Job Closed

This listing is no longer active.

FICO logo
FICO

FICO is an analytics company helping businesses make better decisions that drive higher levels of growth and success.

Principal Data and AI Security Architect

Security EngineerSecurity EngineerOtherRemoteLeadTeam 1,001-5,000Since 1956H1B No SponsorCompany SiteLinkedIn

Location

United States

Posted

174 days ago

Salary

$161K - $253K / year

Seniority

Lead

Job Description

Principal Data and AI Security Architect

FICO

• Secure the design of AI and ML capabilities within FICO Platform, services and corporate tools. • Provide full-stack security architecture design from cloud infrastructure to application features for FICO and internal customers. • Oversee security aspects of Analytical Model Life Cycle, and influence stakeholders for adopting best security standards and implementations. • Define comprehensive data security strategy and guide implementation of enterprise-wide data protection programs including DLP, data classification, security logging, and data protection controls across products and enterprise systems. • Proof the security implementations within infrastructure & application deployment manifests and the MLSecOps pipeline. • Define required controls and capabilities for the protection of FICO AI and data services and environments and collaborate with architects, developers and product managers, to implement security controls at scale. • Design, Implement and manage scalable security controls and automation in a DevOps environment within public clouds (AWS, Azure, GCP, Oracle) across IaaS, PaaS, SaaS, and container platforms. • Integrate security in depth throughout FICO software delivery processes and pipelines.

Job Requirements

  • Experience in securing AI and ML models and data systems, as well as building MLSecOps and data security controls.
  • Knowledge of adversarial techniques within the analytics domains, and AI related threats and mitigation strategies.
  • Experience designing and implementing enterprise data security programs including Data Loss Prevention (DLP), data classification frameworks, data governance controls, and data protection strategies across cloud and on-premises environments.
  • Experience in architecture, security reviews and requirement definition for complex environments.
  • Experience in threat modeling, code reviews, security testing, vulnerability detection, attacker exploit techniques, and methods for their remediation.
  • Hands-on experience with programming languages, such as: Java, Python, etc.
  • Experience deploying and securing cloud environments, preferably AWS with focus on data security services and data lake/warehouse security architectures.
  • Hands-on experience with IaC (Terraform, Cloudformation, Helm) and CI/CD pipelines (Github, Jenkins, JFrog).
  • Experience with security testing at scale and integration of security controls into CI/CD workflows for rapid deployments.
  • Familiarity with industry regulations, frameworks, and practices. For example, PCI, ISO 27001, NIST, GDPR, CCPA, and data privacy regulations.
  • Ability to articulate complex architectural challenges with the business leadership and product management teams.
  • Independently drive transformational security projects across teams and organizations.

Benefits

  • An inclusive culture strongly reflecting our core values: Act Like an Owner, Delight Our Customers and Earn the Respect of Others.
  • The opportunity to make an impact and develop professionally by leveraging your unique strengths and participating in valuable learning experiences.
  • Highly competitive compensation, benefits and rewards programs that encourage you to bring your best every day and be recognized for doing so.
  • An engaging, people-first work environment offering work/life balance, employee resource groups, and social events to promote interaction and camaraderie.

Related Categories

Related Job Pages

More Security Engineer Jobs

Included Health logo

Senior Security Engineer

Included Health

Access. Answers. Advocacy. We're raising the standard of healthcare for everyone.

Security Engineer174 days ago
OtherRemoteTeam 1,001-5,000H1B Sponsor

• Design, build, and implement Just-in-Time (JIT) access controls and Privileged Access Management (PAM) workflows to eliminate standing privileged accounts in production. • Conduct platform permission reviews and implement a least-privilege access model for cloud and application roles. • Ensure 100% of production access requests and approvals are captured in audit logs. • Lead the implementation, tuning, and operation of security tools in the CI/CD pipeline, including SAST, DAST, SCA, and secrets scanning. • Develop custom SAST rules to detect specific, high-risk flaw patterns, such as authorization bypasses or insecure PII/PHI handling. • Partner with engineering to deploy IDE plugins and automated PR checks that block sensitive data exposure before deployment. • Conduct manual security code reviews for high-risk features and cryptographic implementations. • Design, build, and maintain automation for the end-to-end vulnerability management lifecycle. • Engineer automated workflows to triage, validate, and assign new vulnerabilities • Develop and maintain security automation scripts, tools, and services in Python or Go to streamline security operations and compliance checks. • Partner with SecOps to build high-fidelity SIEM correlation rules and automated response playbooks. • Design, implement, and maintain encryption strategies for data at rest and in transit, ensuring PHI is protected in compliance with HIPAA. • Manage the cryptographic key lifecycle and administer key management systems • Design and implement secure cloud network architectures (VPCs, subnets, security groups, NACLs) and network segmentation strategies. • Lead the remediation of cloud security findings • Implement and manage a centralized security control plane • Design and implement Data Loss Prevention (DLP) policies for endpoints and cloud services to protect against sensitive data exfiltration. • Design and enforce security configurations and hardening standards for diverse operating systems (macOS, Windows, Linux) via MDM/UEM platforms. • Manage and tune endpoint security solutions, including EDR/XDR (e.g., CrowdStrike). • Lead threat modeling sessions for new features and conduct secure design reviews of system architectures, applications, and APIs. • Act as an embedded security partner and subject matter expert for product and platform teams, providing technical guidance and mentorship. • Develop and manage security programs for emerging risks, including SaaS security and AI security.

United States
$128.1K - $235.3K / year
Olo logo

Staff Security Engineer, Blue Team

Olo

Olo is a leading open SaaS platform for restaurants that enables hospitality at every touchpoint.

Security Engineer174 days ago
OtherRemoteTeam 501-1,000Since 2005H1B No Sponsor

• Guide and coach Olo’s Blue Team on Information Protection, Incident Detection and Response and Service Delivery. • You will provide strategic and technical oversight to the team and the program. • Technically lead a team of security engineers and analysts who hunt, detect, and respond to internal and external threats. • Collaborate with customers and partners to strengthen their security posture. • Drive ongoing optimizations by implementing new technologies, replacing technologies, addressing evolving threats, scaling practices and automating security activities. • Ultimately you will keep team member and customers data safe by identifying and mitigating vulnerabilities and risks by providing actionable guidance to product teams.

New York
Ivanti logo

Security Data and Risk Analyst

Ivanti

Ivanti finds, heals and protects every device, everywhere – automatically.

Security Engineer174 days ago
OtherRemoteTeam 1,001-5,000Since 1985H1B Sponsor

• Lead the execution of multiple functions: Taking ownership of and creating awareness around security-relevant key performance and key risk indicators • Develop automation for data gathering, analysis and presentation using Python and Go • Educate as well as inform audiences of a wide variety of security and risk expertise, including building libraries of material to support understanding of benefits and costs of security management. • Generating insights and supporting information for decisions to be made including wrangling data from complex data sets and data sources • Create dynamic dashboards and presentations • Articulate risk and risk management as realistic, measurable harm; Create dynamic dashboards and presentations • Support the Security Governance and executive workstreams, including analysis and presentations materials. • Coordinate, chair and present data to management, leadership and C-suite stakeholders in their languages.

United States
OtherRemoteTeam 1,001-5,000Since 2006H1B No Sponsor

• Define and lead the product security strategy for the medical device portfolio. • Ensure robust protection of patient data, device integrity, and regulatory compliance. • Partner with executive leadership, engineering, product management, regulatory, quality, and privacy teams. • Oversee end-to-end product security management including risk assessments and incident response. • Ensure compliance with FDA, HIPAA, GDPR, and international cybersecurity regulations and standards. • Drive alignment across engineering, regulatory, privacy, and quality teams. • Recruit, mentor, and develop a team of product security experts.

United States
$215K - $280K / year
Job Closed