Senior Associate - AI AppSec Engineer

New York LifeNew York, NY
$124,000 - $177,000Hybrid

About The Position

New York Life is transitioning from AI experimentation to production, agentic, and automated decisioning systems. As an AI Application Security Engineer, you will be instrumental in ensuring these systems are developed and operated securely. This involves embedding application security controls, guardrails, and secure-by-default practices throughout the entire AI development lifecycle. Within the Application Security team, you will work hands-on to secure AI applications, agentic systems, and supporting AI platform services across both development and production environments. Utilizing Google Cloud Vertex AI as the enterprise AI platform, you will collaborate closely with AI engineers, data scientists, MLOps platform teams, and Model Risk Management. Your focus will be on integrating AI security into application development, CI/CD pipelines, infrastructure-as-code workflows, and cloud platforms. This individual contributor role demands strong technical expertise, collaborative problem-solving skills, and a dedication to building scalable security capabilities that foster innovation while effectively mitigating risk.

Requirements

  • Bachelor's degree in Computer Science, Engineering, or a related discipline (or equivalent practical experience) with 5+ years of experience in application security, cloud security, security engineering, or a closely related field.
  • Hands-on experience securing production AI platforms, with experience in Google Cloud Vertex AI preferred; comparable experience with Amazon SageMaker or Azure Machine Learning will also be considered.
  • Strong understanding of AI application and model lifecycles, including data ingestion, training, model registry, deployment, online and offline serving, and secure environment separation across development, training, staging, and production.
  • Experience implementing security controls within CI/CD pipelines and infrastructure-as-code environments, along with knowledge of cloud IAM, least-privilege principles, service accounts, workload identity, and non-human identity management.
  • Knowledge of modern application security practices including authentication and authorization, secure API design, software supply chain security (SLSA, SBOMs, signed artifacts), secrets management, and AI-specific threat models.
  • Proficiency in Python for automation, security tooling, and detection engineering, with the ability to independently implement, troubleshoot, and evolve security solutions in partnership with cross-functional teams.

Nice To Haves

  • Experience securing agentic AI systems or orchestration frameworks such as LangChain, LangGraph, Vertex AI Agent Builder, ADK, CrewAI, or similar production AI workflows.
  • Familiarity with AI security frameworks including MITRE ATLAS, OWASP Top 10 for LLM Applications, NIST AI RMF, Google Secure AI Framework (SAIF), or comparable industry guidance.
  • Experience supporting AI governance or security controls within a regulated industry, including collaboration with model risk management, model validation, or second-line risk organizations.
  • Experience with policy-as-code technologies, AI detection engineering, or AI security and guardrail solutions such as OPA/Rego, Cloud Custodian, Sentinel, Lakera, Protect AI, NeMo Guardrails, Llama Guard, or Vertex AI Safety Filters.

Responsibilities

  • Design and implement application security controls for AI applications, agentic systems, and tool-invoking workflows, ensuring secure-by-default patterns are embedded throughout the software development lifecycle.
  • Build and operationalize security guardrails that protect against emerging AI threats, including prompt injection, indirect prompt injection, unsafe tool invocation, data exfiltration, model abuse, and other evolving attack techniques.
  • Integrate AI security controls into existing application security, CI/CD, SSDLC, and infrastructure-as-code processes while helping secure AI platform workflows across data ingestion, model training, deployment, serving, and runtime execution with a primary focus on Google Cloud Vertex AI.
  • Partner with MLOps platform teams, AI engineers, data scientists, cloud engineering, and Model Risk Management to review identity architectures, automate security controls, remediate findings, and establish reusable security standards across enterprise AI initiatives.
  • Develop Python-based automation, security tooling, detection capabilities, and technical guidance that improve the organization's ability to securely deploy, monitor, and scale AI solutions in production.

Benefits

  • leave programs
  • adoption assistance
  • student loan repayment programs
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service