More jobs:
AI Security Engineer
Job in
Chicago, Cook County, Illinois, 60290, USA
Listed on 2026-07-04
Listing for:
tms (USA)
Full Time
position Listed on 2026-07-04
Job specializations:
-
IT/Tech
Cybersecurity
Job Description & How to Apply Below
WHAT YOU WILL BRING TO THE AGENCY
This role sits at the intersection of traditional security engineering and modern AI‑driven tooling, requiring a practitioner who can evaluate emerging AI capabilities through a security lens while executing core engineering functions across SaaS application reviews, architecture assessments, and third‑party plugin governance.
The ideal candidate brings hands‑on coding proficiency, a working knowledge of secure software development practices, and direct experience securing marketing technology stacks, AI‑integrated platforms, and enterprise SaaS environments.
ROLES AND RESPONSIBILITIES AI ENGINEERING SECURITY- Evaluate AI tools, models, and platforms for security risk, including prompt injection vulnerabilities, data leakage, model output integrity, and supply chain risks.
- Develop and enforce security standards for AI‑assisted development workflows, including LLM‑integrated CI/CD pipelines and code generation tools.
- Assess AI API integrations and third‑party model usage for data handling compliance, authorization controls, and audit logging.
- Participate in the design and review of AI‑powered internal tooling and automation, ensuring security requirements are embedded from inception.
- Stay current on evolving AI security threats including adversarial prompting, model poisoning, and emerging OWASP LLM Top 10 guidance.
- Conduct secure code reviews across multiple languages and frameworks, with an emphasis on Python, JavaScript/Type Script, and cloud‑native applications.
- Apply OWASP principles and industry‑standard secure development lifecycle (SDLC) practices to engineering workflows.
- Perform static and dynamic application security testing (SAST/DAST) and triage findings with development teams through to remediation.
- Collaborate with software engineers to embed security controls into code pipelines, authentication flows, and data handling routines.
- Lead third‑party SaaS application security assessments, evaluating vendor security posture, data handling practices, access control models, and contractual compliance.
- Maintain a SaaS application inventory and risk register, conducting periodic reviews and ensuring ongoing controls alignment.
- Evaluate browser‑based plugins, marketplace extensions, and integrations for privilege scope, data exfiltration risk, and policy adherence.
- Partner with Procurement and Legal during the vendor onboarding process to communicate security requirements and assess residual risk.
- Assess the security posture of marketing platforms including CRMs, CDPs, ad tech stacks, campaign automation tools, and analytics platforms.
- Evaluate data flows between marketing systems and core enterprise infrastructure, identifying excessive data sharing, weak authentication, and shadow IT exposure.
- Support the review and governance of marketing API keys, OAuth tokens, and webhook configurations.
- Partner with Marketing and Digital teams to align platform configuration with data privacy requirements (GDPR, CCPA) and organizational policy.
- Participate in architecture review boards (ARB) to assess new systems and integration patterns for security risk.
- Develop and maintain security reference architectures for SaaS integrations, AI platform connections, and plugin frameworks.
- Contribute to security policies, standards, and playbooks relevant to AI security, SaaS governance, and third‑party risk.
- Support threat modeling exercises for new platform deployments and significant system changes.
- Minimum of 5 years of hands‑on experience in information technology, with a focus on risk management and compliance.
- Comprehensive knowledge of industry market structures and associated regulatory compliance frameworks, such as ISO 27001, SOC 2, NIST, NIS2, and GDPR.
- Demonstrated expertise in identity management standards, as well as cloud‑based storage and disaster recovery strategies.
- Proficiency in utilizing security assessment tools, including but not limited to Rapid
7. - Familiarity with Governance, Risk, and…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×