
Enterprise AI Security Engineer
Posted 2 days ago

Posted 2 days ago
This is a fully remote position, open to applicants in United States.
• Develop, optimize, and manage detection and policy content for enterprise AI guardrails across AI assistants, coding agents, and custom-built agents
• Assess findings, differentiate between true and false positives, and gather evidence to transition controls from monitoring to blocking
• Sustain runbooks, configuration as code, and test suites for guardrail rules and policies
• Engage in tuning reviews, change management processes, and support rotations
• Evaluate AI applications, agents, integrations, MCP servers, tool connectors, and third-party AI products
• Conduct tests for prompt injection, sensitive data exposure, excessive permissions, and unsafe agent actions
• Contribute to AI threat models and security acceptance criteria utilizing OWASP Top 10 for LLM Applications and MITRE ATLAS
• Monitor remediation efforts and confirm fixes
• Create telemetry pipelines, analytics, and dashboards to track AI usage and agent activities
• Design AI-specific detections and alerts and integrate them with SIEM and SOAR platforms
• Assist in security operations and insider-threat investigations related to AI tools
• Evaluate and report on the effectiveness of controls
• Integrate AI security tools with AWS, Azure, endpoint security, identity management, data protection, and ticketing systems
• Automate deployment, testing, and rollback processes using CI/CD and infrastructure-as-code principles
• Assess and pilot vendor and platform capabilities
• Implement least privilege, secrets management, and logging practices in security tools
• Collaborate with AI application and agent teams to enforce security requirements and approved patterns
• Contribute to the creation of documentation, standards, and reusable patterns
• Stay updated on LLM and agent threats, vendor guardrails, and industry standards
• At the Principal Engineer level, guide workstreams, mentor engineers, and represent the team in cross-functional discussions
• Bachelor's degree in Computer Science, Cybersecurity, Information Systems, or a related IT field
• A minimum of 2 years of experience in security engineering, software engineering, cloud engineering, or security operations
• Must be authorized to work in the United States on a full-time basis
• Lilly will not provide support for or sponsor work authorization or visas for this position
• Proficient in Python and Bash or PowerShell scripting
• Experience with REST APIs and structured data formats such as JSON and SQL
• Familiarity with AWS or Azure environments
• Knowledge of identity and access management, application security, data protection, or security monitoring
• Practical experience with LLM-based applications, coding assistants, or agents
• Understanding of prompt injection, data leakage, and excessive permissions
• Background in detection engineering, DLP, or rule tuning within SIEM, EDR, or proxy/gateway platforms
• Experience with LLM APIs, agent frameworks, MCP, and AI evaluation or red-team tools
• Familiar with OWASP Top 10 for LLM Applications and MITRE ATLAS
• Knowledge of infrastructure-as-code, containers, and CI/CD pipelines, such as Terraform, CloudFormation, Docker, or GitHub Actions
• Proficient in querying and analyzing large datasets using SQL, Athena, or similar tools
• Experience in building dashboards
• Relevant certifications such as Security+, AWS or Azure security, or GIAC, or involvement in CTF or AI red-team exercises
• Ability to analyze data, articulate clear findings, and communicate technical issues to both technical and non-technical audiences
• Attention to detail, good judgment, and comfort in a regulated environment with change control and audit requirements
• Company bonus based on both company and individual performance
• Company-sponsored 401(k) plan
• Pension plan
• Vacation benefits
• Comprehensive medical, dental, vision, and prescription drug benefits
• Flexible benefits, including healthcare and/or dependent daycare flexible spending accounts
• Life insurance and death benefits
• Paid time off and leave of absence benefits
• Well-being benefits, including an employee assistance program, fitness benefits, and employee clubs and activities
Cummins Inc.
Tangible
GitLab
Tevora
Get handpicked remote jobs straight to your inbox weekly.