Security Engineer and AI Security Architect
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+31 more
Job description
-
Oversees enterprise security architecture, including security reference architectures, design standards, architectural review of new systems and integrations, and formal security design approval for major initiatives.
-
Engineers and maintains the university’s core security platforms, including SIEM, endpoint detection and response, email security, network security controls, secure web gateway, and data loss prevention; owns platform health, tuning, integration, and lifecycle.
-
Leads detection engineering, including development and tuning of correlation rules, analytics, and use cases mapped to MITRE ATT&CK, and continuous reduction of false positives to improve analyst effectiveness.
-
Oversees cloud security posture across the university’s cloud footprint, including cloud security posture management, cloud identity and entitlement management, infrastructure-as-code scanning, workload protection, and secure landing zone and baseline standards.
-
Defines and advances the university’s zero trust architecture roadmap, including network segmentation, conditional access design, device trust, and least-privilege access patterns.
-
Establishes AI security architecture, including security guardrails and reference patterns for AI-enabled platforms, evaluation of model and data exposure risk, controls addressing prompt injection, sensitive data leakage, insecure output handling, and supply chain risk consistent with the OWASP Top 10 for Large Language Model Applications, and secure integration standards for AI services and agents.
-
Partners with the Manager of Security Governance, Risk, and Compliance to translate AI and cloud architecture decisions into documented, testable controls and audit evidence.
-
Leads threat modeling for high-risk applications, research computing environments, clinical systems, and third-party integrations, and drives remediation and design changes to completion.
-
Engineers and matures the vulnerability management and attack surface management toolchain, including scanning coverage, asset correlation, risk-based prioritization, and remediation reporting.
-
Establishes cryptographic standards and supports encryption, certificate, and key management practices across enterprise and cloud environments.
-
Embeds security into the software development lifecycle in partnership with Enterprise Applications and Digital Platforms, including secure coding standards, static and dependency analysis, secrets management, and pipeline security controls.
-
Serves as the senior technical escalation point for complex security incidents, providing advanced analysis, containment engineering, and forensic support, and leading technical root cause analysis.
-
Provides technical mentorship, design review, and skills development for Security Analysts and other technical staff.
-
Evaluates emerging security technologies, conducts proofs of concept, develops business justification, and advises the CISO on security tooling investment and roadmap.
-
Completes special projects as assigned.
-
Performs other duties as assigned or required.
Requirements
- Comprehensive knowledge of security architecture principles, defense-in-depth design, and zero trust architecture models.
- Comprehensive knowledge of SIEM and endpoint detection and response engineering, detection development, and the MITRE ATT&CK framework.
- Comprehensive knowledge of cloud security across at least one major provider (Amazon Web Services, Microsoft Azure, or Google Cloud Platform), including identity, network, workload, and posture management controls.
- Working knowledge of artificial intelligence and machine learning system architecture and the associated security risks, including model and data exposure, prompt injection, insecure output handling, and AI supply chain risk.
- Working knowledge of identity and access management architecture, including federation, single sign-on, conditional access, and privileged access management.
- Working knowledge of secure software development practices, DevSecOps tooling, container and Kubernetes security, and API security.
- Working knowledge of cryptography, public key infrastructure, and certificate lifecycle management.
- Working knowledge of incident response, digital forensics, and threat hunting methodologies.
Skills:
- Complex Problem Solving - Proficient skills in identifying complex problems and reviewing related information to develop and evaluate options and implement solutions.
- Systems Engineering - Advanced skills in designing, deploying, integrating, and operating enterprise security platforms at scale.
- Automation and Scripting - Proficient skills in at least one scripting or automation language, such as Python or PowerShell, and in infrastructure-as-code tooling.
- Technical Communication - Proficient skills in documenting architecture decisions and explaining technical risk to non-technical stakeholders and executive leadership.
-
Mentorship - Proficient skills in developing the technical capability of less experienced staff. Abilities:
- Ability to make and defend architectural decisions that balance security, usability, academic freedom, and cost.
- Ability to operate as the senior technical authority in a small team without a peer technical reviewer.
- Ability to lead technical work through matrixed teams and vendors without direct supervisory authority.
- Ability to remain effective under pressure during active security incidents.
- Ability to evaluate emerging technology rapidly and reach a defensible recommendation.
Physical Requirements and Working Environment:
- Speech Recognition - Must be able to identify and understand the speech of another person.
- Speech Clarity - Must be able to speak clearly so others can understand you.
- Near Vision - Must be able to see details at close range (within a few feet of the observer).
- Travel - Must be able to travel on a daily and/or overnight basis.
- May be required to work nights or weekends.
- May be exposed to short, intermittent, and/or prolonged periods of sitting and/or standing in performance of job duties.
- May be required to accomplish job duties using various types of equipment/supplies, to include but not limited to pens, pencils, and computer keyboards.
Required Certifications/Licensures: Must possess one of the following certifications at the time of hire or obtain at least one (1) within twelve (12) months of hire and maintain it in good standing throughout employment:
Certified Information Systems Security Professional (CISSP) or equivalent senior security certification.
Required Education: Bachelor’s degree
Major (if required:
Required Experience: 1. Minimum six (6) to eight (8) years’ experience in information technology experience, including security engineering, security architecture, or equivalent technical security roles.
- Experience with engineering enterprise security platforms and securing cloud environments., 1. Experience designing security controls for artificial intelligence or machine learning platforms.
- Experience in higher education, academic health, or research computing environments.
- Experience in a decentralized environment with significant shadow IT and diverse regulatory requirements.
- Experience with managed detection and response provider integration and oversight.
- Experience securing research data environments subject to NIST SP 800-171 or Controlled Unclassified Information requirements.
About the company
Nova Southeastern University (NSU) was founded in 1964, and is a not-for-profit, independent university with a reputation for academic excellence and innovation. Nova Southeastern University offers competitive salaries, a comprehensive benefits package including tuition waiver, retirement plan, excellent medical and dental plans and much more. NSU cares about the health and welfare of its students, faculty, staff, and campus visitors and is a tobacco-free university.
We appreciate your support in making NSU the preeminent place to live, work, study and grow. Thank you for your interest in a career with Nova Southeastern University.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
9 Ways to Make Money Hacking
Best Paying Jobs in Technology
Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence
Got AI ideas but no money? Here are 10 free ways to level up your AI skills with Google Cloud