
Principal AI Security Engineer
Posted 2 days ago

Posted 2 days ago
This is a fully remote position, open to applicants in United States.
• Take ownership of CDW's AI security assessment program, encompassing its processes, criteria, and risk tiers for approving, restricting, monitoring, or blocking AI use cases, platforms, vendors, and shadow AI.
• Lead the security assessments of AI systems, agents, and integrations both prior to and following deployment.
• Collaborate with the AI Council, AppSec, and platform teams to integrate assessment findings into AI use case evaluations.
• Assess third-party AI vendors, purchased AI capabilities, and unapproved AI usage against CDW's AI security standards and guidelines.
• Establish methods and tools for AI red teaming, including automated adversarial testing.
• Evaluate AI-related controls within CDW's security framework, identify gaps, and drive root-cause remediation efforts.
• Define and manage enterprise AI security architecture, standards, reference architectures, and secure design patterns.
• Set security requirements throughout the AI lifecycle, from data handling and model selection to deployment, monitoring, and retirement.
• Define trust boundaries, authorization models, and least privilege principles for both single-agent and multi-agent systems.
• Design comprehensive security for LLM inference pipelines, AI agents, MCP-based tool orchestration, and agentic workflows.
• Develop and implement guardrails, sandboxes, runtime controls, and AI gateway capabilities.
• Build or implement governance for AI identities, such as agents, service principals, workload identities, and delegated access.
• Partner with Identity Engineering, Detection Engineering, and Security Operations teams on identity standards, detections, telemetry, and response playbooks.
• Collaborate with engineering, data science, product, and infrastructure teams to embed security from the design phase through to production.
• Present risk assessments, recommendations, and investment priorities to senior leadership and security governance entities.
• Mentor security engineers and architects to enhance AI security expertise across CDW.
• Bachelor's degree with 10+ years in security engineering or security architecture, including practical experience in securing AI/ML systems, or 14+ years of experience in security engineering or security architecture with hands-on work securing AI/ML systems.
• Demonstrated experience in designing and leading security assessments of AI systems, platforms, or vendors, and translating findings into clear, risk-based decisions.
• Hands-on experience securing production AI technologies, which includes deploying AI guardrails or sandboxes, managing AI or agent identities, detecting or mitigating prompt injection, or implementing AI security tools.
• Experience in building or evaluating security for production AI systems, beyond theoretical or research applications.
• Strong understanding of LLMs, including pretraining, fine-tuning, RLHF, inference, retrieval-augmented generation, and safety alignment, along with the potential attack vectors for each layer.
• Experience securing AI platforms and agent frameworks such as Microsoft Copilot Studio, Azure AI services, OpenAI or Anthropic tool usage, MCP-based integrations, Semantic Kernel, or LangChain.
• Experience in securing AI deployments within public cloud environments (Azure, AWS, or GCP), identity and access management, and zero trust principles.
• Proven capability to influence senior leaders and cross-functional teams without direct authority.
• Experience on a security team defending production AI systems at scale, or at a leading AI lab, is a plus.
• Background in Infrastructure, Cloud, Platform, or Corporate Security, Security Operations, or Detection and Response is a plus.
• Experience in software security review, secure SDLC, vulnerability discovery, or offensive security is a plus.
• Published work, conference presentations, CTF results, or production red team experience in prompt injection, jailbreak research, or adversarial ML is a plus.
• Experience with AI security posture management, AI gateways, or AI observability platforms is a plus.
• Relevant certifications such as CISSP, CCSP, OSCP, or AI security credentials are a plus.
• Annual bonus target of 15% subject to terms and conditions of the plan.
• Comprehensive benefits package available at https://cdw.benefit-info.com/.
• Salary ranges may vary based on geographic differentials.
Cummins Inc.
Tangible
GitLab
Tevora
Get handpicked remote jobs straight to your inbox weekly.