Senior Security Engineer
Oraclecloud · Dallas, TX, United States
About The Role
At Cetera, our Information Security organization protects employees, advisors, and clients from evolving cyber threats across cloud, SaaS, and emerging AI-enabled technologies. As artificial intelligence capabilities expand across the enterprise, Cetera is building a formal AI risk and compliance program — grounded in industry-recognized AI risk management frameworks — to ensure innovation aligns with regulatory, security, and third-party risk expectations.
We are seeking an AI Risk and Compliance Engineer to operationalize AI governance controls, manage AI-related third-party and vendor risk, and lead adversarial threat modeling for AI/ML systems using the MITRE ATLAS framework. This role serves as a key bridge across IT Risk, Cloud Security, Legal/Procurement, and AI/ML Engineering teams, translating AI risk management framework requirements into practical, auditable processes within a regulated financial services environment.
What will you do
- Operationalize AI governance controls: Implement and maintain controls aligned to recognized AI risk management frameworks (spanning governance, mapping, measurement, and management of AI risk), including control documentation, risk-control matrices (RCM), and evidence collection to support audits and regulatory exams.
- Lead AI third-party risk management: Evaluate and onboard third-party AI/ML tools and vendors against security, privacy, and compliance criteria; document AI-specific vendor and contract requirements, SLAs, and fourth-party disclosures; support due diligence for AI vendors and data provenance reviews.
- Maintain AI/vendor risk inventories: Build and maintain documentation of third-party AI components (models, datasets, APIs, pre-trained/foundation models) covering provenance, functionality, and known limitations, and map internal controls to those components.
- Run ongoing AI risk assessments: Conduct recurring vendor risk and compliance assessments covering AI system performance, data quality, algorithmic bias, and security controls; monitor pre-trained/foundation model drift and SLA adherence; assess concentration and dependency risk across AI vendors.
- Perform AI threat modeling: Design and execute threat models for AI/ML systems using the MITRE ATLAS framework to identify adversarial tactics and techniques — including prompt injection, data/model poisoning, model evasion, model extraction, and supply-chain risk in ML pipelines — across the AI development and deployment lifecycle.
- Coordinate adversarial testing: Plan and coordinate red-teaming, adversarial testing, and penetration testing of AI/ML systems, and drive ongoing threat assessments informed by current threat intelligence and prior incidents.
- Integrate AI into vulnerability management: Ensure AI-specific vulnerabilities and security findings are captured, prioritized, and remediated through existing enterprise vulnerability management processes.
- Identify and assess unsanctioned AI usage: Support discovery and risk assessment of unsanctioned (shadow) AI tool usage across the enterprise and recommend remediation or approval pathways.
- Partner cross-functionally: Work closely with IT Risk, Cloud Security, Legal, Procurement, and Application/AI Engineering teams to embed AI risk and compliance requirements into intake, procurement, and development processes.
- Support governance and audit activities: Develop and maintain AI risk standards, control narratives, and runbooks; support internal and external audits and regulatory compliance activities (e.g., FINRA) by producing control evidence tied to the organization's AI risk management framework.
What you will have
- 8-10+ years of experience in IT/cyber risk, GRC, security engineering, or a related discipline, with direct exposure to AI/ML systems
- Working knowledge of AI risk and control frameworks (e.g., NIST AI RMF or similar industry AI risk management frameworks) and OWASP Top 10 for LLMs
- Practical experience with, or strong working knowledge of, threat modeling methodologies for AI/ML systems, including familiarity with MITRE ATT&CK and MITRE ATLAS
- Experience building or operating third-party/vendor risk management processes — due diligence, contracting/SLAs, ongoing monitoring, and issue remediation
- Understanding of AI-specific attack techniques (prompt injection, data/model poisoning, model evasion, model extraction/inversion) and associated mitigations
- Ability to translate technical risk findings into control objectives, policy language, and audit-ready documentation
- Experience in regulated environments (financial services or FINRA preferred)
- Strong communication skills across technical, risk, legal, and compliance stakeholders
Preferred Qualifications
- Experience with GRC platforms (e.g., Archer, ServiceNow GRC) for control and risk-register management
- Certifications such as CRISC, CISSP, CCSP, or IAPP AIGP (AI Governance Professional)
- Experience with AWS Bedrock or other cloud AI/ML platforms and cloud-native AI security
- Familiarity with model cards, data lineage/provenance tooling, and AI bill-of-materials (AI-BOM) concepts
- Prior participation in red team, purple team, or adversarial testing exercises involving ML systems
- Exposure to AI governance committees or model risk management (MRM) functions
This is an external listing. JobSpring does not represent or verify the employer. Report this listing
JobSpring