Dereck Davis - Senior AI Security Engineer; Artificial Intelligence Security Posture Management; AiSPM
Listed on 2026-08-26
-
IT/Tech
Cybersecurity, Information Security & Data Protection, Security Management & Operations
Please review the following job description:
This role is 5 days a week in the Atlanta or Charlotte Office
Regular or Temporary:
Regular
Language Fluency:
English (Required)
Work Shift:
1st shift (United States of America)
The Artificial Intelligence Security Posture Management (AiSPM) function supports two core areas:
Shadow Artificial Intelligence (Shadow AI) risk reduction and AI Security Review/Governance for enterprise AI use cases.
This Senior AI Security Engineer will help identify, evaluate, document, and reduce AI-related security risk across approved, emerging, and unapproved AI usage patterns.
The role uses security and governance tooling such as Crowd Strike, Wiz, Zscaler, and supporting enterprise workflows to analyze AI exposure, validate ownership, support remediation, and maintain repeatable review evidence.
Strong candidates will understand cloud security, software security, data protection, security governance, and enterprise risk management, with the ability to translate technical AI risks into clear actions for engineering, security, and .
ESSENTIAL DUTIES AND RESPONSIBILITIESSupports the Artificial Intelligence Security Posture Management function by identifying, evaluating, documenting, and reducing security risk associated with enterprise AI usage.
Investigates Shadow Artificial Intelligence observations from tools such as Crowd Strike, Wiz, and Zscaler, validating usage context, ownership, business purpose, and potential exposure.
Performs AI Security Reviews for proposed or existing AI use cases, reviewing intake details, data sensitivity, model or service interactions, control coverage, and residual risk.
Partners with application, infrastructure, business, and security teams to confirm AI asset ownership, assess risk, identify required controls, and track remediation or governance outcomes.
Documents review evidence, risk gaps, action items, and decision rationale in a clear, repeatable, and audit-ready manner aligned to established security guidance and governance processes.
Analyzes telemetry, alerts, inventories, and workflow records to identify trends in AI usage, prioritize risk reduction, and support executive or operational reporting.
Contributes to the development and refinement of AI security review procedures, intake checklists, escalation paths, knowledge articles, and operational playbooks.
Supports escalation of higher-risk AI observations to appropriate security partners, including Security Operations Center teams, incident response partners, and risk or governance stakeholders when warranted.
Communicates technical and governance findings in plain language, helping stakeholders understand AI risk, required controls, remediation expectations, and approval dependencies.
Maintains awareness of emerging AI security risks, detection methods, governance practices, and tooling capabilities to improve the effectiveness of the AiSPM program over time.
Bachelors degree or equivalent education, training, and work-related experience.
Minimum of 7 years of experience in security engineering or related cybersecurity roles.
Deep specialized knowledge in cybersecurity principles, theories, and concepts.
Proven experience in software development lifecycle security practices.
Deep knowledge of threat modeling, security testing, and penetration testing.
Experience implementing and managing complex information security technologies.
Working knowledge of AI security, cloud security, data protection, and governance frameworks, including:
National Institute of Standards and Technology Artificial Intelligence Risk Management Framework (NIST AI RMF)
National Institute of Standards and Technology Special Publication 800-53 (NIST SP 800-53)
Open Worldwide Application Security Project Machine Learning Top 10 (OWASP ML Top 10)
Open Worldwide Application Security Project Large Language Model Top 10 (OWASP LLM Top 10)
Federal Financial Institutions Examination Council (FFIEC) guidance applicable to regulated financial services environments
Cloud Security Alliance guidance related to AI, cloud, and third-party technology risk
Experience reviewing AI use cases, machine learning services, large language model applications, or AI-enabled business workflows for security, privacy, governance, or compliance risks.
Experience using Crowd Strike, Wiz, Zscaler, or similar security tools to investigate endpoint, cloud, network, software, or SaaS-related risk signals.
Experience with security review, risk assessment, exception management, evidence validation, or control mapping in a regulated enterprise environment.
Proficiency or familiarity with Python, Power Shell, Structured Query Language (SQL), or similar scripting and analysis methods used to normalize data, support investigations, and improve repeatable reporting.
Relevant security certifications such as Certified Information Systems Security Professional (CISSP), Certified Cloud Security Professional (CCSP), Security+, or similar…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).