About this role
The Senior Security Engineer, AI Security is a hands-on technical expert responsible for designing, implementing, and continuously enhancing the firm's AI Security Program. This role will serve as a key security partner to Application Security, Product Development, Technology Architecture, Infrastructure, and AI Enablement teams to ensure AI technologies are deployed securely, responsibly, and in alignment with technologies are deployed securely, responsibly, and in alignment with business, regulatory, and risk management requirements.
This role is responsible for implementing security controls across the AI ecosystem, including large language models (LLMs), AI coding assistants, Agents, AI gateways, and platforms such as Claude. The successful candidate will establish security guardrails, monitor AI risks, implement technical controls, and support governance processes that enable secure AI adoption.
The ideal candidate brings deep expertise in AI, application, and cloud security, with the ability to navigate complexity, solve complex problems, work effectively amid ambiguity, and deliver measurable security outcomes.
ESSENTIAL JOB DUTIES & RESPONSIBILITIES
- Lead the implementation, maturation, and continuous improvement of the enterprise AI Security Program.
- Develop and operationalize AI security standards, control frameworks, secure design patterns, implementation baselines, and governance processes that support the secure evaluation, onboarding, deployment, and monitoring of AI technologies.
- Serve as the lead security engineer for enterprise AI platforms, including Claude, AI coding assistants, AI gateways, Agents, MCP-based integrations, and other emerging AI technologies.
- Design, implement, and continuously improve security controls including identity and access management, authorization models, tenant security configurations, encryption, logging, monitoring, and data protection safeguards.
- Develop and operationalize AI guardrails to mitigate risks including prompt injection, jailbreaks, unauthorized access, excessive agency, sensitive data exposure, model misuse, and adversarial attacks.
- Develop security automation, governance automation, and policy-as-code capabilities that enable scalable AI security operations.
- Contribute to security architecture reviews and threat modeling activities for AI-enabled applications, platforms, agents, workflows, and integrations.
- Establish secure development standards for AI-enabled software development practices.
- Support security operations teams in monitoring and responding to AI security threats and emerging adversarial techniques.
- Partner with Data Protection, Privacy, Compliance, and Governance teams to implement safeguards for the secure use of data within AI platforms.
- Function as the firm's subject matter expert on AI security, emerging threats, adversarial AI risks, and industry best practices.
- Provide technical security engineering leadership for AI security innovation, proof-of-concepts, and future-state capabilities that improve security and business enablement.
- Define, and report key performance indicators (KPIs) to measure security effectiveness and maturity.
- Stay current on emerging threats, technologies, and industry trends to proactively reduce organizational risk.
- Build strong cross-functional partnerships across global teams and external stakeholders.
EDUCATION
- Bachelor’s degree in information security, IT, related discipline, or equivalent experience
- Professional certifications such as CISSP, CCSP, CISM, or similar preferred
SKILLS AND EXPERIENCE
- 10+ years of experience in security engineering, application security, cloud security, or a related cybersecurity discipline, with 3+ years of hands-on experience securing AI platforms, AI-enabled applications, or enterprise AI solutions.
- Deep knowledge of AI security principles and frameworks, including OWASP Top 10 for LLM Applications, NIST AI Risk Management Framework (AI RMF), MITRE ATLAS, secure AI development practices, and AI governance principles.
- Strong understanding of AI threats including prompt injection, jailbreaks, data poisoning, model manipulation, excessive agency, MCP vulnerabilities and sensitive data exposure.
- Experience securing enterprise AI platforms such as Claude, Microsoft Copilot, AI coding assistants, AI agents, or similar technologies.
- Experience implementing identity, authentication, authorization, RBAC, API security, and privileged access controls for AI platforms.
- Experience building security automation, policy-as-code, and governance automation to support AI security operations at scale.
- Knowledge of Secure SDLC, OWASP Top 10, API Security, software supply chain security, container security, and DevSecOps best practices.
- Demonstrated ability to build developer-friendly security controls that balance risk management with engineering productivity.
- Ability to manage multiple concurrent objectives and activities and make effective judgments in prioritizing and time allocation.
- Must be able to build collaborative relationships and is comfortable interacting frequently with leadership and internal/external stakeholders.
Salary Information
NY Only: The estimated base salary range for this position is $180,000 to $215,000 at the time of posting.
The actual salary offered will depend on a variety of factors, including without limitation, the qualifications of the individual applicant for the position, years of relevant experience, level of education attained, certifications or other professional licenses held, and if applicable, the location in which the applicant lives and/or from which they will be performing the job. This role is exempt meaning it is not overtime pay eligible.
Simpson Thacher will not sponsor applicants for work visas for this position.
Privacy Notice
For information about how Simpson Thacher & Bartlett LLP collects and processes your personal information, please refer to our Privacy Notice available at https://www.stblaw.com/other/privacy-notice .
Simpson Thacher & Bartlett is committed to a collegial work environment in which all individuals are treated with respect and dignity. The Firm prohibits discrimination or harassment based upon race, color, religion, gender, gender identity or expression, age, national origin, citizenship status, disability, marital or partnership status, sexual orientation, veteran’s status or any other legally protected status. This Policy pertains to every aspect of an individual’s relationship with the Firm, including but not limited to recruitment, hiring, compensation, benefits, training and development, promotion, transfer, discipline, termination, and all other privileges, terms and conditions of employment.
#LI-Hybrid