Thrivent is a financial organization committed to helping others thrive with purpose. They are seeking a Principal Engineer in AI Security to define and lead their strategy for defending against emerging AI-powered threats, focusing on protecting the enterprise from adversarial AI capabilities. The role involves deep technical expertise in AI-driven threats and requires collaboration across teams to implement scalable protections.
Responsibilities:
- Apply expert-level knowledge of AI-driven threats, cyber defense, and enterprise security architecture to define and drive outcomes that protect the organization from emerging AI-powered attack vectors
- Create the enterprise strategy for defending against AI-enabled threats, including automated vulnerability discovery, exploitation, and adversarial AI techniques
- Establish architecture for detection, prevention, and response capabilities specific to generative AI threat patterns
- Define and implement security patterns and guardrails to enable safe and secure enterprise consumption of AI technologies
- Drive integration of AI threat detection and controls into existing cyber defense tooling and platforms
- Build threat models focused on generative AI attack patterns and emerging adversarial techniques
- Use independent, critical thinking to translate evolving AI threat intelligence into scalable engineering controls and defensive capabilities
- Lead the development of detection and response mechanisms for AI-driven attacks across enterprise environments
- Design and implement telemetry strategies to identify anomalous behavior indicative of AI-enabled threats
- Partner with Cyber Defense teams to operationalize detections, response playbooks, and automation for AI-related incidents
- Prototype and evaluate defensive applications of AI to enhance detection, response, and security operations
- Develop architecturally significant components that advance the organization’s ability to defend against AI-driven adversaries
- Lead research initiatives focused on emerging AI threat capabilities, adversarial AI techniques, and evolving attack methodologies
- Maintain deep expertise in industry frameworks such as OWASP LLM Top 10 and MITRE ATLAS
- Continuously evaluate and introduce modern security technologies and approaches to address AI-era risks
- Drive adoption of innovative defensive techniques across the organization to stay ahead of threat evolution
- Provide deep technical expertise in AI security to solve complex, high-impact problems and remove critical technical roadblocks
- Partner with product owners and engineering teams to incorporate AI security requirements into technical designs and user stories
- Act as a technical leader in system design across teams, ensuring AI security considerations are embedded into broader architecture decisions
- Mentor engineers and elevate AI security capabilities within teams
- Partner closely with Cyber Defense, IAM, and Application Security teams to integrate AI threat protections across the security ecosystem
- Promote adherence to enterprise security standards while extending them to address AI-specific risks
- Broker design and implementation of AI security controls across product teams to support strategic priorities
- Drive alignment across teams on detection engineering, telemetry, and response strategies for AI threats
- Influence senior leadership on AI risk posture, threat landscape evolution, and required investments in defensive capabilities
- Provide enterprise-wide guidance on AI security architecture, ensuring consistent and scalable protection strategies
- Represent the organization externally on AI security topics when appropriate (industry forums, partnerships, etc.)
- Translate complex AI security risks into actionable insights for both technical and non-technical stakeholders
- Define enterprise-level capabilities required to defend against AI-powered threats
- Shape the strategic direction for AI security across cyber defense, detection engineering, and secure AI adoption
- Provide subject matter expertise to guide platform and security investments related to AI risk mitigation
- Establish and promote engineering standards for AI security, including secure AI usage patterns and detection frameworks
- Collaborate across teams to ensure consistent application of AI security controls and design patterns
- Drive adoption of best practices for integrating AI threat protections into engineering workflows and platforms
- Provide technical leadership in identifying and responding to AI-driven security incidents and emerging threats
- Introduce resilient and scalable technologies to improve detection and response capabilities for evolving attack patterns
- Evaluate and implement enhancements to CI/CD and operational pipelines to incorporate AI security controls
- Influence cross-functional teams to proactively address risks associated with AI-enabled development and deployment
- Provide technical expertise in evaluating AI security tools, detection platforms, and emerging defensive technologies
- Assess how vendor solutions align with enterprise strategy for defending against AI-driven threats
- Contribute to selection criteria for platforms that enhance AI security posture and detection capabilities
- Mentor engineers in AI security concepts, threat modeling, and detection engineering
- Provide guidance on best practices for securing AI-enabled systems and defending against adversarial AI techniques
- Deliver training, workshops, and knowledge-sharing sessions to build AI security expertise across the organization
- Engage in the broader AI and security community to strengthen organizational expertise and visibility in AI security
- Support recruitment efforts to hire engineers with specialized skills in AI security and advanced cyber defense
- Model Thrivent’s leadership competencies: Model the Way, Rally the Team, and Deliver Outcomes
- Foster a culture of continuous improvement, innovation, and strong security practices aligned to evolving AI risks
Requirements:
- Bachelor's degree in Computer Science, Cybersecurity, or related technical field, or equivalent work experience
- 10+ years of experience in security engineering or related field
- Proven experience defining and executing enterprise security strategy
- Deep knowledge of modern threats, attack techniques, and detection engineering
- Experience with threat modeling, incident response, and security operations
- Demonstrated ability to influence both technical and executive stakeholders
- Experience working with AI/ML systems and security implications
- Knowledge of adversarial AI techniques and AI threat modeling
- Experience with XDR, SIEM, and detection engineering practices
- Familiarity with AI security frameworks (e.g., OWASP LLM Top 10, MITRE ATLAS)
- Financial services industry experience