Job Closed

This listing is no longer active.

SNHU Careers logo
SNHU Careers

At SNHU, we do life-changing work — and not just for our students. Find out how your life can change, too.

AI Security Engineer

Security EngineerSecurity EngineerFull TimeRemoteSeniorTeam 10,001+Since 1932H1B No SponsorCompany SiteLinkedIn

Location

Alabama + 31 moreAll locations: Alabama | Arizona | Florida | Hawaii | Idaho | Iowa | Kansas | Kentucky | Louisiana | Maine | Nebraska | New Hampshire | New Mexico | North Carolina | North Dakota | Ohio | Oklahoma | Maryland | Massachusetts | Michigan | Mississippi | Missouri | South Carolina | South Dakota | Tennessee | Texas | Utah | Vermont | Virginia | West Virginia | Wisconsin | Wyoming

Posted

66 days ago

Salary

$94.1K - $150.6K / year

Seniority

Senior

Bachelor Degree5 yrs expEnglishCyber Security

Job Description

AI Security Engineer

SNHU Careers

• Document AI system components and data flows, including prompts, context, embeddings, training data, model artifacts, outputs, and agent tool interactions. • In collaboration with the AI team, identify attack surfaces, trust boundaries, and privilege transitions within AI pipelines and agent workflows and perform structured threat modeling for AI systems during design, development, and change cycles in collaboration with the AI team. • In collaboration with the AI team, translate identified threats into concrete, relevant security requirements and engineering tasks in collaboration with the AI team. • Implement technical controls informed by established AI security frameworks (e.g., OWASP LLM Top 10, NIST AI RMF) according to compliance requirements and AI governance guidance. • Design, build, and maintain automated security testing for AI systems within CI/CD pipelines, supports testing for prompt injection, unsafe model behavior, misconfigured access, data exposure, and agent misuse. • Ensure AI security controls are validated during build, deployment, and change cycles, with failures surfaced early to engineering teams. • Implement technical guardrails to protect sensitive data used by AI systems, including retrieval of augmented generation (RAG) pipelines and external data sources. • In collaboration with the AI Team, Design and operate controls for sensitive data identification, minimization, redaction, and leakage prevention—addressing PII and other protected data in prompts, context, embeddings, and outputs to ensure privacy preserving AI operation in production environments. • Design, implement, and maintain security controls across the full AI/ML lifecycle—including data ingestion, training, evaluation, deployment, inference, and CI/CD—covering model artifacts, configurations, embeddings, prompts, and deployment patterns. • Implement and operate runtime safeguards for AI services and agent-based systems, including input and output controls, context isolation, tool use restrictions, and abuse prevention mechanisms (e.g., rate limiting and anomaly detection), ensuring safe operation without breaking functional requirements. • Design security controls that balance safety, system performance, reliability, and developer usability in production of AI services. • Implement and operate secure identity, secrets, and access control patterns for AI services, agents, and integrations, enforcing least privilege, integrating with enterprise IAM and key management systems, and monitoring credential usage and rotation. • Instrument AI systems to produce actionable logging, metrics, and traces; build dashboards and alerts for detecting prompt manipulation, anomalous usage, and unexpected behavior; and integrate AI specific signals into enterprise security operations workflows. • Embed with AI engineering and platform teams to design and maintain technical security controls; develop reusable security components and patterns; contribute documentation and runbooks; and, in collaboration with the AI team, communicate AI security requirements and remediation outcomes to technical, non-technical, and cross functional stakeholders.

Job Requirements

  • 5+ years of experience in IT or cybersecurity, with engineering responsibilities (i.e. IT Security or Application Development)
  • 2 + years of experience securing AI/ML systems or adjacent domains with demonstrated application to AI workloads.
  • Experience with security engineering principles, including authentication, authorization, logging, and monitoring.
  • Experience with AI/ML concepts such as models, training data, inference pipelines, embeddings, and agent frameworks.
  • Experience modeling data flows, trust boundaries, and attack paths in AI systems.
  • Experience mitigating threats such as prompt injection, model poisoning, model theft, and data leakage.
  • Experience implementing controls such as input validation, output filtering, context isolation, and abuse detection.

Benefits

  • High-quality, low-deductible medical insurance
  • Low to no-cost dental and vision plans
  • 5 weeks of paid time off (plus almost a dozen paid holidays)
  • Employer-funded retirement
  • Free tuition program
  • Parental leave
  • Mental health and wellbeing resources

Related Categories

Related Job Pages

More Security Engineer Jobs

Mondelēz International logo

Senior Security Detection Engineer

Mondelēz International

We’re a house of incredible brands providing people with the right snack, for the right moment, made the right way.

Full TimeRemoteTeam 10,001+Since 2012H1B No Sponsor

• Design, develop, and maintain detection rules, alerts, and analytics to identify cybersecurity threats across endpoints, network, identity, cloud, and application platforms. • Collaborate with threat intelligence, threat hunting, and security operations teams to understand emerging threats and translate TTPs into actionable detections. • Continuously monitor the threat landscape and proactively recommend improvements to detection coverage and methodology. • Validate, test, and tune detection content to reduce false positives and improve accuracy, performance, and signal-to-noise ratio. • Partner with incident response teams to provide detection insights, improve alert fidelity, and support investigation workflows. • Maintain and enhance the organization’s detection repository within SIEM and detection platforms, ensuring content stays current with evolving attack techniques. • Develop and refine Data Loss Prevention (DLP) detection policies and monitoring use cases to protect sensitive data and support compliance requirements. • Identify detection gaps and raise risks, working with engineering and security stakeholders to prioritize remediation and improvements.

Texas
$109K - $149.9K / year
Job Closed
Full TimeRemoteTeam 501-1,000Since 1988H1B No Sponsor

• Configure and manage security policies on the firewall, including access rules, traffic filtering, and application control; • Implement and fine-tune firewall rules, defining granular policies aligned with security guidelines and periodically reviewing them to eliminate redundancies or inconsistencies; • Continuously analyze implemented rules to identify obsolete or misconfigured entries, record justifications, and document all changes made to the environment; • Evaluate the impact of rules on critical applications, adjusting them to avoid unintended blocks or network bottlenecks while monitoring the performance of protected services; • Configure specific rules for application and service filtering based on the firewall App-ID, allowing authorized traffic and mitigating risks associated with untrusted applications; • Monitor firewall logs and events to identify suspicious or anomalous activity; • Apply firmware updates and threat signature updates to the firewall according to established guidelines; • Implement hardening practices on the firewall in line with the organization’s security standards; • Perform periodic audits of firewall configurations to verify compliance with internal and regulatory security policies; • Evaluate and adjust NAT (Network Address Translation) and routing configurations on the firewall to ensure correct network operation; • Document security incidents related to the firewall and propose technical recommendations for mitigation; • Collaborate with internal teams in the investigation of incidents involving the firewall; • Prepare technical reports on the firewall security status and performance metrics of implemented policies; • Configure and maintain advanced firewall features such as IPS (Intrusion Prevention System), Threat Prevention, and WildFire; • Conduct periodic scans to detect vulnerabilities in firewall configurations using dedicated tools; • Perform integrity audits of firewall rules and logging systems (logs) within the firewall environment; • Assess the use of privileged accounts and segregation of duties in firewall management during audits; • Implement and manage multifactor authentication (MFA) solutions for firewall access; • Evaluate and configure SSL/TLS traffic control policies on the firewall to prevent encryption-based attacks; • Monitor and respond to security alerts generated by the firewall and integrated with SIEM (Security Information and Event Management) tools; • Configure and manage site-to-site and remote access VPN policies using the firewall’s VPN tools, defining granular rules for authentication and access control based on the environment’s needs (Host Information Profile, split-tunnel traffic, etc.); • Configure segmentation rules for VPN traffic on the firewall, isolating critical networks and limiting lateral access to reduce the spread of threats from remote connections; • Implement SSL/TLS inspection policies for VPN traffic, enabling analysis of encrypted packets without compromising VPN security or performance; • Implement and monitor security policies to protect critical services such as site-to-site and remote access VPNs on the firewall; • Configure and manage access policies based on the Zero Trust Network Access (ZTNA) model; • Monitor and audit access performed via ZTNA; • Perform other information security and firewall-related activities as required by operations.

Brazil
Job Closed
Full TimeRemoteTeam 501-1,000Since 1988H1B No Sponsor

• Configure and manage security policies on Windows operating systems, including GPOs (Group Policy Objects) and access controls; • Monitor event logs on Windows servers and workstations to identify suspicious or anomalous activity; • Apply patches and security updates to Windows systems according to established guidelines; • Configure and monitor multi-factor authentication (MFA) systems in Windows environments; • Implement hardening practices on Windows servers and workstations aligned with the organization's security standards; • Document security incidents related to the Windows environment and provide technical recommendations for mitigation; • Collaborate with internal teams to investigate incidents involving Windows systems; • Prepare technical reports on the security status of Windows systems and performance metrics for tools used; • Configure and maintain local firewalls and other protective tools on Windows systems; • Perform regular scans to detect vulnerabilities on Windows servers and workstations; • Evaluate new security tools and technologies specific to Windows environments and recommend adoption to the responsible team; • Perform integrity audits of critical files and registry systems in Windows environments; • Review the use of privileged accounts and segregation of duties in Windows systems during audits; • Implement and manage data encryption solutions in Windows systems, such as BitLocker, to protect sensitive information; • Evaluate and configure application control policies (application whitelisting/blacklisting) to prevent execution of unauthorized software; • Monitor and respond to security alerts generated by SIEM (Security Information and Event Management) tools specific to Windows environments; • Implement and monitor security policies to protect Active Directory, including analysis of delegated permissions and mitigation of attacks such as Kerberoasting and Pass-the-Hash; • Conduct forensic analysis on compromised Windows systems to identify attack vectors and impacts; • Design resilient and secure architectures for Active Directory infrastructures, including domain segregation, creation of isolated forests, and implementation of granular controls to minimize attack surfaces; • Create and maintain custom scripts (in PowerShell, Python or other languages) to automate tasks such as containment of compromised endpoints, disabling suspicious accounts, malware removal, among others; • Perform other activities related to information security and Windows environments as required by operations.

Brazil
Job Closed
Full TimeRemoteTeam 501-1,000Since 1988H1B No Sponsor

• Develop and apply hardening policies for operating systems, servers, and network devices; • Configure and manage endpoint protection solutions, including antivirus, EDR (Endpoint Detection and Response), XDR (Extended Detection and Response), and device control tools; • Apply security patches and updates to operating systems and applications installed on endpoints; • Perform regular scans on devices to detect vulnerabilities and threats; • Monitor security events on endpoints to identify suspicious or anomalous activity; • Conduct detailed analysis of logs and events to detect anomalous behavior on endpoints; • Document endpoint-related security incidents and propose technical mitigation recommendations; • Support forensic investigations of incidents on devices, documenting attack vectors and recommendations; • Develop and maintain incident response playbooks for scenarios such as ransomware, APTs, and other advanced threats; • Execute incident simulation tests to validate and improve response processes; • Prepare detailed technical reports on incidents, including attack vectors, impacts, and prevention recommendations; • Monitor sources such as NVD, vendor alerts, and CVEs to identify new critical vulnerabilities; • Validate the effectiveness of fixes in controlled environments before applying them to production; • Assess the impact of vulnerabilities from the perspective of regulations such as LGPD (Brazilian General Data Protection Law), ISO/IEC 27001, and other applicable regulations; • Configure and manage network segmentation policies (VLANs, security zones, DMZs) to minimize attack surface; • Implement and optimize Network Detection and Response (NDR) solutions to detect anomalies in internal and external traffic; • Configure and manage Identity and Access Management (IAM) solutions with role-based (RBAC) and attribute-based (ABAC) policies; • Implement and optimize Privileged Access Management (PAM) systems, including automatic password rotation and secure vaults; • Design and implement multi-factor authentication (MFA) flows integrated with critical systems; • Manage user lifecycle (provisioning and deprovisioning), ensuring adherence to policies; • Perform periodic audits of permissions, identifying excess privileges and adjusting policies in PAM; • Monitor privileged account logs to detect anomalous behavior.

Brazil