Hiring.Camp

AI Security Engineer

Truist

·

Today

Location
Charlotte NC - 214 North Tryon Street, United States of America
Type
Full-time
Department
Engineering
Experience
5+ years
Closing date
Today
Source
Workday

Description

The position is described below. If you want to apply, click the Apply Now button at the top or bottom of this page. After you click Apply Now and complete your application, you'll be invited to create a profile, which will let you see your application status and any communications. If you already have a profile with us, you can log in to check status.

Need Help?

If you have a disability and need assistance with the application, you can request a reasonable accommodation. Send an email to Accessibility (accommodation requests only; other inquiries won't receive a response).

Regular or Temporary:

Regular

Language Fluency:  English (Required)

Work Shift:

1st shift (United States of America)

Please review the following job description:

The AI Security Engineer is responsible for implementing, validating, and supporting security controls for artificial intelligence, generative AI, and agentic solutions across the enterprise.

This role works closely with AI engineering, application development, platform, cybersecurity, governance, and architecture teams to help ensure AI-enabled solutions are secure, resilient, compliant, and operationally ready.

As a key contributor within the Forge AI Security organization, the AI Security Engineer assists in the design, implementation, testing, monitoring, and validation of security capabilities for AI-enabled applications, intelligent agents, retrieval-augmented generation (RAG) solutions, and enterprise AI platforms.

The role supports security reviews, threat modeling activities, adversarial testing exercises, control validation efforts, and deployment readiness assessments throughout the AI delivery lifecycle.

This position requires hands-on security engineering experience and a strong understanding of modern application security principles, cloud security, and AI security concepts.

The role regularly partners with developers and solution teams to implement security controls, troubleshoot security issues, validate configurations, and improve the overall security posture of AI-enabled systems.

The successful candidate will be comfortable working across no-code, low-code, and pro-code AI development environments and supporting AI solutions deployed within Microsoft Azure and AWS cloud platforms, including services such as Azure AI, Azure OpenAI, and Amazon Bedrock.

ESSENTIAL DUTIES AND RESPONSIBILITIES

The following is a summary of the essential functions for this role. Other duties may be performed, both major and minor, which are not mentioned below. Specific activities may change from time to time.

AI Security Engineering

  • Implement and maintain security controls for AI-enabled applications, agentic workflows, intelligent automation solutions, and AI platforms.

  • Support secure integration of AI services, APIs, orchestration frameworks, and external tool connections.

  • Configure and validate security controls including identity protections, access controls, secrets management, logging, monitoring, and deployment safeguards.

  • Assist engineering teams in implementing secure patterns for AI and generative AI solutions.

  • Support AI solution development across no-code, low-code, and pro-code environments.

Security Reviews and Testing

  • Participate in security architecture reviews, threat modeling activities, and AI security assessments.

  • Assist in identifying security risks, design weaknesses, and control gaps within AI-enabled solutions.

  • Perform validation testing to verify effectiveness of implemented controls and security requirements.

  • Support adversarial testing, misuse-case analysis, vulnerability assessments, and deployment readiness reviews.

  • Document findings, recommendations, remediation activities, and validation results.

Detection, Monitoring, and Observability

  • Build and maintain monitoring and alerting capabilities for AI-enabled applications and workflows.

  • Develop and enhance detection logic designed to identify suspicious prompts, unusual workflow behavior, unauthorized access attempts, and policy violations.

  • Support collection and analysis of telemetry used to monitor AI system health, security, and compliance.

  • Assist cybersecurity operations teams with investigation and remediation of AI-related security events.

Project Support and Collaboration

  • Partner with software engineering, platform, product, architecture, and cybersecurity teams to implement security requirements throughout the development lifecycle.

  • Support project teams by providing technical guidance on secure implementation practices and control requirements.

  • Participate in design reviews, working sessions, and implementation discussions to ensure security considerations are included early in the delivery process.

  • Assist in remediation planning and implementation activities for identified security findings.

Continuous Improvement

  • Stay current on emerging AI security risks, threats, technologies, and industry trends.

  • Contribute to the improvement of AI security controls, monitoring capabilities, testing practices, and implementation standards.

  • Assist in the development of security documentation, implementation guides, runbooks, and operational procedures.

  • Support automation efforts that improve security efficiency, consistency, and control effectiveness.


Required Qualifications
The requirements listed below are representative of the knowledge, skill and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.

  • Bachelor’s degree or equivalent education, training, and work-related experience.

  • Minimum of 5 years of experience in security engineering or related cybersecurity roles.

  • Advanced knowledge in cybersecurity principles, theories, and concepts.

  • Proven experience in software development lifecycle security practices.

  • Advanced knowledge of threat modeling, security testing, and penetration testing.

  • Experience implementing and managing complex information security technologies.

Technical Knowledge

  • Understanding of AI and LLM security concepts including prompt injection, jailbreak techniques, sensitive data exposure, tool-use risks, model misuse, and output handling concerns.

  • Familiarity with AI-enabled applications, intelligent agents, automation platforms, or generative AI solutions.

  • Knowledge of cloud-native security principles, access control, identity management, secrets handling, and secure integration design.

  • Understanding of monitoring, logging, alerting, and observability concepts.

  • Familiarity with no-code, low-code, and pro-code development environments and associated security considerations.

  • Strong analytical, troubleshooting, and problem-solving skills.

  • Effective written and verbal communication skills

Preferred Qualifications

  • Minimum of 5 years of experience in cybersecurity engineering, application security, cloud security, software engineering, DevSecOps, or related technical disciplines.

  • Experience implementing security controls for enterprise applications, APIs, cloud-native solutions, or distributed systems.

  • Experience participating in security reviews, security testing, vulnerability management, or threat modeling activities.

  • Experience supporting software development lifecycle security practices.

  • Experience collaborating with software engineering and technology teams to address security requirements and remediation activities.

  • Experience implementing or supporting security controls for generative AI, AI-enabled applications, agentic systems, or intelligent automation platforms.

  • Experience with Microsoft Azure security services, Azure AI Services, Azure OpenAI, Azure AI Foundry, Copilot Studio, or related technologies.

  • Experience with AWS cloud services, including Amazon Bedrock and related AI capabilities.

  • Experience performing application security testing, penetration testing, vulnerability assessments, or security validation activities.

  • Experience working in financial services, banking, healthcare, government, or other regulated industries.

  • Experience supporting governance, compliance, or audit-driven technology environments.

  • Familiarity with retrieval-augmented generation (RAG), vector databases, agent orchestration frameworks, and AI workflow platforms.

  • Industry certifications such as Security+, Azure Security Engineer Associate, AWS Security Specialty, CISSP Associate, GIAC certifications, or similar credentials.

General Description of Available Benefits for Eligible Employees of Truist Financial Corporation: All regular teammates (not temporary or contingent workers) working 20 hours or more per week are eligible for benefits, though eligibility for specific benefits may be determined by the division of Truist offering the position. Truist offers medical, dental, vision, life insurance, disability, accidental death and dismemberment, tax-preferred savings accounts, and a 401k plan to teammates. Teammates also receive no less than 10 days of vacation (prorated based on date of hire and by full-time or part-time status) during their first year of employment, along with 10 sick days (also prorated), and paid holidays. For more details on Truist’s generous benefit plans, please visit our Benefits site. Depending on the position and division, this job may also be eligible for Truist’s defined benefit pension plan, restricted stock units, and/or a deferred compensation plan. As you advance through the hiring process, you will also learn more about the specific benefits available for any non-temporary position for which you apply, based on full-time or part-time status, position, and division of work.

Truist is an Equal Opportunity Employer that does not discriminate on the basis of race, gender, color, religion, citizenship or national origin, age, sexual orientation, gender identity, disability, veteran status, or other classification protected by law. Truist is a Drug Free Workplace.

EEO is the Law    E-Verify IER Right to Work

Skills

AWSAzureCybersecurityPenetration TestingComplianceCISSP
AI Security Engineer at Truist | Hiring.Camp