Lead AI Security Engineer
Charlotte, NC - USA
Job Summary
The position is described below. If you want to apply click the Apply Now button at the top or bottom of this page. After you click Apply Now and complete your application youll be invited to create a profile which will let you see your application status and any communications. If you already have a profile with us you can log in to check status.
If you have a disability and need assistance with the application you can request a reasonable accommodation. Send an email to Accessibility (accommodation requests only; other inquiries wont receive a response).
Regular or Temporary:
RegularLanguage Fluency: English (Required)
Work Shift:
1st shift (United States of America)This role focuses on securing agent behavior prompt and context flows tool invocation data access model interaction pipeline integrity runtime execution observability and deployment readiness in a regulated enterprise environment.
The engineer leads implementation of AI-specific security patterns including prompt-injection defenses guardrails output filtering secure tool-use boundaries identity and permission controls evidence capture logging monitoring and detection content for AI-enabled systems.
The work spans architecture review threat modeling adversarial test readiness control validation automation detection engineering deployment gating production monitoring and incident response support for AI and agentic solutions.
Daily work includes partnering with product engineering platform data risk and security teams to translate AI security requirements into implementable controls that enable safe traceable resilient and governed deployment of enterprise AI capabilities.
ESSENTIAL DUTIES AND RESPONSIBILITIES
Following is a summary of the essential functions for this job. Other duties may be performed both major and minor which are not mentioned below. Specific activities may change from time to time.
Lead the design and implementation of security controls for AI-enabled applications agents model integrations orchestration layers and AI delivery pipelines.
Perform AI and agentic threat modeling across prompts context windows retrieval flows tools APIs permissions memory model access data movement and runtime execution paths.
Implement and validate guardrails for prompt-injection resistance unsafe output handling tool-use abuse sensitive data exposure privilege escalation model misuse and policy-violating behavior.
Build and maintain monitoring alerting and detection logic for AI systems including anomalous prompts abnormal agent actions suspicious tool invocation unsafe model responses and control degradation.
Embed security requirements into AI design reviews acceptance criteria validation plans CI/CD or LLMOps workflows model or prompt change controls and release-readiness gates.
Validate that AI solutions meet required security governance traceability and evidence standards before release and continue to meet them after deployment.
Support AI-related incident investigation root-cause analysis remediation planning and operational response for suspicious behavior control failures data exposure or unsafe system outcomes.
Maintain control documentation implementation guidance runbooks validation evidence engineering patterns and operating procedures for AI security engineering activities.
Continuously improve AI security automation validation workflows detection content guardrail logic and deployment controls as models agents workflows and attack techniques evolve.
Required Qualifications:
The requirements listed below are representative of the knowledge skill and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
Bachelors degree or equivalent education training and work-related experience.
Minimum of 10 years of experience in security engineering or related cybersecurity roles.
Deep specialized knowledge in cybersecurity principles theories and concepts.
Extensive experience in software development lifecycle security practices.
Expertise in threat modeling security testing and penetration testing.
Proven experience implementing and managing complex information security technologies.
Additional Requirements:
Minimum of 10 years of experience in security engineering application security product security cloud security cybersecurity operations or related technical cybersecurity roles.
Demonstrated experience leading complex security engineering efforts across modern software API cloud-native automation or platform environments.
Strong understanding of AI LLM or agentic security risks including prompt injection insecure tool use data exposure model misuse pipeline compromise and unsafe output handling.
Experience with threat modeling security testing control validation detection engineering logging monitoring or incident response for production systems.
Ability to translate security requirements into implementable engineering controls validation criteria deployment gates documentation and operational runbooks.
3 years of experience in a lead security engineering application security AI security cybersecurity operations or closely related technical discipline.
Hands-on experience implementing controls for enterprise software APIs cloud-native services workflow automation model integrations or agentic applications.
Working knowledge of LLM and agentic security concepts such as prompt injection indirect prompt injection insecure tool use excessive agency sensitive data exposure model misuse and control boundary enforcement.
Experience securing CI/CD DevSecOps MLOps LLMOps model prompt or configuration-change pipelines through validation approvals evidence capture and release controls.
Experience with telemetry logging alerting monitoring or detection content for identifying suspicious anomalous or policy-violating behavior in applications or AI workflows.
Understanding of identity access control secrets handling least privilege secure integration design API protections sandboxing and environment-based deployment controls.
Ability to partner with engineering teams to convert AI security risks into practical guardrails tests detections monitoring requirements and deployment-readiness controls.
Strong written documentation and communication skills especially for control designs validation results remediation evidence technical guidance and audit-ready operating procedures.
Preferred Qualifications:
Experience securing AI agents autonomous workflows tool-calling systems retrieval-augmented generation patterns or LLM-enabled enterprise applications.
Experience with Microsoft Azure Copilot Copilot Studio Azure AI or other enterprise AI and automation platforms.
Familiarity with AI security guidance and frameworks such as OWASP LLM risks OWASP agentic application risks NIST AI RMF MITRE ATLAS or related industry practices.
Experience with adversarial testing AI red teaming support misuse-case validation model or prompt evaluation or safety monitoring for AI-enabled systems.
Experience in financial services cybersecurity regulated enterprise environments or platforms with high audit risk privacy and control expectations.
Working knowledge of secure tool-calling patterns API protections prompt and model change validation runtime traceability and observability for AI systems.
General Description of Available Benefits for Eligible Employees of Truist Financial Corporation: All regular teammates (not temporary or contingent workers) working 20 hours or more per week are eligible for benefits though eligibility for specific benefits may be determined by the division of Truist offering the offers medical dental vision life insurance disability accidental death and dismemberment tax-preferred savings accounts and a 401k plan to teammates. Teammates also receive no less than 10 days of vacation (prorated based on date of hire and by full-time or part-time status) during their first year of employment along with 10 sick days (also prorated) and paid holidays. For more details on Truists generous benefit plans please visit our Benefits site. Depending on the position and division this job may also be eligible for Truists defined benefit pension plan restricted stock units and/or a deferred compensation plan. As you advance through the hiring process you will also learn more about the specific benefits available for any non-temporary position for which you apply based on full-time or part-time status position and division of work.
Truist is an Equal Opportunity Employer that does not discriminate on the basis of race gender color religion citizenship or national origin age sexual orientation gender identity disability veteran status or other classification protected by law. Truist is a Drug Free Workplace.
Required Experience:
IC
About Company
Your journey to better banking starts with Truist. Checking and savings accounts, credit cards, mortgages, small business, commercial banking, and more.