Senior AI Security Engineer
Job Summary
About InvoiceCloud:
InvoiceCloud is a fast-growing fintech leader recognized with 20 major awards in 2025 including USA TODAY and Boston Globe Top Workplaces multiple SaaS Awards wins for Best Solution for Finance and FinTech and national customer service honors from Stevie and the Business Intelligence Group. Judges also highlighted our mission to reduce digital exclusion and restore simplicity and dignity to how people pay for essential services as well as our leadership in AI maturity and responsible innovation. Its an award-winning purpose-driven environment where top talent thrives. To learn more .
AI Security Engineer
InvoiceCloud is a fast-growing fintech company with an award-winning culture and a leading disruptor in the electronic bill presentment and payment (EBPP) space. Serving more than 3200 customers across the utility government and insurance industries InvoiceClouds secure and innovative SaaS platform enhances the customer experience driving higher digital payment AutoPay and paperless adoption rates. By switching to InvoiceCloud clients can improve customer engagement and satisfaction while lowering costs accelerating payments and reducing staff workloads. To learn more .
Excellence in technology information security and regulatory compliance are foundational to our success. InvoiceCloud has chosen an AI First approach with the technology augmenting human activities across the globe. The AI Security Engineer designs and implements security controls for AI/ML systems and generative AI capabilities enabling safe innovation across InvoiceCloud products and internal operations. This role partners with Engineering Data Science Product DevSecOps and Security Operations to threat model AI use cases build secure AI/ML delivery pipelines (MLSecOps) perform adversarial testing and AI red teaming and ensure AI solutions meet security privacy and compliance expectations.
Mission:
The AI Security Engineer plays a key role in the InvoiceCloud Cybersecurity Program. This role requires strong attention to detail persistence expertise in application security and AI/ML risk planning skills self-motivation organization communication and problem-solving abilities. The primary objective of this position is to consistently identify prioritize and reduce AI-specific security risks across the model lifecycledata training evaluation deployment and operationswhile maintaining business velocity and product quality.
Responsibilities:
- AI Security Architecture & Secure Design
- Design and implement security controls for AI/ML and generative AI systems across the full lifecycle (data training evaluation deployment monitoring).
- Establish secure reference architectures for common patterns (e.g. retrieval-augmented generation (RAG) model gateways tool/agent execution) with least privilege data minimization and isolation.
- Threat Modeling & Risk Assessment
- Perform AI/ML threat modeling for new and existing systems including prompt injection data poisoning model extraction data leakage and abuse/misuse scenarios.
- Map risks to industry frameworks (e.g. OWASP Top 10 for LLM Applications MITRE ATLAS NIST AI RMF) and drive mitigations with engineering teams.
- Secure MLOps / MLSecOps
- Partner with DevSecOps/MLOps to integrate security into AI delivery pipelines (secure model registry artifact signing provenance access control dependency scanning secrets management CI/CD guardrails).
- Ensure training and inference environments are hardened (cloud IAM network segmentation key management container security).
- AI Security Testing & Red Teaming
- Build and execute AI security test plans and adversarial evaluations (prompt injection jailbreaks data exfiltration content policy bypass model evasion).
- Develop automated test harnesses and regression suites to validate controls over time.
- Monitoring Detection & Incident Response
- Define and implement telemetry for AI systems (prompt/output logging tool calls policy decisions) with appropriate privacy controls.
- Integrate AI security signals into SIEM/SOC workflows; create detection logic and response playbooks for AI-specific incidents.
- Governance Privacy & Third-Party Risk
- Support AI governance by defining security requirements for AI use cases third-party models/vendors and data usage.
- Partner with Legal/Privacy/Compliance to ensure AI implementations align with internal policy and applicable regulations.
- Cross-Functional Collaboration & Enablement
- Provide security guidance training and documentation for engineers and data scientists; raise overall AI security maturity.
- Communicate risks and progress updates to Security leadership ELT stakeholders and the CISO as needed.
Qualifications:
This role has privileged access to highly sensitive information intellectual property legal matters and complex business scenarios. The successful candidate has:
- Bachelors degree in Computer Science Cybersecurity Engineering Data Science or related field (or equivalent practical experience).
- 5 years of experience in security engineering application/product security cloud security or DevSecOps.
- 2 years of experience building or securing AI/ML systems (including LLM-based applications) in production environments.
- Strong understanding of AI/ML threats and defenses (e.g. prompt injection data poisoning model extraction model inversion adversarial inputs data leakage abuse/misuse).
- Experience integrating security into CI/CD and MLOps pipelines; comfortable with containerization and cloud platforms (AWS and Azure).
- Preferred: Familiarity with OWASP GenAI guidance/Top 10 for LLM Applications MITRE ATLAS and/or NIST AI RMF.
- Preferred: Certifications such as CISSP CSSLP CCSP Azure Security certifications or relevant GIAC certifications.
Personal Skills
- Optimistic persistently driving for the positive outcome
- Team player; collaborative and can work independently
- Excellent coordination and orchestration abilities
- Strong work ethic interpersonal skills time management planning and execution skills
- Resourceful collaborative out of the box thinking
- Demonstrates a personal code of ethics integrity and trust
- Able to successfully navigate within varying degrees of ambiguity in a fast-paced environment
- Efficient communications skills (written/verbal) and interpersonal savvy
- Possess a good sense of self and a strong approachable personal presence.
- Possess the determination to get results without harm provide transparent feedback and prioritize a positive outcome
Outcomes
First 30 days Immersion and Formulation
- Inventory current and planned AI/ML and generative AI use cases across products and internal operations; document architecture data flows and sensitive-data touchpoints.
- Establish a baseline AI security posture by reviewing existing controls (access secrets logging content filtering data governance) and identifying immediate gaps.
- Define/confirm an AI security taxonomy and intake process (risk rating approvals documentation and ownership) aligned with the SDLC.
- Meet with Engineering Data Science Product DevSecOps Legal/Privacy and SOC to align priorities risk appetite and escalation paths.
- Select and socialize the primary frameworks and references for AI security (e.g. OWASP Top 10 for LLM Applications MITRE ATLAS NIST AI RMF) and map them to InvoiceClouds environment.
- Identify and prioritize the top 23 near-term initiatives (e.g. secure GenAI reference architecture AI red teaming process model and data protection controls).
- Observe meetings and insert yourself into communications streams (design reviews security reviews SOC and incident review cadences).
First 150 days - Execution
- Deliver threat models and secure design recommendations for priority AI/ML systems including GenAI/RAG patterns and any agent/tool integrations.
- Implement a secure reference architecture and guardrails for GenAI applications (prompt injection defenses least-privilege tool access data-loss prevention for prompts/outputs isolation/sandboxing where needed).
- Integrate AI/ML security controls into MLOps pipelines (artifact integrity model registry protections access control environment hardening dependency scanning secrets management).
- Stand up an AI security testing and red teaming workflow; build a repeatable test plan and automate regression tests for known abuse cases.
- Define and implement runtime monitoring for AI systems (prompt/output/tool telemetry abuse detection anomaly signals) and integrate key signals into SIEM/SOC workflows.
- Develop AI-specific incident response playbooks (prompt injection/data exfiltration model theft training data compromise malicious output) and run at least one tabletop exercise.
- Provide recurring progress updates and metrics to Security leadership and partner teams; track remediation through to closure.
First 210 days Results
- Deliver documented value for the top priorities defined in the Immersion and Execution phases (e.g. measurable risk reduction improved guardrails improved monitoring coverage reduced data exposure).
- Establish a sustainable operating rhythm for AI security: intake/design reviews security testing cadence red team findings remediation pipeline and monitoring/alerting ownership.
- Publish a forward-looking 6month and 12month AI security maturation plan (outcomes key metrics tooling needs and process improvements) aligned to business goals.
- Ensure AI security requirements are embedded into product SDLC procurement/vendor evaluations and platform engineering standards.
- Create executive-ready reporting that communicates AI security posture and trend insights to ELT stakeholders and the CISO.
Competencies
- Leadership humble but confident persuasive inspirational determined patient accountable and objective
- Subject Matter Expert recognized as demonstrates and qualifies as the as key knowledge base for risk
- Business Acumen tempers and overlays all actions outcomes and initiatives with a consideration of business impact leverages knowledge of management development product legal and business development in execution of objectives
- Critical Multi-Dimensional Thinker digs deep doesnt settle for surface answers or how answers to what and why questions; looks for the truth not the easy and potentially wrong or most disruptive solution
- Organization gravitates towards bringing order to chaos and can quickly organize and maintain order from disorder
- Accountability and responsibility - ability to embrace and foster a culture of ownership by accurately forecasting reporting and monitoring of key metrics; recognize successful achievement
Benefits
We offer a competitive benefits program including:
- Medical dental vision life & disability insurance
- 401(k) plan with company match
- Flexible Time Off (FTO) wellbeing days paid holidays and summer Fridays
- Mental health resources
- Paid parental leave & Backup Care
- Tuition reimbursement
- Employee Resource Groups (ERGs)
InvoiceCloud is committed to providing equal employment opportunities to all employees and applicants. We do not tolerate discrimination or harassment of any kind based on race color religion age sex nationality disability genetic information veteran or military status sexual orientation gender identity or expression or any other characteristic protected under applicable laws.
This commitment applies to all aspects of employment including recruitment hiring placement promotion termination layoff recall transfer leave compensation and training.
If you require a disability-related or religious accommodation during the application or recruitment process and wish to discuss possible adjustments please contact .
Click here to review InvoiceClouds Job Applicant Privacy Policy.
For recruitment agencies: InvoiceCloud does not accept unsolicited resumes from agencies. Please do not forward resumes to our job aliases employees or any other company location. InvoiceCloud is not responsible for any fees associated with unsolicited submissions.
Required Experience:
Senior IC
About Company
Invoice Cloud provides simple online electronic bill payment solutions that improve customer engagement and increase e-payment adoption. Schedule A Demo Today.