AI Security Engineer (Remote in the U.S.)

GuidePoint Security · Remote · Engineering

Posted 2026-10-05

Apply for this role →

General Description

The GuidePoint Security North Central region is seeking a skilled AI Security Engineer to join our growing AI Security Services team within the Automation and AI Practice. You will assist customers in the design, implementation, security, and operational management of generative AI security solutions — including AI governance assessments, LLM and agent security testing, shadow AI discovery, agentic workflow development, and architecture reviews.

About the North Central AI Security Practice

You will work closely with peers across multiple domains including AppSec, Cloud Security, and Identity and Access Management to deliver holistic and secure solutions adhering to industry best practices. This role offers the opportunity to contribute directly to the continued growth of our AI security practice and its expanding service portfolio.

Roles and Responsibilities:

AI Security Architecture & Assessment: Conduct secure configuration reviews and security assessments of enterprise AI platforms (e.g., Anthropic Claude Enterprise, OpenAI ChatGPT Enterprise, Microsoft Copilot) against established control domains — including identity and provisioning, network and access enforcement, data protection and retention, and audit and compliance — identifying vulnerabilities, attack surfaces, and gaps against industry frameworks (e.g., OWASP LLM Top 10, MITRE ATLAS)

Threat Modeling for AI Systems: Lead threat modeling exercises specific to AI workloads, covering prompt injection, model inversion, data poisoning, supply chain risks, excessive agency, privilege escalation through tool chaining, and unauthorized cross-application data movement across SaaS, self-hosted, and local AI deployments

AI Coding Tool & Development Environment Security: Assess AI coding tools and development environments — including Claude Code, OpenAI Codex, Open Code, Cursor, and MCP servers — for sandbox isolation, plugin allowlisting, secrets access, network egress controls, and CI/CD pipeline security

Secure AI Integration Guidance: Advise client teams on securely integrating SaaS AI services and APIs (e.g., OpenAI, Azure OpenAI, AWS Bedrock) into enterprise applications, including safe handling of credentials, outputs, and user data

Data Security & Privacy Controls: Evaluate and recommend controls for data ingestion pipelines, RAG architectures, and vector databases to prevent unauthorized data exposure, leakage through model outputs, or non-compliant data processing — including zero data retention enforcement, sensitivity labeling, data classification, and encryption key management

Shadow AI Discovery: Conduct shadow AI discovery engagements to inventory unsanctioned AI tool usage and assess associated data exposure risks across client environments

Security Controls & Guardrails Evaluation: Evaluate security controls and guardrails across AI platforms, including identity and access management, DLP integration, conditional access policies, SIEM and logging configurations, human-in-the-loop mechanisms, and AI-specific runtime protections

Agentic Workflow Development: Design, build, and deploy AI agent workflows including use-case design, agent architecture, and integration with security tooling and automation platforms

Security Architecture Reviews: Perform security architecture reviews for organizations deploying AI agents that connect to tools, data sources, or other agents via MCP or agentic frameworks, delivering reference architectures and recommendations

Security Documentation & Deliverables: Develop and deliver engagement artifacts including secure configuration review reports, prioritized findings registers, AI security control matrices, reference architectures, risk assessments, control frameworks, and secure enablement roadmaps

Strategic AI Security Roadmap: Contribute to the development of long-term AI security strategies for clients, including prioritized remediation roadmaps, capability maturity assessments, and investment recommendations

Collaboration & Stakeholder Engagement: Serve as a trusted security advisor bridging business stakeholders, AI/ML engineers, IT operations, and information security teams — conducting stakeholder interviews and facilitating knowledge transfer sessions covering AI platform administration, troubleshooting, and operational runbooks

AI Threat Landscape Monitoring: Continuously track emerging AI security research, adversarial techniques, regulatory developments, and vendor security advisories (e.g., Anthropic, OpenAI, Microsoft feature releases) to keep client guidance relevant and proactive

Required Experience and Education:

3+ years of experience in security engineering with a significant focus on cloud security and/or application security

Hands-on experience implementing, managing, securing, and supporting agentic AI solutions within an enterprise context, including enterprise AI platforms such as Anthropic Claude (Enterprise, Desktop, Cowork, Code), OpenAI (ChatGPT Enterprise, Codex, API), or Microsoft Copilot

Familiarity with major cloud service provider AI-focused services such as AWS Bedrock, AWS SageMaker, Azure AI Foundry, or Google Vertex

Solid understanding of generative AI concepts, Large Language Models (LLMs), context engineering, agentic tool usage, and foundational AI/ML principles

Operational experience in the usage of agentic coding assistants such as Claude Code, Open Code, Cursor, or Codex

Understanding of AI-specific security challenges including prompt injection, data poisoning, supply chain security, model extraction attacks, excessive agency, and privilege escalation through tool chaining

Ability to produce professional client-facing deliverables including assessment reports, findings registers, control matrices, and reference architecture documentation

Strong written and verbal communication skills with the ability to explain complex technical concepts to both technical and non-technical audiences

Embraces emerging technologies, including AI tools, to work smarter, solve problems, and drive better business outcomes

Preferred Experience and Education

Certifications such as AWS Certified AI Practitioner, AWS Certified Machine Learning Engineer, Azure AI Engineer Associate, or Claude Certified Architect

Understanding or experience with model fine-tuning techniques

Experience with policy as code languages like Cedar or Rego and Infrastructure as Code (IaC) tools like AWS CloudFormation, Terraform, OpenTofu, or equivalent technologies

Experience designing and implementing agentic AI architectures that balance security and autonomy

Familiarity with MCP client/server architecture vs. agentic skills and the associated security risks of each

Experience with AI security tooling categories such as AI Security Posture Management (AISPM), AI runtime protection, or AI control plane platforms

Prior experience in a consulting, professional services, or managed services delivery model with direct client engagement

Travel Requirements:

Up to 10% travel

Physical Requirements:

Sedentary work

Substantial movement of the wrists, hands, and/or fingers for a minimum of 8 hours a day

Required to have close visual acuity to view computer terminal and/or extensive reading for a minimum of 8 hours a day

Apply for this role →

← Back to all jobs