About this role
Position Overview
This role is the senior-most individual contributor in Technology and owns the technical direction for cybersecurity and AI security across Invitation Homes, including enterprise security architecture, secure development standards, and the security model for every AI and agentic system the company builds or buys. It requires deep, hands-on expertise in application, API, cloud, identity, and data security; in securing LLM and agentic systems (AI gateways, guardrails, adversarial testing, tool and MCP security); and in building the automation that enforces standards in the delivery pipeline. This role reports to the EVP & Chief Technology Officer and partners with the Chief Information Security Officer, who owns the security program, risk posture, and security operations, by setting architecture and engineering standards and building the controls that make them real. It serves as the technical authority on security to senior technology leadership and engineering teams. This is a builder's role with executive-level influence and no direct reports; the Fellow writes code and ships.
Key Responsibilities
- Own enterprise security architecture and standards across cloud, platform, identity, data, and applications, including reference architectures, secure defaults, and paved roads that make the secure path the shortest path, and hold security authority on the architecture review board.
- Define and enforce the security model for all AI and agentic systems, built or bought: the AI gateway as the single control point for model access (authentication, policy, logging, data classification, rate and cost limits, model routing), input and output guardrails, scoped agent identities and least-agency permissions, tool and MCP integration security, human approval for consequential actions, and kill-switch and containment controls.
- Lead threat modeling, secure design review, adversarial testing, and red-teaming for high-consequence systems (resident data, payments, identity, physical access, and AI actions with side effects), and build the automation that keeps review cycle time to days rather than weeks.
- Own the security quality gates in CI/CD, including static analysis, dependency and secrets scanning, infrastructure-as-code and container scanning, API testing, and scanning of AI-generated code, with gates that block on critical and high findings and exceptions that are time-bound and owned.
- Set identity and access architecture for workforce, resident, and non-human identities, including phishing-resistant MFA, privileged and just-in-time access, workload identity, secrets management, and scoped, auditable identities for AI agents.
- Drive cloud, platform, and data security engineering: security posture and attack-path management, Kubernetes hardening, policy as code, encryption and tokenization of personal and payment data, and data security posture and loss prevention across the warehouse and AI pipelines.
- Serve as technical lead on major incidents and partner with security operations on detection engineering as code, telemetry coverage for AI systems, and tabletop and purple-team exercises that include AI failure modes.
- Lead security assessments of models, vendors, and integrations (frontier model providers, AI coding assistants, data platforms, smart-home devices), write security requirements into contracts and integration designs, and perform technical due diligence for acquisitions.
- Establish engineering practices and metrics: threat modeling as a design artifact, evaluation-gated AI releases, right-sized model selection with cost and quality targets, design fidelity between approved and as-built architecture, architecture decision records, and security metrics reported alongside delivery metrics.
- Champion security tooling and automation across the platform (cloud security posture, endpoint and SIEM, SAST, SCA, secrets and API security, LLM gateway and guardrails, AI red-teaming and evaluation, AI observability, data security posture and loss prevention), and raise the security floor of the engineering organization through standards, reusable libraries, training, and mentorship of principal and senior engineers.
- Partner with the CTO, CISO, Legal, and Compliance on regulatory obligations that depend on technical controls, including SEC cybersecurity disclosure, SOX IT general controls, PCI DSS for rent payments, state privacy and breach notification laws, and FCRA and Fair Housing requirements for any model that touches leasing, screening, pricing, or collections.
Required Qualifications
- 15+ years of experience in software engineering and cybersecurity, including 8+ years focused on security and recent hands-on experience securing production generative AI, LLM, or agentic systems (threat modeling, adversarial testing, gateway and guardrail design, model and tool assessment).
- Proven success as the technical authority for security architecture at enterprise scale in a regulated or public-company environment.
- Hands-on engineer who writes production-quality code in Python and at least one other language, has built security tooling or automation that other teams depend on, and has integrated controls into CI/CD pipelines.
- Deep expertise in at least one major cloud platform (AWS, Azure, or GCP) and Kubernetes, with secure microservices and API design experience.
- Demonstrated record of reducing security review friction through automation without lowering the bar, with measurable results.
- Exceptional executive communication: explains technical risk to executives and the board in business terms and to engineers in specifics.
- Bachelor’s degree in computer science, engineering, or a related field, or equivalent experience. Experience with consumer platforms carrying payments, identity, and fraud exposure (real estate, fintech, telecom), IoT or smart-home security, or SEC registrant environments preferred.
Core Competencies
- Enterprise Security Architecture
- AI & Agentic Systems Security
- Secure SDLC & Pipeline Quality Gates
- Threat Modeling & Adversarial Testing
- Identity, Cloud & Data Security
- Detection & Incident Response Engineering
- Security Automation & Tooling
- Regulatory & Disclosure Fluency (SEC, SOX, PCI, FCRA, Fair Housing)
- Executive Communication & Engineering Influence
- Technical Mentorship & Enablement
## Salary Range
The salary range for this position is: $211,650.00 - $366,860.00, plus individuals may be eligible for an annual discretionary bonus. Actual compensation within the range will be dependent upon the individual's skills, experience, qualifications, location, and applicable employment laws.
Compensation and Benefits
To attract and retain top talent, we're pleased to offer competitive compensation and benefits, including:
- Annual bonus program
- Health, dental, vision, and life insurance
- Long-term and short-term disability insurance
- Generous paid time off plans include vacation accrual, sick time, standard holidays and floating holidays
- 401(k) with company matching contributions
- Awesome work environment with casual dress
- Team events and gatherings (Pre- and Post-Covid)
Invitation Homes is an equal opportunity employer committed to fostering a diverse, inclusive and innovative environment with the best associates. We are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity, Veteran status or any other factor protected by applicable federal, state or local law. If you have a disability or special need that requires accommodation, please contact us at [email protected] .
To all recruitment agencies: Invitation Homes does not accept agency resumes. Please do not forward resumes to Invitation Homes employees. Invitation Homes is not responsible for any fees related to unsolicited resumes.
#LI-JA1