AI Security Engineer
Job in
Chicago, Cook County, Illinois, 60290, USA
Listed on 2026-09-09
Listing for:
tms
Full Time
position Listed on 2026-09-09
Job specializations:
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Job Description & How to Apply Below
AI Security Engineer
tms seeks an AI Security Engineer to shape the security landscape for world‑renowned brands in a culture that values innovation, authenticity, and inclusion. The role blends traditional security engineering with AI‑driven tooling, requiring expertise in secure software development, AI platform security, and SaaS governance.
Responsibilities AI Engineering Security- Evaluate AI tools, models, and platforms for security risk, including prompt injection vulnerabilities, data leakage, model output integrity, and supply chain risks.
- Develop and enforce security standards for AI‑assisted development workflows, including LLM‑integrated CI/CD pipelines and code generation tools.
- Assess AI API integrations and third‑party model usage for data handling compliance, authorization controls, and audit logging.
- Participate in the design and review of AI‑powered internal tooling and automation, ensuring security requirements are embedded from inception.
- Stay current on evolving AI security threats including adversarial prompting, model poisoning, and emerging OWASP LLM Top 10 guidance.
- Conduct secure code reviews across multiple languages and frameworks, with an emphasis on Python, JavaScript/Type Script, and cloud‑native applications.
- Apply OWASP principles and industry‑standard secure development lifecycle (SDLC) practices to engineering workflows.
- Perform static and dynamic application security testing (SAST/DAST) and triage findings with development teams through to remediation.
- Collaborate with software engineers to embed security controls into code pipelines, authentication flows, and data handling routines.
- Lead third‑party SaaS application security assessments, evaluating vendor security posture, data handling practices, access control models, and contractual compliance.
- Maintain a SaaS application inventory and risk register, conducting periodic reviews and ensuring ongoing controls alignment.
- Evaluate browser‑based plugins, marketplace extensions, and integrations for privilege scope, data exfiltration risk, and policy adherence.
- Partner with Procurement and Legal during the vendor onboarding process to communicate security requirements and assess residual risk.
- Assess the security posture of marketing platforms including CRMs, CDPs, ad tech stacks, campaign automation tools, and analytics platforms.
- Evaluate data flows between marketing systems and core enterprise infrastructure, identifying excessive data sharing, weak authentication, and shadow IT exposure.
- Support the review and governance of marketing API keys, OAuth tokens, and webhook configurations.
- Partner with Marketing and Digital teams to align platform configuration with data privacy requirements (GDPR, CCPA) and organizational policy.
- Participate in architecture review boards (ARB) to assess new systems and integration patterns for security risk.
- Develop and maintain security reference architectures for SaaS integrations, AI platform connections, and plugin frameworks.
- Contribute to security policies, standards, and playbooks relevant to AI security, SaaS governance, and third‑party risk.
- Support threat modeling exercises for new platform deployments and significant system changes.
- Minimum of 5 years of hands‑on experience in information technology, focused on risk management and compliance.
- Comprehensive knowledge of industry market structures and regulatory compliance frameworks (ISO 27001, SOC 2, NIST, NIS2, GDPR).
- Demonstrated expertise in identity management standards, cloud‑based storage, and disaster recovery strategies.
- Proficiency in utilizing security assessment tools, including Rapid
7. - Familiarity with Governance, Risk, and Compliance (GRC) platforms such as ZenGRC, One Trust, and Archer.
- Documented success coordinating and executing multiple risk and compliance initiatives.
- Proven ability to manage third‑party audits, compiling evidence and organizing comprehensive responses.
- Exceptional attention to detail and accuracy.
- Strong written and verbal communication skills, with the ability to…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×