- Location
- Charlotte NC - 214 North Tryon Street, United States of America
- Type
- Full-time
- Department
- Engineering
- Seniority
- Lead
- Experience
- 10+ years
- Source
- Workday
Description
The position is described below. If you want to apply, click the Apply Now button at the top or bottom of this page. After you click Apply Now and complete your application, you'll be invited to create a profile, which will let you see your application status and any communications. If you already have a profile with us, you can log in to check status.
If you have a disability and need assistance with the application, you can request a reasonable accommodation. Send an email to Accessibility (accommodation requests only; other inquiries won't receive a response).
Regular or Temporary:
RegularLanguage Fluency: English (Required)
Work Shift:
1st shift (United States of America)Please review the following job description:
The AI Security Engineering Lead is a senior technical leader responsible for securing the organization's adoption of artificial intelligence, generative AI, and agentic technologies across the enterprise.This role combines technical leadership, consulting, and hands-on security engineering to ensure AI-enabled solutions are secure, resilient, governed, and production-ready.
Operating within the Forge AI Security organization, this individual serves as a trusted advisor and security partner to engineering, product, platform, architecture, governance, risk, and cybersecurity teams.
The role leads security reviews, architecture assessments, threat modeling exercises, control validations, adversarial testing activities, and deployment readiness reviews for AI-enabled applications, intelligent agents, retrieval-augmented generation (RAG) solutions, and enterprise AI platforms.
The AI Security Engineering Lead works directly with delivery teams throughout the development lifecycle, helping teams identify risks, implement security controls, validate configurations, and remediate findings while accelerating the secure adoption of AI technologies.
This role regularly supports multiple concurrent initiatives, acting as the primary AI security consultant embedded within project teams during critical phases of solution design, build, testing, and deployment.
The position needs a talent with deep expertise in cybersecurity engineering and modern AI technologies, including no-code, low-code, and pro-code development approaches.
The role supports AI solutions operating across cloud platforms, with a primary focus on Microsoft Azure and growing adoption of AWS services, including Amazon Bedrock.
This is a lead individual contributor position that influences technical direction and security outcomes across multiple teams while remaining deeply involved in hands-on implementation, engineering, validation, testing, and operational support activities.
ESSENTIAL DUTIES AND RESPONSIBILITIES
The following is a summary of the essential functions for this role. Other duties may be performed, both major and minor, which are not mentioned below. Specific activities may change from time to time.
AI Security Architecture and Design
Lead security architecture reviews, threat modeling exercises, and design assessments for AI-enabled applications, agents, and enterprise AI platforms.
Define secure design patterns and reference architectures for generative AI, agentic systems, RAG solutions, model integrations, and AI-enabled workflows.
Establish and evolve AI security standards, security guardrails, and technical implementation patterns across the enterprise.
Evaluate new AI technologies and architectures to identify risks, security requirements, and appropriate control strategies.
AI Security Engineering and Implementation
Design, implement, configure, and validate technical security controls for AI-enabled solutions across development, testing, and production environments.
Build and enhance AI security capabilities, including access controls, logging, monitoring, output protections, security automation, and deployment controls.
Develop technical guardrails that reduce the risk of prompt injection, indirect prompt manipulation, unauthorized tool use, sensitive data exposure, privilege escalation, and other AI-specific attack scenarios.
Partner with engineering teams to implement secure patterns for tool calling, workflow orchestration, model access, agent permissions, data retrieval, and external system integrations.
Support security integration within no-code, low-code, and pro-code AI development environments.
Security Reviews and Validation
Lead AI security assessments, control validations, architecture reviews, and deployment readiness evaluations.
Validate that AI solutions meet enterprise security, governance, safety, and compliance requirements before release.
Review implementations for adherence to approved security standards, guardrails, and operational controls.
Conduct hands-on testing and validation activities to identify security weaknesses and implementation gaps.
Support adversarial testing, misuse-case analysis, red-teaming activities, and remediation planning.
Detection, Monitoring, and Response
Design and maintain monitoring, alerting, and detection capabilities for AI and agentic systems.
Develop telemetry requirements and detection logic designed to identify suspicious prompts, anomalous agent behavior, unauthorized tool usage, policy violations, and other security concerns.
Partner with cybersecurity operations and incident response teams to investigate and remediate AI-related security events.
Improve observability capabilities that support the monitoring and operational governance of AI systems.
Consulting and Technical Leadership
Serve as the primary AI security consultant for multiple concurrent delivery initiatives and platform efforts.
Provide practical, actionable security guidance to engineering teams throughout the software development lifecycle.
Translate complex AI security risks into implementable controls, technical requirements, engineering standards, and remediation plans.
Lead technical discussions, design reviews, and security working sessions with stakeholders across engineering, architecture, platform, governance, and cybersecurity functions.
Mentor engineers and project teams on AI security best practices and emerging threat considerations.
Continuous Improvement and Innovation
Research emerging AI threats, attack techniques, industry trends, and defensive technologies.
Recommend and drive improvements to AI security processes, controls, tooling, automation, and operating models.
Contribute to the evolution of enterprise AI security strategy, standards, and governance frameworks.
Continuously improve testing methodologies, monitoring capabilities, validation processes, and deployment controls as AI technologies evolve.
Required Qualifications
The requirements listed below are representative of the knowledge, skill and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
Bachelor’s degree or equivalent education, training, and work-related experience.
Minimum of 10 years of experience in security engineering or related cybersecurity roles.
Deep specialized knowledge in cybersecurity principles, theories, and concepts.
Extensive experience in software development lifecycle security practices.
Expertise in threat modeling, security testing, and penetration testing.
Proven experience implementing and managing complex information security technologies.
Technical Knowledge
Strong understanding of AI and LLM security concepts including prompt injection, indirect prompt injection, jailbreak techniques, sensitive data exposure, model abuse, agent security, output manipulation, tool-use abuse, and retrieval security.
Experience designing, implementing, or validating security controls for AI-enabled applications, AI platforms, intelligent agents, or automation workflows.
Working knowledge of modern AI development approaches including no-code, low-code, and pro-code implementations.
Strong knowledge of cloud-native security principles, identity management, access controls, secrets management, and secure integration design.
Experience with logging, alerting, monitoring, observability, and security detection capabilities.
Strong written and verbal communication skills with the ability to explain complex technical concepts to diverse audiences.
Preferred Qualifications
Minimum of 3 years leading complex security engineering initiatives, assessments, and technical reviews.
Demonstrated experience influencing technical outcomes across multiple teams without direct management responsibility.
Extensive experience with secure software development lifecycle practices.
Experience performing threat modeling, security testing, security reviews, vulnerability management, and security assessments.
Experience implementing and managing security controls for enterprise applications, cloud-native services, APIs, and distributed systems.
Experience partnering directly with software engineering and platform teams as a security advisor, consultant, architect, or security engineering lead.
Experience securing enterprise AI, generative AI, agentic AI, or intelligent automation platforms.
Experience with Microsoft Azure security services, Azure AI Services, Azure OpenAI, Azure AI Foundry, Microsoft Copilot, Copilot Studio, and related Microsoft AI technologies.
Experience with AWS cloud services and security architectures, including Amazon Bedrock and emerging AI services.
Experience with adversarial testing, red teaming, penetration testing, abuse-case analysis, or AI security validation activities.
Experience with retrieval-augmented generation (RAG), agent orchestration frameworks, tool-calling architectures, and autonomous workflow systems.
Experience as a cybersecurity consultant, security architect, technology advisor, or customer-facing security engineering professional.
Experience in financial services, banking, or other highly regulated industries.
Familiarity with model governance, model risk management, responsible AI practices, and AI validation frameworks.
Experience supporting enterprise governance, risk, compliance, audit, and regulatory requirements.
Industry certifications such as CISSP, CISM, CCSP, CSSLP, GIAC, Azure Security Engineer Associate, AWS Security Specialty, or similar credentials.
General Description of Available Benefits for Eligible Employees of Truist Financial Corporation: All regular teammates (not temporary or contingent workers) working 20 hours or more per week are eligible for benefits, though eligibility for specific benefits may be determined by the division of Truist offering the position. Truist offers medical, dental, vision, life insurance, disability, accidental death and dismemberment, tax-preferred savings accounts, and a 401k plan to teammates. Teammates also receive no less than 10 days of vacation (prorated based on date of hire and by full-time or part-time status) during their first year of employment, along with 10 sick days (also prorated), and paid holidays. For more details on Truist’s generous benefit plans, please visit our Benefits site. Depending on the position and division, this job may also be eligible for Truist’s defined benefit pension plan, restricted stock units, and/or a deferred compensation plan. As you advance through the hiring process, you will also learn more about the specific benefits available for any non-temporary position for which you apply, based on full-time or part-time status, position, and division of work.
Truist is an Equal Opportunity Employer that does not discriminate on the basis of race, gender, color, religion, citizenship or national origin, age, sexual orientation, gender identity, disability, veteran status, or other classification protected by law. Truist is a Drug Free Workplace.