Staff AI Security Engineer
New York City, NY - USA
Job Summary
THE POSITION
Our roster has an opening with your name on it
As a Staff AI Security Engineeryoulldrive how FanDuel builds and uses AI securely from the engineers shipping production agents and models to the business use cases they security into the path of least resistance and catch risk before it reaches production across FanDuels AI gateway agent orchestration layer and the growing MCP tool ecosystem.
This role sits within Security and works in close day-to-day partnership with the teams building and operating FanDuels AI shape platform security standardsred teamthe agents and reference workflows running onit andmake sure security controls are built into the platform itself as it matures rather than left to individual application teams.
Success in this role means AI/LLM and agentic security is treated as a property of the platform enforced at the gateway and orchestration layer not something each team reinvents.
In addition to the specific responsibilities outlined above employees may be required to perform other such duties as assigned by the Company. This ensures operational flexibility and allows the Company to meet evolving business needs.
THE GAME PLAN
- Define the AI security roadmap:Own the multi-year AI and agentic security roadmap for FanDuelthe vision strategy and standardsdeveloped jointly with the teams building the AI platform so platform and security standards are one bar not two.
- Secure the inference and agent stack:Drive AI/LLM and agentic security architecture across the platform asitsbuilt out: the AI gateway and MCP tool registry the agent orchestration layer theskillsand capability catalogue and the evals and observability pipeline. Define controls guardrails and monitoring for prompt injection jailbreaking insecure output handling training andretrievaldata poisoning model and datasupply-chainrisk and excessive agent agency.
- Own the MCP and tool-use attack surface:Define security requirements for MCP server registration tool authentication and authorization and agent-to-tool trust boundariesfrom tool poisoning and confused-deputy patterns to unauthenticated or over-privileged tool access.
- Stand up AI red-teaming:Build and run AI red-teaming and adversarialtestingso failure modes are found before they reach production and partner with the platform teams to feed those results into the platforms review process.
- Own the AI security governance model:defining assessment frameworks using OWASP LLM Top 10 MITRE ATLAS and NIST AI RMF to give engineering teams a clear path to shipping AI features safely.
- Automate and scale:Build automation and toolingautomated red-team and adversarial test suites policy-as-code for the gatewaythat turns AI security into a scalable repeatable secure-by-default system rather than manual review.
- Partner and mentor:Partner across Security the AI platform teams and the business to shape direction and trade-offs. Mentor engineers on bothsides andhelp grow AI security capability across the organization.
THE STATS
What were looking for in our next teammate
- Deep hands-on security engineering experience embedded in the software development lifecycle from design and code review through CI/CD deployment and production.
- Hands-on AI/LLM and agentic security experience: you understand how these systems fail in practice (prompt injection jailbreaking insecure output handling data and model poisoning excessive agency tool-use exploits) and have strong defensible opinions on how to secure them.
- Working knowledge of the AI-specific security frameworks (OWASP LLM Top 10 MITRE ATLAS NIST AI RMF) and a pragmatic view on how established frameworks (NIST ISO 27001 OWASP MITRE ATT&CK SOC 2) extend to AI systems.
- Experience securing AI or agent infrastructure such as API gateways agent orchestration platforms or MCP/tool-registry architectures is strongly preferred.
- Familiarity with LLM red-teaming and adversarial testing tooling (e.g. GarakPyRIT Rebuff Lakera Guard or equivalent) and LLM eval/observability platforms or a real eagerness to build depth here.
- A demonstrated track record of defining and delivering multi-year security strategy in ambiguous fast-moving environments.
- Strong experience building and scaling reusable security patterns and assets across an engineering organization.
- A track recordof building automation and tooling that scales security capabilities and reduces manual toil.
- Familiarity with modern cloud infrastructure (AWS GCP or Azure) CI/CD pipelines and software development environments at scale.
- Solid coding skills in at least one modern programming language (Python Go or similar).
- Experience mentoring senior engineers and shaping technical culture across an organization.
- Comfortable partnering closely with a platform engineering org (not just application teams) to embed controls at the infrastructure level.
This is a new and fast-moving field. If you bring strong security engineering fundamentals and a realtrack recordextending into AIwedlike to hear from you even if youdontcheck every box above.
ABOUT FANDUEL
FanDuel Group is the premier mobile gaming company in the United States and Canada. FanDuel Group consists of a portfolio of leading brands across mobile wagering including: Americas #1 Sportsbook FanDuel Sportsbook; its leading iGaming platform FanDuel Casino; the industrys unquestioned leader in horse racing and advance-deposit wagering FanDuel Racing; and its daily fantasy sports product.
In addition FanDuel Group operates FanDuel TV its broadly distributed linear cable television network and FanDuel TV its leading direct-to-consumer OTT platform. FanDuel Group has a presence across all 50 states Canada and Puerto Rico.
The company is based in New York with US offices in Los Angeles Atlanta and Jersey City as well as global offices in Canada and Scotland. The companys affiliates have offices worldwide including in Ireland Portugal Romania and Australia.
FanDuel Group is a subsidiary of Flutter Entertainment the worlds largest sports betting and gaming operator with a portfolio of globally recognized brands and traded on the New York Stock Exchange (NYSE: FLUT).
PLAYER BENEFITS
We treat our team right
We offer amazing benefits above and beyond the basics. We have an array of health plans to choose from (some as low as $0 per paycheck) that include programs for fertility and family planning mental health support and fitness benefits. We offer generous paid time off (PTO & sick leave) annual bonus and long-term incentive opportunities (based on performance) 401k with up to a 5% match commuter benefits pet insurance and more - check out all our benefits here:FanDuel Total Rewards. *Benefits differ across location role and level.
FanDuel is an equal opportunities employer and we believe as one of our principles states We are One Team!. As such we are committed to equal employment opportunity regardless of race color ethnicity ancestry religion creed sex national origin sexual orientation age citizenship status marital status disability gender identity gender expression veteran status or any other characteristic protected by state local or federal law. We believe FanDuel is strongest and best able to compete if all employees feel valued respected and included.
The applicable salary range for this position is $184000 - $241500 USD which is dependent on a variety of factors including relevant experience location business needs and market demand. This role may offer the following benefits: medical vision and dental insurance; life insurance; disability insurance; a 401(k) matching program; among other employee benefits. This role may also be eligible for short-term or long-term incentive compensation including but not limited to cash bonuses and stock program participation. This role includes paid personal time off and 14 paid company holidays. FanDuel offers paid sick time in accordance with all applicable state and federal laws.
FanDuel is committed to providing reasonable accommodations for qualified individuals with disabilities. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process including support for the interview or onboarding process please email.
It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.
#LI-Hybrid
Required Experience:
Staff IC