Charlotte, NC

Salary
Posted
Jul 28, 2026
Location
Charlotte, NC
Last confirmed open
Jul 29, 2026

What this job asks for AI summary

A senior hands-on security engineering role at a regulated financial institution, focused on designing and implementing security controls for AI-enabled applications, LLM integrations, and agentic workloads. The engineer leads threat modeling, guardrail implementation, detection engineering, and deployment gating across AI and MLOps/LLMOps pipelines, while partnering with product, platform, and risk teams to embed security throughout the AI lifecycle.

Senior level · 10+ years · Full-time

Must have (11)
application securitythreat modelingpenetration testingLLMsCI/CDMLOpscloud-native securityAPI securitylogging and monitoringincident responseDevSecOps
Nice to have (7)
Azure or Microsoft Azure AiCopilot StudioAzure AIOWASPNIST AI RMFMITRE ATLASAI red teaming

“or” means any one of them counts — you don't need all of them.

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

What won't set you apart
incident response62%CI/CD45%application security40%

Most people in this occupation already list these. Still required — just not what gets you shortlisted.

What the occupation pays Median $132,021 (middle half $99,961–$167,095).

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 29, 2026. It is a model, not a headcount.

Why we read it this way (8)

No work location is specified in the posting beyond 'United States of America' (shift reference). No city, state, or metro is identified, so CBSA fields are left blank.

The role title is 'Lead AI Security Engineer.' The posting uses 'senior hands-on' in its description, and the title word 'Lead' maps most naturally to the Senior band given the 10-year experience gate and no explicit org-wide scope; it is not presented as a Staff or Principal role.

SOC classification is a genuine judgment call: the role is primarily security analysis and control design (15-1212), but it also involves substantial hands-on implementation and automation coding (15-1252). 15-1212 was chosen because threat modeling, detection engineering, guardrail validation, and incident response are the dominant day-to-day activities.

The posting requires a Bachelor's degree 'or equivalent education, training, and work-related experience,' so the degree requirement is set to None per schema rules.

Several required skills (e.g., 'security engineering,' 'application security,' 'cloud-native security,' 'identity and access control') are functional domains rather than specific named tools, but they appear explicitly in the Required Qualifications section with firm gating language and represent genuine rejection criteria for this role. They are retained as required skills accordingly.

The 3+ years in a lead/AI security discipline is a secondary experience gate nested within the broader 10-year requirement; the overall years minimum reflects the primary 10-year gate.

Preferred qualifications explicitly call out Microsoft, Azure, Copilot, Copilot Studio, Azure AI, OWASP LLM/agentic frameworks, NIST AI RMF, MITRE ATLAS, and AI red teaming — all marked as preferred.

Ignored 3 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): security engineering, detection engineering, identity and access control.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗