Principal Engineer - Secure AI (Remote Eligible
Minneapolis, Hennepin County, Minnesota, 55444, USA
Listed on 2026-08-05
-
IT/Tech
Cybersecurity, Information Security & Data Protection, Systems Engineer, AI Engineer (Applied/Software)
Principal Engineer
As a Principal Engineer, you'll collaborate with technical and leadership teams across Target Tech to assess, validate, and continuously improve the security of AI systems and platforms. You will identify security risks and gaps in existing AI implementations, evaluate the effectiveness of security controls and mitigations, perform architectural and technical reviews, and provide actionable recommendations to strengthen the overall security posture of AI solutions.
This role is highly technical, requiring deep expertise in AI security, threat modeling, security controls, testing methodologies, and industry standards. You will serve as a trusted advisor and hands-on expert, helping teams identify emerging risks, validate security assumptions, and drive continuous improvements as AI capabilities are deployed, scaled, and evolved across the enterprise.
Beyond the deep expertise, you have great interpersonal skills: our Principal Engineers are called upon to collaborate across the enterprise and have exceptional communication skills that enable open and cooperative partnerships.
Expect to:
- Collaborate with AI platform, product, and engineering teams to evaluate the security posture of AI systems throughout their lifecycle
- Assess AI architectures, models, agents, and supporting infrastructure to identify security risks, vulnerabilities, and design weaknesses
- Develop and execute security validation strategies for AI systems, including threat modeling, attack simulation, and adversarial testing
- Evaluate the effectiveness of existing security controls, guardrails, and mitigations protecting AI applications and platforms
- Identify emerging AI-specific threats, attack techniques, and vulnerabilities, and communicate their potential business impact
- Recommend risk mitigation strategies and prioritized remediation plans to improve the security and resilience of AI systems
- Conduct deep technical reviews of AI products, platforms, and architectures to identify opportunities for security improvement
- Partner with engineering teams to validate secure deployment patterns for AI workloads across cloud and hybrid environments
- Define security assessment methodologies, testing frameworks, and assurance standards for AI technologies
- Provide expert guidance on AI security best practices, including model security, prompt injection defenses, agent security, supply chain security, and data protection
- Prioritize high-impact security improvements that measurably reduce risk while enabling innovation and business objectives
- Perform hands-on security analysis and testing of complex AI-enabled systems, identifying gaps in architecture, implementation, and operational controls
- Collaborate with security, architecture, and engineering teams to continuously improve AI security controls and governance practices
- Efficiently assess and communicate security risks to stakeholders, balancing technical realities, business priorities, and organizational objectives
- Serve as a trusted advisor on AI security, helping teams make informed decisions as AI capabilities evolve across the enterprise
Core responsibilities of this job are described within this job description. Job duties may change at any time due to business needs.
About You:
- 4-year degree OR equivalent experience
- Polyglot programmer comfortable in many languages across different platforms
- 10+ years of hands-on experience in technology, with extensive knowledge of cybersecurity domains including Information Protection, Cloud Security (GCP strongly preferred), Networking Security, IAM, Automation, and SIEM
- LLM Security expertise (RAG, MCP, Input validation, Sandboxing etc.)
- In-depth understanding of OWASP top 10 for Large Language Model Applications
- Expertise in AI and ML
- Understanding of prompt injection and its various styles (direct, indirect, RAG poisoning, etc) / Familiarity with OWSAP top ten for LLMs
- Understanding of MCP auth patterns including dynamic client registration
- Knowledge in RAG authorization patterns - "How do you implement RBAC in a RAG?"
- Understanding of OAuth roles and flows, and how it pertains to minimizing risky permissions
- Experience mitigating the security risks…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).