EngRadardirect-apply

Senior AI Security Engineer

InvoiceCloud

InvoiceCloud is a fast-growing fintech leader recognized with 20 major awards in 2025, providing a platform to reduce digital exclusion and restore simplicity and dignity to how people pay for essential services.

InvoiceCloud is the employer — EngRadar is a job radar, not a recruiter. We track this posting from their own careers page and send you straight there; we never handle applications or CVs.

Hyderabad, India Posted today fintech

About InvoiceCloud: 

InvoiceCloud is a fast-growing fintech leader recognized with 20 major awards in 2025, including USA TODAY and Boston Globe Top Workplaces, multiple SaaS Awards wins for Best Solution for Finance and FinTech, and national customer service honors from Stevie and the Business Intelligence Group. Judges also highlighted our mission to reduce digital exclusion and restore simplicity and dignity to how people pay for essential services, as well as our leadership in AI maturity and responsible innovation. It’s an award-winning, purpose-driven environment where top talent thrives. To learn more, visit InvoiceCloud.com. 

AI Security Engineer

InvoiceCloud is a fast-growing fintech company with an award-winning culture and a leading disruptor in the electronic bill presentment and payment (EBPP) space. Serving more than 3,200 customers across the utility, government, and insurance industries, InvoiceCloud's secure and innovative SaaS platform enhances the customer experience, driving higher digital payment, AutoPay, and paperless adoption rates. By switching to InvoiceCloud, clients can improve customer engagement and satisfaction while lowering costs, accelerating payments, and reducing staff workloads. To learn more, visit InvoiceCloud.com. 

Excellence in technology, information security, and regulatory compliance are foundational to our success. InvoiceCloud has chosen an AI First approach with the technology augmenting human activities across the globe. The AI Security Engineer designs and implements security controls for AI/ML systems and generative AI capabilities, enabling safe innovation across InvoiceCloud products and internal operations. This role partners with Engineering, Data Science, Product, DevSecOps, and Security Operations to threat model AI use cases, build secure AI/ML delivery pipelines (MLSecOps), perform adversarial testing and AI red teaming, and ensure AI solutions meet security, privacy, and compliance expectations.

 

Mission:

 

The AI Security Engineer plays a key role in the InvoiceCloud Cybersecurity Program. This role requires strong attention to detail, persistence, expertise in application security and AI/ML risk, planning skills, self-motivation, organization, communication, and problem-solving abilities. The primary objective of this position is to consistently identify, prioritize, and reduce AI-specific security risks across the model lifecycle—data, training, evaluation, deployment, and operations—while maintaining business velocity and product quality.

 

Responsibilities:

  • AI Security Architecture & Secure Design
    • Design and implement security controls for AI/ML and generative AI systems across the full lifecycle (data → training → evaluation → deployment → monitoring).
    • Establish secure reference architectures for common patterns (e.g., retrieval-augmented generation (RAG), model gateways, tool/agent execution) with least privilege, data minimization, and isolation.
  • Threat Modeling & Risk Assessment
    • Perform AI/ML threat modeling for new and existing systems, including prompt injection, data poisoning, model extraction, data leakage, and abuse/misuse scenarios.
    • Map risks to industry frameworks (e.g., OWASP Top 10 for LLM Applications, MITRE ATLAS, NIST AI RMF) and drive mitigations with engineering teams.
  • Secure MLOps / MLSecOps
    • Partner with DevSecOps/MLOps to integrate security into AI delivery pipelines (secure model registry, artifact signing, provenance, access control, dependency scanning, secrets management, CI/CD guardrails).
    • Ensure training and inference environments are hardened (cloud IAM, network segmentation, key management, container security).
  • AI Security Testing & Red Teaming
    • Build and execute AI security test plans and adversarial evaluations (prompt injection, jailbreaks, data exfiltration, content policy bypass, model evasion).
    • Develop automated test harnesses and regression suites to validate controls over time.
  • Monitoring, Detection & Incident Response
    • Define and implement telemetry for AI systems (prompt/output logging, tool calls, policy decisions) with appropriate privacy controls.
    • Integrate AI security signals into SIEM/SOC workflows; create detection logic and response playbooks for AI-specific incidents.
  • Governance, Privacy & Third-Party Risk
    • Support AI governance by defining security requirements for AI use cases, third-party models/vendors, and data usage.
    • Partner with Legal/Privacy/Compliance to ensure AI implementations align with internal policy and applicable regulations.
  • Cross-Functional Collaboration & Enablement
    • Provide security guidance, training, and documentation for engineers and data scientists; raise overall AI security maturity.
    • Communicate risks and progress updates to Security leadership, ELT stakeholders, and the CISO as needed.

 

Qualifications:

This role has privileged access to highly sensitive information, intellectual property, legal matters, and complex business scenarios.  The successful candidate has:

  • Bachelor’s degree in Computer Science, Cybersecurity, Engineering, Data Science, or related field (or equivalent practical experience).
  • 5+ years of experience in security engineering, application/product security, cloud security, or DevSecOps.
  • 2+ years of experience building or securing AI/ML systems (including LLM-based applications) in production environments.
  • Strong understanding of AI/ML threats and defenses (e.g., prompt injection, data poisoning, model extraction, model inversion, adversarial inputs, data leakage, abuse/misuse).
  • Experience integrating security into CI/CD and MLOps pipelines; comfortable with containerization and cloud platforms (AWS and Azure).
  • Preferred: Familiarity with OWASP GenAI guidance/Top 10 for LLM Applications, MITRE ATLAS, and/or NIST AI RMF.
  • Preferred: Certifications such as CISSP, CSSLP, CCSP, Azure Security certifications, or relevant GIAC certifications.

 

Personal Skills 

  • Optimistic, persistently driving for the positive outcome 
  • Team player; collaborative and can work independently
  • Excellent coordination and orchestration abilities 
  • Strong work ethic, interpersonal skills, time management, planning and execution skills 
  • Resourceful, collaborative, ‘out of the box’ thinking 
  • Demonstrates a personal code of ethics, integrity, and trust
  • Able to successfully navigate within varying degrees of ambiguity in a fast-paced environment  
  • Efficient communications skills (written/verbal) and interpersonal savvy  
  • Possess a good sense of self and a strong, approachable personal presence.    
  • Possess the determination to get results without harm, provide transparent feedback, and prioritize a positive outcome

 

Outcomes 

First 30 days – Immersion and Formulation 

  • Inventory current and planned AI/ML and generative AI use cases across products and internal operations; document architecture, data flows, and sensitive-data touchpoints.
  • Establish a baseline AI security posture by reviewing existing controls (access, secrets, logging, content filtering, data governance) and identifying immediate gaps.
  • Define/confirm an AI security taxonomy and intake process (risk rating, approvals, documentation, and ownership) aligned with the SDLC.
  • Meet with Engineering, Data Science, Product, DevSecOps, Legal/Privacy, and SOC to align priorities, risk appetite, and escalation paths.
  • Select and socialize the primary frameworks and references for AI security (e.g., OWASP Top 10 for LLM Applications, MITRE ATLAS, NIST AI RMF) and map them to InvoiceCloud’s environment.
  • Identify and prioritize the top 2–3 near-term initiatives (e.g., secure GenAI reference architecture, AI red teaming process, model and data protection controls).
  • Observe meetings and insert yourself into communications streams (design reviews, security reviews, SOC and incident review cadences). 

 

First 150 days - Execution 

  • Deliver threat models and secure design recommendations for priority AI/ML systems, including GenAI/RAG patterns and any agent/tool integrations.
  • Implement a secure reference architecture and guardrails for GenAI applications (prompt injection defenses, least-privilege tool access, data-loss prevention for prompts/outputs, isolation/sandboxing where needed).
  • Integrate AI/ML security controls into MLOps pipelines (artifact integrity, model registry protections, access control, environment hardening, dependency scanning, secrets management).
  • Stand up an AI security testing and red teaming workflow; build a repeatable test plan and automate regression tests for known abuse cases.
  • Define and implement runtime monitoring for AI systems (prompt/output/tool telemetry, abuse detection, anomaly signals) and integrate key signals into SIEM/SOC workflows.
  • Develop AI-specific incident response playbooks (prompt injection/data exfiltration, model theft, training data compromise, malicious output) and run at least one tabletop exercise.
  • Provide recurring progress updates and metrics to Security leadership and partner teams; track remediation through to closure. 

 

First 210 days – Results 

  • Deliver documented value for the top priorities defined in the Immersion and Execution phases (e.g., measurable risk reduction, improved guardrails, improved monitoring coverage, reduced data exposure).
  • Establish a sustainable operating rhythm for AI security: intake/design reviews, security testing cadence, red team findings → remediation pipeline, and monitoring/alerting ownership.
  • Publish a forward-looking 6‑month and 12‑month AI security maturation plan (outcomes, key metrics, tooling needs, and process improvements) aligned to business goals.
  • Ensure AI security requirements are embedded into product SDLC, procurement/vendor evaluations, and platform engineering standards.
  • Create executive-ready reporting that communicates AI security posture and trend insights to ELT stakeholders and the CISO.

 

Competencies 

  • Leadership – humble but confident, persuasive, inspirational, determined, patient, accountable, and objective 
  • Subject Matter Expert – recognized as, demonstrates, and qualifies as the as key knowledge base for risk 
  • Business Acumen – tempers and overlays all actions, outcomes, and initiatives with a consideration of business impact, leverages knowledge of management, development, product, legal, and business development in execution of objectives 
  • Critical, Multi-Dimensional Thinker – digs deep, doesn’t settle for surface answers or “how” answers to “what and why” questions; looks for the truth, not the easy and potentially wrong or most disruptive solution 
  • Organization – gravitates towards bringing order to chaos and can quickly organize and maintain order from disorder 
  • Accountability and responsibility - ability to embrace and foster a culture of ownership by accurately forecasting, reporting, and monitoring of key metrics; recognize successful achievement 

 

Benefits
We offer a competitive benefits program including:

  • Medical, dental, vision, life & disability insurance
  • 401(k) plan with company match
  • Flexible Time Off (FTO), wellbeing days, paid holidays, and summer Fridays
  • Mental health resources
  • Paid parental leave & Backup Care
  • Tuition reimbursement
  • Employee Resource Groups (ERGs)

InvoiceCloud is committed to providing equal employment opportunities to all employees and applicants. We do not tolerate discrimination or harassment of any kind based on race, color, religion, age, sex, nationality, disability, genetic information, veteran or military status, sexual orientation, gender identity or expression, or any other characteristic protected under applicable laws.

This commitment applies to all aspects of employment, including recruitment, hiring, placement, promotion, termination, layoff, recall, transfer, leave, compensation, and training.

If you require a disability-related or religious accommodation during the application or recruitment process, and wish to discuss possible adjustments, please contact [email protected].

Click here to review InvoiceCloud’s Job Applicant Privacy Policy.

For recruitment agencies: InvoiceCloud does not accept unsolicited resumes from agencies. Please do not forward resumes to our job aliases, employees, or any other company location. InvoiceCloud is not responsible for any fees associated with unsolicited submissions.

Posted by InvoiceCloud on their own careers page — you apply directly, no recruiter in between. View original / apply →

More at InvoiceCloud

Database Engineer

InvoiceCloud · InvoiceCloud is a fast-growing fintech leader recognized with 20…

Remote United States - Remote fintech
3mo ago

Data Engineer

InvoiceCloud · InvoiceCloud is a fast-growing fintech leader recognized with 20…

Hyderabad, India fintech
8mo ago