Senior Security Engineer

CeteraDallas, TX
$108,000 - $143,000

About The Position

At Cetera, our Information Security organization protects employees, advisors, and clients from evolving cyber threats across cloud, SaaS, and emerging AI-enabled technologies. As artificial intelligence capabilities expand across the enterprise, Cetera is building a formal AI risk and compliance program — grounded in industry-recognized AI risk management frameworks — to ensure innovation aligns with regulatory, security, and third-party risk expectations. We are seeking an AI Risk and Compliance Engineer to operationalize AI governance controls, manage AI-related third-party and vendor risk, and lead adversarial threat modeling for AI/ML systems using the MITRE ATLAS framework. This role serves as a key bridge across IT Risk, Cloud Security, Legal/Procurement, and AI/ML Engineering teams, translating AI risk management framework requirements into practical, auditable processes within a regulated financial services environment.

Requirements

  • 8-10+ years of experience in IT/cyber risk, GRC, security engineering, or a related discipline, with direct exposure to AI/ML systems
  • Working knowledge of AI risk and control frameworks (e.g., NIST AI RMF or similar industry AI risk management frameworks) and OWASP Top 10 for LLMs
  • Practical experience with, or strong working knowledge of, threat modeling methodologies for AI/ML systems, including familiarity with MITRE ATT&CK and MITRE ATLAS
  • Experience building or operating third-party/vendor risk management processes — due diligence, contracting/SLAs, ongoing monitoring, and issue remediation
  • Understanding of AI-specific attack techniques (prompt injection, data/model poisoning, model evasion, model extraction/inversion) and associated mitigations
  • Ability to translate technical risk findings into control objectives, policy language, and audit-ready documentation
  • Experience in regulated environments (financial services or FINRA preferred)
  • Strong communication skills across technical, risk, legal, and compliance stakeholders

Nice To Haves

  • Experience with GRC platforms (e.g., Archer, ServiceNow GRC) for control and risk-register management
  • Certifications such as CRISC, CISSP, CCSP, or IAPP AIGP (AI Governance Professional)
  • Experience with AWS Bedrock or other cloud AI/ML platforms and cloud-native AI security
  • Familiarity with model cards, data lineage/provenance tooling, and AI bill-of-materials (AI-BOM) concepts
  • Prior participation in red team, purple team, or adversarial testing exercises involving ML systems
  • Exposure to AI governance committees or model risk management (MRM) functions

Responsibilities

  • Implement and maintain controls aligned to recognized AI risk management frameworks (spanning governance, mapping, measurement, and management of AI risk), including control documentation, risk-control matrices (RCM), and evidence collection to support audits and regulatory exams.
  • Evaluate and onboard third-party AI/ML tools and vendors against security, privacy, and compliance criteria; document AI-specific vendor and contract requirements, SLAs, and fourth-party disclosures; support due diligence for AI vendors and data provenance reviews.
  • Build and maintain documentation of third-party AI components (models, datasets, APIs, pre-trained/foundation models) covering provenance, functionality, and known limitations, and map internal controls to those components.
  • Conduct recurring vendor risk and compliance assessments covering AI system performance, data quality, algorithmic bias, and security controls; monitor pre-trained/foundation model drift and SLA adherence; assess concentration and dependency risk across AI vendors.
  • Design and execute threat models for AI/ML systems using the MITRE ATLAS framework to identify adversarial tactics and techniques — including prompt injection, data/model poisoning, model evasion, model extraction, and supply-chain risk in ML pipelines — across the AI development and deployment lifecycle.
  • Plan and coordinate red-teaming, adversarial testing, and penetration testing of AI/ML systems, and drive ongoing threat assessments informed by current threat intelligence and prior incidents.
  • Ensure AI-specific vulnerabilities and security findings are captured, prioritized, and remediated through existing enterprise vulnerability management processes.
  • Support discovery and risk assessment of unsanctioned (shadow) AI tool usage across the enterprise and recommend remediation or approval pathways.
  • Work closely with IT Risk, Cloud Security, Legal, Procurement, and Application/AI Engineering teams to embed AI risk and compliance requirements into intake, procurement, and development processes.
  • Develop and maintain AI risk standards, control narratives, and runbooks; support internal and external audits and regulatory compliance activities (e.g., FINRA) by producing control evidence tied to the organization's AI risk management framework.

Benefits

  • Inclusive health, dental, vision, and life insurance plans built to support diverse lifestyles, offer preventative care, and protect against hardship.
  • Easy access to mental health benefits to meet our team members and their families where they are.
  • 20+ days of paid time off (PTO), paid holidays, and 2 paid wellness days to give our employees the time they need to stay close with their loved ones, recharge, and give back to their communities.
  • 401(k) savings plan with a generous company contribution (up to 5%), and access to a financial professional to offer our employees the opportunity to plan-ahead for a strong financial future well beyond their working years.
  • Paid parental leave to support all team members with birth, adoption, and fostering.
  • Health Savings and Flexible Spending Account options to help you save money on healthcare, daycare, commuting, and more.
  • Employee Assistance Program (EAP), LifeLock, Pet Insurance and more.
  • Paid caregiver leave to provide time away from work when caring for an ill or recovering family member.
  • Additional benefits such as an Employee Assistance Program (EAP), identity theft protection (LifeLock), pet insurance, and other voluntary benefits to provide extra peace of mind
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service