan Hutting Johan Hutting · World Congress 2024

6:36 min

Funding open source through GitHub Accelerator and Sponsors

Stormy Peters · World Congress 2023

3:44 min

Integrating static security scanning in the build phase

Milecia Mcgregor · LIVE

2:40 min

Using GitHub primitives for internal documentation and corporate operations

Kyle Daigle · Coffee With Developers

3:00 min

Top security vulnerabilities for AI applications

Deepu Deepu · World Congress 2025

Videos

See all

Related articles

See all