CybersecurityJobs.io
← Back to all jobs

Job Description

Cetera Financial Group is seeking an experienced Principle Security Engineer to help operationalize AI risk and compliance in a regulated financial services environment. This role focuses on embedding AI governance controls, managing AI third-party and vendor risk, and leading adversarial threat modeling for AI/ML systems using MITRE ATLAS.

Based in Oregon (onsite), this position will translate technical findings into audit-ready documentation while partnering across IT Risk, Cloud Security, Legal, Procurement, and Application/AI Engineering to strengthen end-to-end AI intake, procurement, and development processes.

Responsibilities

  • Operationalize AI governance controls by implementing and maintaining controls mapped to recognized AI risk management frameworks, including governance, mapping, measurement, and management of AI risk. Produce control documentation, risk-control matrices (RCM), and evidence to support audits and regulatory exams.
  • Lead AI third-party risk management by evaluating and onboarding third-party AI/ML tools and vendors against security, privacy, and compliance criteria. Document AI-specific vendor and contract requirements, SLAs, and fourth-party disclosures, and support due diligence and data provenance reviews.
  • Maintain AI and vendor risk inventories by documenting third-party AI components such as models, datasets, APIs, and pre-trained or foundation models, including provenance, functionality, and known limitations. Map internal controls to these components.
  • Run ongoing AI risk assessments by conducting recurring reviews for vendor and compliance risks, including AI system performance, data quality, algorithmic bias, and security controls. Monitor pre-trained or foundation model drift and SLA adherence, and assess concentration and dependency risk across AI vendors.
  • Perform AI threat modeling using the MITRE ATLAS framework to identify adversarial tactics and techniques across the AI development and deployment lifecycle, including prompt injection, data and model poisoning, model evasion, model extraction, and supply-chain risk in ML pipelines.
  • Coordinate adversarial testing by planning and driving red-teaming, adversarial testing, and penetration testing of AI/ML systems, using threat intelligence and prior incidents to inform ongoing threat assessments.
  • Integrate AI into vulnerability management by ensuring AI-specific vulnerabilities and security findings are captured, prioritized, and remediated through existing enterprise vulnerability management processes.
  • Identify and assess unsanctioned AI usage by supporting discovery and risk assessment of shadow AI tool usage across the enterprise, with recommendations for remediation or approval pathways.
  • Partner cross-functionally to embed AI risk and compliance requirements into intake, procurement, and development processes.
  • Support governance and audit activities by developing and maintaining AI risk standards, control narratives, and runbooks, and producing control evidence tied to the organization’s AI risk management framework for internal and external audits and regulatory compliance activities (including FINRA).

Requirements

  • 10+ years of experience in IT/cyber risk, GRC, security engineering, or a related discipline, with direct exposure to AI/ML systems.
  • Working knowledge of AI risk and control frameworks (for example, NIST AI RMF or similar) and OWASP Top 10 for LLMs.
  • Practical experience with threat modeling methodologies for AI/ML systems, including familiarity with MITRE ATT&CK and MITRE ATLAS.
  • Experience building or operating third-party/vendor risk management processes, including due diligence, contracting and SLAs, ongoing monitoring, and issue remediation.
  • Understanding of AI-specific attack techniques (prompt injection, data and model poisoning, model evasion, model extraction and inversion) and associated mitigations.
  • Ability to translate technical risk findings into control objectives, policy language, and audit-ready documentation.
  • Experience in regulated environments (financial services or FINRA preferred).
  • Strong communication skills across technical, risk, legal, and compliance stakeholders.

Technologies

  • MITRE ATLAS, MITRE ATT&CK
  • NIST AI RMF, OWASP Top 10 for LLMs
  • FINRA
  • Archer, ServiceNow GRC
  • GRC platforms
  • AWS Bedrock
  • Red team, purple team, penetration testing
  • Model cards, data lineage/provenance tooling
  • AI bill-of-materials (AI-BOM)

Benefits

  • Inclusive health, dental, vision, and life insurance plans
  • Easy access to mental health benefits
  • 20+ days of paid time off (PTO), paid holidays, and 2 paid wellness days
  • 401(k) savings plan with a generous company contribution (up to 5%)
  • Paid parental leave to support all team members with birth, adoption, and fostering
  • Health Savings and Flexible Spending Account options
  • Employee Assistance Program (EAP), LifeLock, pet insurance, and more
  • Paid caregiver leave

Similar Jobs