Skip to main content
Posted August 28, 2026

Sr. AI Security Engineer

McCarthy Building Companies, Inc.
St. Louis, Missouri, United States 63101 Full Time
Reference: 286761869

McCarthy Building Companies, Inc.

POSITION SUMMARY

The Sr. AI Security Engineer will help secure the design, deployment, and operation of AI-enabled products and services. This role will help protect data, systems, users, and customers as generative AI, machine learning, and agentic technologies continue to evolve.

As a member of the Cybersecurity team, the engineer will work closely with AI, engineering, architecture, legal, and compliance teams. The organization has existing AI tools and controls in place, and this role will assess their effectiveness, recommend additional capabilities where needed, and mature the overall AI security toolset over time. Rather than building an AI-security stack from scratch, the engineer will configure, tune, validate, operate, and extend existing security solutions while helping teams apply practical secure-by-design practices.

The ideal candidate combines hands-on security architecture or engineering experience, production AI-security experience, and the ability to explain complex risks clearly to both technical and non-technical audiences.

RESPONSIBILITIES

  • Develop and maintain enterprise AI security standards, control requirements, and risk-based review processes.
  • Assess AI applications, models, agents, APIs, integrations, vendors, and data flows before and after deployment.
  • Define security requirements for AI systems across design, development, testing, deployment, operation, and retirement.
  • Evaluate identity, access, identity governance, data protection, privacy, logging, monitoring, retention, and human-oversight controls.
  • Test AI systems and agent workflows for prompt injection, indirect injection, jailbreaks, data leakage, excessive agency, unsafe tool use, insecure integrations, and configuration drift.
  • Conduct threat modeling, architecture reviews, security assessments, and control validation for AI-enabled solutions.
  • Establish processes for AI security findings, incident response, exception management, remediation, and executive reporting.
  • Review AI vendors, models, third parties, subprocessors, data handling practices, and material platform or configuration changes.
  • Configure, tune, validate, operate, and extend existing AI-security, AI-governance, application-security, data-security, and monitoring tools.
  • Support the evaluation and integration of additional capabilities where existing controls require enhancement.
  • Create practical security patterns, reference architectures, playbooks, standards, and guidance for engineering and product teams.
  • Monitor emerging AI threats, vulnerabilities, standards, regulations, and industry practices and translate them into actionable improvements.
  • Partner with development and platform teams to integrate security controls into AI development and deployment workflows.
  • Communicate technical risks, business impact, and recommended actions to both technical and non-technical stakeholders.
  • Promote responsible AI adoption through measurable controls, clear accountability, and continuous improvement.

QUALIFICATIONS

  • Bachelors degree in cybersecurity, computer science, information systems, engineering, or a related field, or equivalent professional experience.
  • Minimum five years of proven experience in an established security architecture, security engineering, architecture, or engineering role.
  • Working experience handling AI security in a production environment, including the assessment, governance, monitoring, or protection of AI applications, models, agents, or integrations.
  • Strong understanding of cybersecurity principles, including identity governance, least privilege, data protection, risk assessment, incident response, security architecture, and security governance.
  • Familiarity with OWASP LLM and AI risks, including prompt injection, indirect injection, jailbreaks, sensitive information disclosure, excessive agency, insecure output handling, and agent or tool-use security.
  • Practical understanding of generative AI architectures, large language models, retrieval-augmented generation, AI agents, APIs, and model or application lifecycle risks.
  • Ability to explain how risks such as indirect prompt injection or excessive agency would surface in a real agent workflow and how those risks could be detected, validated, and mitigated.
  • Experience evaluating security controls, technology vendors, data handling practices, privacy considerations, and third-party risk.
  • Ability to develop clear standards and communicate complex technical risks to engineers, product teams, business leaders, and executives.
  • Strong analytical, written, verbal, collaboration, and problem-solving skills.
  • Sound judgment, personal integrity, curiosity, and a demonstrated commitment to protecting confidential information.

      Preferred Qualifications

      • Experience with AI-security, application-security, cloud-security, data-security, DevSecOps, or security-monitoring tools.
      • Experience performing AI red teaming, adversarial testing, penetration testing, threat modeling, or control validation.
      • Familiarity with the NIST AI Risk Management Framework or comparable AI-governance frameworks.
      • Experience integrating security controls into software development, cloud engineering, or platform operations.
      • Familiarity with data classification, DLP, audit logging, security information and event management, and privacy-by-design practices.
      • Relevant certifications such as CISSP, Security+, or a portfolio demonstrating comparable practical experience.

      McCarthy is proud to be an equal opportunity employer, including disability and protected veteran status.

      NOTICE TO EXTERNAL SEARCH FIRMS: McCarthys Talent Acquisition Team is the only authorized representative permitted to engage with external search firms, staffing agencies, or other third-party recruiting partners. McCarthy maintains an Approved Agency List for recruiting partners, which is reviewed and updated annually.

      McCarthy will only consider submissions from agencies with a signed fee agreement in place for the current year. McCarthy does not accept unsolicited resumes, candidate submissions, or referrals from agencies that do not meet these requirements.

      If a candidate is submitted without an active agreement, McCarthy will have no obligation to pay any fees and reserves the right to contact, engage, interview, or hire such candidate(s) without any financial or other responsibility to the submitting agency. Unsolicited resumes, including those sent directly to hiring managers or other employees, will be considered the property of McCarthy.





      Equal employment opportunity, including veterans and individuals with disabilities.

      PI286761869

      Sign up for Job Alerts