> Markdown version of [/jobs/ext/616890-lead-ai-security-engineer](https://www.wearedevelopers.com/jobs/ext/616890-lead-ai-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Lead AI Security Engineer - **Company:** Credit One Bank - **Location:** Las Vegas, NV, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Proxy Servers, Audit Trail, User Authentication, Microsoft Azure, Cloud Computing, Cloud Computing Security, Continuous Integration, Data Validation, Information Leak Prevention, Software Design Patterns, DevOps, Key Management, Open Web Application Security, Systems Development Life Cycle, Role-Based Access Control, Trusted Systems, Data Logging, Large Language Models, Software Security, AI Platforms, Kubernetes, Docker - **Published:** June 18, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=252e162d4d4d932d ## About the Role Do you have experience in System design for system development?, * 5+ years of experience in cybersecurity with a strong mix of offensive and defensive security tactics. * Deep familiarity with the OWASP Top 10 for LLM Applications * Hands-on experience with Docker, Kubernetes, and Cloud Security (AWS/Azure/GCP). * Experience designing and securing AI gateways, API proxies, or centralized policy enforcement layers for AI workloads. * Working knowledge of MCP server security and secure tool-integration patterns, including identity, authorization, validation, proxy risks, and logging. * Strong communication skills with the ability to work across Application Security, Cloud Infrastructure, Platform Engineering, and Product Engineering teams. * Familiarity with AI red teaming methodologies and adversarial testing for LLM applications. * Ability to translate complex AI risks into actionable technical requirements for developers and executive stakeholders. * Familiarity with regulatory frameworks (e.g., NIST AI RMF, ISO/IEC 42001) ## Description We are seeking an experienced AI Security Engineer to lead the design, implementation, and operationalization of security controls for our LLM-powered applications, AI platforms, and model-hosting infrastructure. This role will focus on protecting AI systems from prompt injection, sensitive data leakage, insecure tool use, model abuse, and cloud/infrastructure threats, while helping establish secure engineering patterns for the next generation of AI-enabled products. The role sits at the intersection of Application Security, Cloud Security, and AI Platform Engineering. The ideal candidate combines offensive and defensive security expertise with strong experience in secure system design, cloud infrastructure, CI/CD, containers, and modern software delivery pipelines. You will help define and execute new AI security initiatives across the enterprise, especially in a regulated financial services environment where confidentiality, resilience, governance, and auditability are critical. Sector-specific AI governance and risk management expectations are increasingly being formalized through frameworks such as the NIST AI RMF., * Lead security initiatives for LLM-powered applications, copilots, agentic systems, and AI-assisted workflows. * Design and implement controls to reduce the risks of prompt injection, sensitive information disclosure / data leakage, improper output handling, excessive agent autonomy, model and AI supply chain risk, vector / embedding and retrieval-related weaknesses. * Partner with engineering teams to embed secure-by-design patterns into AI application development, deployment, and operations. * Create guardrails for AI systems that process customers, employees, and regulate financial data. * Architect and implement AI gateway controls that centralize security policy enforcement for model traffic, including prompt inspection, response filtering, PII/secret redaction, model access control, rate limiting / abuse prevention, audit logging and evidence generation. * Define runtime security policies for AI interactions across internal applications, APIs, tools, and model providers. * Build detection and response capabilities for malicious prompts, unsafe model behavior, and data exfiltration attempts. * Secure systems built on the Model Context Protocol (MCP) and related AI tool-integration patterns. * Define security requirements for MCP servers, proxy servers, and tool connectors, including authentication and authorization, least privilege, schema/input validation, secrets management, network isolation, sandboxing, logging and auditability, third-party server risk review. * Assess and mitigate risks associated with MCP architecture, including authorization flaws, confused-deputy scenarios, and unsafe execution paths. * Partner with Cloud Security, Platform Engineering, and DevOps to implement hardening, segmentation, identity controls, observability, and incident response readiness. * Work closely with Security, Engineering, Legal, Compliance, Risk, and Product teams to align AI security controls with regulatory and internal risk expectations. * Help define AI security standards, reference architectures, guardrails, and review processes appropriate for a financial industry environment. ## Related Videos - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Understanding Kubernetes in a visual way](https://www.wearedevelopers.com/videos/100085-understanding-kubernetes-in-a-visual-way) - [The New AI Security Stack: Observe, Detect, Protect](https://www.wearedevelopers.com/videos/100302-the-new-ai-security-stack-observe-detect-protect) - [Microservices: how to get started with Spring Boot and Kubernetes](https://www.wearedevelopers.com/videos/242-microservices-how-to-get-started-with-spring-boot-and-kubernetes) - [Docker build without Docker](https://www.wearedevelopers.com/videos/100114-docker-build-without-docker) ## Related Articles - [How to Become an AI Engineer](https://www.wearedevelopers.com/magazine/331-how-to-become-an-ai-engineer) - [MLOps And AI Driven Development](https://www.wearedevelopers.com/magazine/82-mlops-and-ai-driven-development) - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift) - [Got AI ideas but no money? Here are 10 free ways to level up your AI skills with Google Cloud](https://www.wearedevelopers.com/magazine/600-got-ai-ideas-but-no-money-here-are-10-free-ways-to-level-up-your-ai-skills-with-google-cloud) - [Dev Digest 132 - Binging WADFlix?](https://www.wearedevelopers.com/magazine/473-dev-digest-132-binging-wadflix) - [Dev Digest 210: AI Agents Are Go! Is MCP Dead? LLMs Crack Anonymity](https://www.wearedevelopers.com/magazine/709-dev-digest-210-ai-agents-are-go-is-mcp-dead-llms-crack-anonymity)