Principal AI Security Engineer
AI summary of the role
Candescent seeks an AI Security Engineer to own the security of integrating third-party AI and LLM services across the enterprise.
No longer in the current catalog. Last included 2026-09-09. Check the employer’s posting for availability.
What you’ll do
- Define and maintain secure integration patterns for third-party AI and LLM services, including API security, authentication, secrets management, and data-in-transit protections.
- Build and maintain an AI security risk framework aligned to regulatory obligations (GLBA, PCI DSS 4.0.1, DORA, NYDFS 23 NYCRR 500).
- Identify and mitigate AI-specific risks including prompt injection, model manipulation, data leakage, adversarial inputs, and AI-enabled social engineering.
- Partner with engineering, product, and cloud platform teams to embed security-by-design into AI-enabled applications and integrations.
What you’ll bring
- 7+ years of experience in security engineering, application security, cloud security, or a closely related discipline.
- Hands-on experience securing cloud-native environments and API-based integrations (AWS, Azure, or GCP).
- Working knowledge of AI/ML security risks relevant to an enterprise consumer context: prompt injection, data leakage, insecure API integration, shadow AI, model output manipulation, and AI supply chain risk.
- Experience with or meaningful exposure to securing integrations with LLM service providers (e.g., Azure OpenAI, AWS Bedrock, Google Vertex AI, Anthropic, OpenAI).
Technologies
LLM · API security · AWS · Azure · GCP · OWASP LLM Top 10 · MITRE ATLAS · Azure OpenAI · AWS Bedrock · Google Vertex AI · Anthropic · OpenAI
About Candescent
PE-backed digital banking platform for banks and credit unions, unifying account opening, consumer/business banking, and assisted channels on cloud-native, API-first infrastructure.
Acquired · 1000–2000 people
Source and classification
Internal deployment & tooling · Evidence for this classification:
Candescent is a forward-thinking technology company transforming how financial institutions deliver Intelligent Banking experiences. We unite digital banking, account opening, and branch solutions that power and connect digital banking, account opening, and branch solutions—creating seamless engagement across digital, remote, and in-person channels. Our Experience-Led, Intelligence-Driven approach combines human-centered design with data, automation, and cloud-based innovation. Built on an API-first architecture, our extensible ecosystem enables institutions to adapt quickly, integrate easily, and unlock new opportunities for growth—turning every customer interaction into a moment of clarity, confidence, and connection. Role Summary We are seeking an AI Security Engineer to own the security of how we adopt and integrate third-party artificial intelligence and large language model
More from the job description
Candescent is a forward-thinking technology company transforming how financial institutions deliver Intelligent Banking experiences. We unite digital banking, account opening, and branch solutions that power and connect digital banking, account opening, and branch solutions—creating seamless engagement across digital, remote, and in-person channels. Our Experience-Led, Intelligence-Driven approach combines human-centered design with data, automation, and cloud-based innovation. Built on an API-first architecture, our extensible ecosystem enables institutions to adapt quickly, integrate easily, and unlock new opportunities for growth—turning every customer interaction into a moment of clarity, confidence, and connection. Role Summary We are seeking an AI Security Engineer to own the security of how we adopt and integrate third-party artificial intelligence and large language model (LLM) services across the enterprise. This is a practitioner role for someone with a strong security engineering foundation who has developed meaningful expertise in AI/ML security risks — or who is actively building that expertise and ready to own it as their primary charter. As an enterprise consumer of AI services, our risk surface centers on how we connect to and use external AI providers — securing API integrations, controlling data exposure, governing adoption of AI tools across the organizat [... source excerpt omitted ...] SS 4.0.1, DORA ICT third-party risk, and NYDFS 23 NYCRR 500. Establish governance controls for enterprise AI adoption, including standards for approved AI services, data handling requirements, and shadow AI detection. Align internal AI security controls to emerging frameworks — NIST AI RMF and ISO/IEC 42001 — and advise on the organization's readiness as regulatory expectations evolve. Threat Identification & Engineering Controls Identify and mitigate AI-specific risks including prompt injection, model manipulation, data leakage, adversarial inputs, and AI-enabled social engineering. Partner with security operations to build detection and response capabilities for AI-integrated [... source excerpt omitted ...] ommendations clearly to both technical peers and non-technical leadership. Contribute to security awareness and internal education on AI risk for engineering and business teams. Requirements Bachelor’s degree in Computer Science, Information Security, Engineering, or a related technical discipline or equivalent practical experience. 7+ years of experience in security engineering, application security, cloud security, or a closely related discipline. Hands-on experience securing cloud-native environments and API-based integrations (AWS, Azure, or GCP). Solid understanding of authentication, authorization, secrets management, and data protection in distributed systems. Ability t
Employer postings · Data from · Sources