Member of Technical Staff - AI Security Engineering [Bay Area]

NTT DATA AIVistaPalo Alto, CA
Onsite

About The Position

NTT DATA AIVista, Inc., a wholly owned subsidiary of NTT DATA, is based in Silicon Valley. We develop AI products that operationalize AI across enterprises operating in complex regulatory environments. We partner with other NTT companies (NTT DATA Inc., NTT DATA Japan, NTT Docomo) to ensure successful deployment to NTT clients. Our clients benefit from AIVista’s deep product AI expertise combined with the industry domain and systems integration experience of NTT DATA. The Principal Security Engineer will own the entire security function at NTT DATA AIVista, from the security of our AI products to our cloud environments, our corporate security posture, and our compliance programs. You will set the standard for what “secure” means across the company and be accountable for the security of products deployed into some of the world’s most regulated enterprises. This is a hands-on, senior individual-contributor role to start: you will personally do the architecture, threat modeling, and security engineering. As the company and the security surface grow, you will build and lead a small security team, hiring and mentoring engineers and directing external specialists. We are looking for someone who wants to own security end-to-end now and grow into a security leader. Because our products are agentic AI systems, this role carries a threat model that does not map cleanly onto traditional application security; multi-agent orchestration, sandboxed code execution, agents holding delegated credentials, and untrusted tool output crossing trust boundaries. You will define how we secure these systems.

Requirements

  • 10+ years in security engineering, with deep expertise in application/product security and cloud security.
  • Hands-on experience leading threat modeling and secure design reviews for complex, distributed systems.
  • Strong cloud security expertise (AWS, Azure, or Google Cloud Platform): IAM, network security, secure baselines, logging/monitoring, and vulnerability management.
  • Experience securing AI/ML or agentic systems, or clear ability to reason about novel threat models (sandboxing, delegated credentials, untrusted tool/output boundaries, prompt/agent abuse).
  • Working ownership of security compliance programs (SOC 2, ISO 27001) and the ability to direct auditors and compliance tooling (e.g., Vanta).
  • Experience owning incident response and security risk management.
  • Excellent communication skills, with the ability to influence engineering, executives, customers, and auditors.
  • Comfortable operating as a hands-on solo owner in a fast-paced startup, with the ambition and ability to build and lead a team.

Nice To Haves

  • Experience at a technology, AI, or enterprise-software company serving regulated industries is preferred.

Responsibilities

  • Lead secure design reviews and threat modeling for our AI products, including agentic and multi-agent systems, identifying risks that don’t map to existing frameworks.
  • Define security architecture and secure-by-design standards for AI agents, tool use, sandboxing, and delegated-credential and identity boundaries.
  • Partner with Engineering and the CTO organization to embed security into the product and development lifecycle (secure SDLC, code review, dependency and supply-chain security).
  • Build or introduce security tooling and guardrails that let product security scale with the business.
  • Own cloud security architecture and posture across AWS, Azure, and/or Google Cloud Platform — IAM design, network security, secure baselines, logging, monitoring, and vulnerability management.
  • Define the security standards that IT and DevOps implement and operate against.
  • Lead threat detection, posture management, and remediation prioritization across cloud environments.
  • Own the company security program, roadmap, risk register, and security policies.
  • Direct the SOC 2 and ISO 27001 programs — setting the control framework and audit strategy while IT operates day-to-day compliance tooling and evidence collection.
  • Own vendor security reviews, security architecture standards, and NTT DATA group security requirements.
  • Oversee security awareness and training across the company.
  • Own incident response and disaster recovery planning, and lead response to security incidents.
  • Establish how security risk is measured, quantified, and reported to leadership.
  • Hire, mentor, and lead a small security team over time; direct external consultants and specialists.
  • Represent security to executives, customers, auditors, and NTT DATA group stakeholders.

Benefits

  • Medical, dental, and vision insurance
  • 401(k) plan
  • Significant company HSA contribution
  • Paid holidays and flexible PTO
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service