JLL is a leading global provider of real estate and investment management services, and they are seeking a Senior Security Engineer, AI Enablement to help the business adopt new AI capabilities securely. This role involves embedding with projects to provide security input, evaluating new AI technologies, and owning risk assessments for AI tools.
Responsibilities:
- Embed temporarily with business and technology teams launching new AI-enabled projects, from early design through launch, providing security input as the project is built rather than at a final review
- Translate emerging AI concepts and platforms, such as Anthropic Managed Agents, Claude Code, and Moveworks, into guidance a project team can act on immediately, not a policy document they have to interpret themselves
- Prioritize which projects need hands-on engagement versus lightweight guidance, based on the actual risk and complexity of what's being built
- Go deep on new AI platforms and capabilities as they reach JLL, including:
- Anthropic Managed Agents, Claude Agent SDK, and Claude Code
- Moveworks and comparable enterprise agent platforms
- New agentic and MCP-based tooling as vendors release it
- Identify the specific risks each new technology introduces, translating vendor documentation and platform behavior into a plain-language risk read the business can use to make a decision
- Define secure configuration patterns and reusable guardrails for each platform so every project adopting it starts from a secure baseline instead of reinventing one
- Own the risk assessment for new AI tools and platforms being evaluated by the business—covering data handling, tool permissions, and agent-to-system access—and turn findings into a clear go, no-go, or go-with-conditions recommendation
- Partner with third-party risk and enterprise risk functions on AI-specific findings, providing the technical depth those teams don't carry in-house
- Maintain a living library of platform risk assessments and secure patterns that other teams can reference before requesting a new one
- Act as the primary point of contact for business teams asking what AI tools they can use and how to use them safely
- Partner with the Sr. Security Engineer, AI Enablement embedded on Falcon, and other product-embedded security engineers, to keep guidance and patterns consistent across the business
- Represent business-facing AI enablement work to the Head of AI Security and the Cyber AI Consortium, surfacing patterns worth turning into enterprise-wide standards
- Maintain hands-on fluency with the AI platforms and agent frameworks JLL is actively adopting, rather than relying on vendor claims or documentation alone
- Track the broader AI vendor landscape for capabilities the business hasn't asked about yet but will
- Bring emerging risks and patterns back to the Head of AI Security so enterprise-wide guidance keeps pace with what's actually being adopted
Requirements:
- 5+ years of security engineering experience, including direct experience evaluating new technology platforms rather than only maintaining existing controls
- Hands-on experience with at least one enterprise AI agent platform, such as Anthropic Claude, Claude Code, Claude Managed Agents, or Moveworks
- Working understanding of how LLMs and AI agents handle data, tool-calling, and permissions, sufficient to assess a new platform without relying on vendor claims
- Demonstrated ability to translate a new, unfamiliar technology into plain-language risk findings and secure patterns a business team can act on
- Comfortable working across many projects and teams at once, re-prioritizing quickly as new tools and requests come in
- Excellent written and verbal communication skills—able to represent technical risk findings to both engineering teams and business stakeholders
- Bachelor's degree in Computer Science, Cybersecurity, or a related field, or equivalent practical experience
- Prior experience in a security architecture, third-party risk, or platform security role
- Familiarity with the OWASP LLM Top 10, MITRE ATLAS, or comparable AI and agentic threat frameworks
- Experience with MCP (Model Context Protocol) governance or enterprise agent permissioning
- Background working directly with business stakeholders outside of IT or Cybersecurity
- Certifications such as CISSP, CCSP, or an AI governance-specific credential