AI Security Engineer

MCCARTHY & COMPANY, P.C.
United States
2 days ago
Apply on jobs.military.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours

Tech stack

Application Programming Interfaces (APIs) Artificial Intelligence Application Lifecycle Management Software System Penetration Testing Audit Trail Cloud Computing Security Cloud Engineering Cyber Security Information Systems Data Governance Monitoring of Systems Open Web Application Security
+9 more
Role-Based Access Control Security Information and Event Management Software Engineering Systems Integration Data Classification Retrieval-Augmented Generation Large Language Models Information Technology Devsecops

Requirements

  • Bachelors degree in cybersecurity, computer science, information systems, engineering, or a related field, or equivalent professional experience.\n
  • Minimum five years of proven experience in an established security architecture, security engineering, architecture, or engineering role.\n
  • Working experience handling AI security in a production environment, including the assessment, governance, monitoring, or protection of AI applications, models, agents, or integrations.\n
  • Strong understanding of cybersecurity principles, including identity governance, least privilege, data protection, risk assessment, incident response, security architecture, and security governance.\n
  • Familiarity with OWASP LLM and AI risks, including prompt injection, indirect injection, jailbreaks, sensitive information disclosure, excessive agency, insecure output handling, and agent or tool-use security.\n
  • Practical understanding of generative AI architectures, large language models, retrieval-augmented generation, AI agents, APIs, and model or application lifecycle risks.\n
  • Ability to explain how risks such as indirect prompt injection or excessive agency would surface in a real agent workflow and how those risks could be detected, validated, and mitigated.\n
  • Experience evaluating security controls, technology vendors, data handling practices, privacy considerations, and third-party risk.\n
  • Ability to develop clear standards and communicate complex technical risks to engineers, product teams, business leaders, and executives.\n
  • Strong analytical, written, verbal, collaboration, and problem-solving skills.\n
  • Sound judgment, personal integrity, curiosity, and a demonstrated commitment to protecting confidential information.\n, * Experience with AI-security, application-security, cloud-security, data-security, DevSecOps, or security-monitoring tools.\n
  • Experience performing AI red teaming, adversarial testing, penetration testing, threat modeling, or control validation.\n
  • Familiarity with the NIST AI Risk Management Framework or comparable AI-governance frameworks.\n
  • Experience integrating security controls into software development, cloud engineering, or platform operations.\n
  • Familiarity with data classification, DLP, audit logging, security information and event management, and privacy-by-design practices.\n
  • Relevant certifications such as CISSP, Security+, or a portfolio demonstrating comparable practical experience.\n

Benefits & conditions

n As a member of the Cybersecurity team, the engineer will work closely with AI, engineering, architecture, legal, and compliance teams. The organization has existing AI tools and controls in place, and this role will assess their effectiveness, recommend additional capabilities where needed, and mature the overall AI security toolset over time. Rather than building an AI-security stack from scratch, the engineer will configure, tune, validate, operate, and extend existing security solutions while helping teams apply practical secure-by-design practices.\n \n The ideal candidate combines hands-on security architecture or engineering experience, production AI-security experience, and the ability to explain complex risks clearly to both technical and non-technical audiences.\n \n \nRESPONSIBILITIES\n \n \n

  • Develop and maintain enterprise AI security standards, control requirements, and risk-based review processes.\n
  • Assess AI applications, models, agents, APIs, integrations, vendors, and data flows before and after deployment.\n
  • Define security requirements for AI systems across design, development, testing, deployment, operation, and retirement.\n
  • Evaluate identity, access, identity governance, data protection, privacy, logging, monitoring, retention, and human-oversight controls.\n
  • Test AI systems and agent workflows for prompt injection, indirect injection, jailbreaks, data leakage, excessive agency, unsafe tool use, insecure integrations, and configuration drift.\n
  • Conduct threat modeling, architecture reviews, security assessments, and control validation for AI-enabled solutions.\n
  • Establish processes for AI security findings, incident response, exception management, remediation, and executive reporting.\n
  • Review AI vendors, models, third parties, subprocessors, data handling practices, and material platform or configuration changes.\n
  • Configure, tune, validate, operate, and extend existing AI-security, AI-governance, application-security, data-security, and monitoring tools.\n
  • Support the evaluation and integration of additional capabilities where existing controls require enhancement.\n
  • Create practical security patterns, reference architectures, playbooks, standards, and guidance for engineering and product teams.\n
  • Monitor emerging AI threats, vulnerabilities, standards, regulations, and industry practices and translate them into actionable improvements.\n
  • Partner with development and platform teams to integrate security controls into AI development and deployment workflows.\n
  • Communicate technical risks, business impact, and recommended actions to both technical and non-technical stakeholders.\n
  • Promote responsible AI adoption through measurable controls, clear accountability, and continuous improvement.\n, McCarthy is proud to be an equal opportunity employer, including disability and protected veteran status.\n \n \nNOTICE TO EXTERNAL SEARCH FIRMS: McCarthys Talent Acquisition Team is the \nonly authorized representative permitted to engage with external search firms, staffing agencies, or other third-party recruiting partners. McCarthy maintains an Approved Agency List for recruiting partners, which is reviewed and updated annually.\n \n McCarthy will only consider submissions from agencies with a signed fee agreement in place for the current year. McCarthy does not accept unsolicited resumes, candidate submissions, or referrals from agencies that do not meet these requirements.\n \n If a candidate is submitted without an active agreement, McCarthy will have no obligation to pay any fees and reserves the right to contact, engage, interview, or hire such candidate(s) without any financial or other responsibility to the submitting agency. Unsolicited resumes, including those sent directly to hiring managers or other employees, will be considered the property of McCarthy.\n \n PI286761868”, “hiringOrganization”: {“@type”: “Organization”, “name”: “McCarthy Building Companies, Inc.”}, “jobLocation”: {“address”: {“addressCountry”: “United States”, “streetAddress”: “Not specified”, “@type”: “PostalAddress”, “postalCode”: “63101”, “addressLocality”: “St. Louis”, “addressRegion”: “Missouri - MO”}, “@type”: “Place”}, “industry”: “”, “identifier”: {“@type”: “PropertyValue”, “name”: “McCarthy Building Companies, Inc.”, “value”: “286761868”}, “baseSalary”: {“@type”: “MonetaryAmount”, “currency”: “USD”, “value”: {“@type”: “QuantitativeValue”, “value”: “Competitive”, “unitText”

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on jobs.military.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

3:56 min

Leveraging GitOps for AI auditing and instant rollbacks

Jaroslaw Gajewski Jaroslaw Gajewski · World Congress 2026 Europe

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

3:00 min

Top security vulnerabilities for AI applications

Deepu Deepu · World Congress 2025

2:09 min

Shifting security left using the DevSecOps approach

Aarno Aukia · LIVE

1:20 min

Utilizing industry threat models for AI security

Balázs Kiss · World Congress 2023

Videos

See all

Related articles

See all