Principal AI Security Engineer
Job Description
The Principal AI Security Engineer acts as an enterprise subject-matter expert focused on securing AI platforms and the surrounding ecosystem, including agents, integrations, APIs, data sources, and supporting infrastructure. This role identifies AI-specific threats and converts governance and risk expectations into scalable technical safeguards and reusable security patterns across the organization.
Role Focus
- Serve as the enterprise security expert for AI platforms, AI agents, integrations, APIs, and emerging AI use cases.
- Assess AI-related risks, including prompt injection, data exposure, insecure tool invocation, excessive agency, and adversarial inputs.
Key Responsibilities
- Design, implement, and validate security controls for AI platforms, including data protection, access controls, monitoring, guardrails, and approved data-use patterns.
- Perform security architecture reviews, threat modeling, control assessments, and risk-based evaluations for AI solutions and third-party services.
- Translate policies, governance requirements, and control frameworks into practical technical requirements, implementation plans, and operational processes.
- Develop monitoring, logging, detection, and investigation capabilities for AI activity and integrate relevant telemetry into security operations.
- Partner with Security Operations and incident response teams to strengthen AI-related detection, investigation, and response processes.
- Collaborate across technical and governance teams to incorporate security requirements into AI platforms, services, and workflows.
- Create reusable security patterns, implementation guidance, metrics, and evidence to support engineering, governance, risk, and audit activities.
- Monitor changes in AI technologies, threats, and industry guidance, evolving the organization’s security approach accordingly.
Required Qualifications
- 10+ years of experience in security engineering, cloud security, data security, application security, detection engineering, or a related technical security discipline.
- Experience implementing, operating, or validating security controls such as data protection, DLP, SIEM, cloud security, API security, endpoint security, or application security.
- Experience conducting security assessments, architecture reviews, threat modeling, or other risk-based security evaluations.
- Experience translating security risks and governance requirements into practical technical safeguards and implementation plans.
- Strong understanding of data protection, including sensitive data discovery, classification, encryption, privacy, and secure data handling.
- Strong analytical, communication, and collaboration skills to align technical and nontechnical stakeholders on practical solutions.
- Bachelor’s degree.
Preferred Qualifications
- Experience securing AI platforms, AI agents, machine learning systems, or other emerging technologies.
- Knowledge of AI-specific threats, including prompt injection, model misuse, sensitive data exposure, adversarial inputs, and insecure tool invocation.
- Familiarity with AI architectures and services such as APIs, Model Context Protocol services, retrieval-augmented generation, guardrails, and human-in-the-loop controls.
- Experience automating security processes using scripting, APIs, infrastructure as code, or similar approaches.
- Familiarity with NIST AI RMF, NIST Cybersecurity Framework, ISO/IEC 27001, ISO/IEC 42001, or OWASP guidance for AI applications.
- Experience developing reusable security patterns that support emerging technology adoption while managing risk.
Relevant Technologies and Guidance
- Prompt injection
- DLP
- SIEM
- API security
- Endpoint security
- Model Context Protocol services
- Retrieval-augmented generation
- Guardrails
- Human-in-the-loop controls
- NIST AI RMF
- NIST Cybersecurity Framework
- ISO/IEC 27001
- ISO/IEC 42001
- OWASP
Location and Work Schedule
- Natick, MA (hybrid)
- Hybrid schedule: 3 days at the Natick, MA Headquarters and 2 days work from home
Compensation
USD 231,300 per yearly.