About this role
This is your opportunity to join AXIS Capital – a trusted global provider of specialty lines insurance and reinsurance. We stand apart for our outstanding client service, intelligent risk taking and superior risk adjusted returns for our shareholders. We also proudly maintain an entrepreneurial, disciplined and ethical corporate culture. As a member of AXIS, you join a team that is among the best in the industry.
At AXIS, we believe that we are only as strong as our people. We strive to create an inclusive and welcoming culture where employees of all backgrounds and from all walks of life feel comfortable and empowered to be themselves. This means that we bring our whole selves to work.
All qualified applicants will receive consideration for employment without regard to any protected characteristic, including age, color, disability, ethnicity, gender identity, marital status, national origin, pregnancy, race, religion, sex, sexual orientation, veteran status, or any basis prohibited by the laws that govern its operations.
Design, develop, and operationalize secure agentic AI capabilities in risk & security operations
- Build, deploy, and maintain AI-powered security agents to augment detection, investigation, and response workflows
- Identify high-value use cases where AI agents can accelerate analyst productivity and improve outcomes
- Continuously validate agent performance, accuracy, and reliability in real-world operations
Ensure responsible and secure use of AI across risk & security operations
- Enforce strong security controls for enterprise AI platforms (e.g., Microsoft Copilot, Copilot Studio, Azure AI Foundry)
- Mitigate AI-specific risks including data leakage, prompt injection, oversharing, and unauthorized access
- Establish evaluation practices for agent accuracy, hallucination risk, false positives/false negatives, failure modes, explainability, audit logging, and measurable operational impact.
- Ensure human-in-the-loop oversight to include analysts challenge, refine, and retrain AI-driven outcomes
Implement and manage data protection controls for AI and enterprise data
- Deploy and optimize Microsoft Purview capabilities (DLP, Information Protection, Insider Risk) across M365 and AI platforms
- Implement DLP controls for AI interactions and outputs to prevent sensitive data exposure
- Monitor and tune data protection policies to meet regulatory and business requirements
Secure AI agents, automation, and data flows
- Define and enforce access controls, data handling policies, and auditability for AI agents and automated workflows
- Ensure all AI-driven processes align with Zero Trust and least privilege principles
- Evaluate and onboard new AI tools and agents with a security-first approach
Operational monitoring, detection, and response
- Monitor AI platform activity and data usage to detect anomalies, misuse, or policy violations
- Support incident response and investigations involving AI systems and data exposure scenarios
- Integrate AI agent workflows directly with SIEM/XDR platforms to allow autonomous context enrichment and preliminary incident triage.
- Support enterprise rollout of AI governance and data security programs
About You:
We encourage you to bring your own experience and expertise to the table, so while there are some qualifications and experiences, we need you to have, we are open to discussing how your individual knowledge might lend itself to fulfilling this role and help us achieve our goals.
What you need to have:
- Bachelor’s degree in Information Technology, Cybersecurity, or related field (Master’s preferred), OR equivalent experience leading enterprise-scale security engineering initiatives
- 5+ years of progressive experience in cybersecurity, data protection, or security engineering
- Proven experience designing and securing enterprise AI platforms, including: Microsoft Copilot, Copilot Studio, and Azure AI Foundry
- Governance, data grounding controls, prompt injection protections, and AI risk management
- Development or oversight of security controls for AI-driven workflows and autonomous/agent-based systems.
- Hands-on expertise with Microsoft security and compliance ecosystems, including: Microsoft Purview (end-to-end deployment, governance, and optimization)
- Microsoft 365, Azure, and Entra ID security architecture
- Collaboration platforms (Exchange, SharePoint, OneDrive, Teams) with a strong focus on data protection and insider risk
- Proven expertise in Data Security and Protection, including: Data Loss Prevention (DLP) strategy, engineering, and tuning at scale
- Data classification, sensitivity labeling, and lifecycle management
- Insider Risk Management and Information Protection programs
- Demonstrated ability to architect and lead enterprise security solutions, including: Defining strategy, roadmaps, and reference architectures
- Driving cross-functional initiatives across Security, IT, Legal, and Business teams
- Acting as a technical authority and escalation point for complex security challenges
- Strong development and automation capabilities, including: Proficiency in Python, PowerShell, TypeScript or similar languages; secure API integration; Microsoft Graph and security platform APIs; CI/CD practices; test automation; and experience deploying AI-enabled workflows using Azure Functions, Logic Apps, or comparable cloud-native services.
- Building automation pipelines for detection, response, and data governance workflows
- Experience with security analytics and telemetry, including: Interpreting logs and signals from Microsoft 365, Azure, endpoints, and AI systems
- Supporting detection engineering and threat-informed defense strategies
- Ability to lead in complex, ambiguous environments, including: Rapidly assessing risk and prioritizing high-impact outcomes
- Driving technical decision-making with incomplete information
- Mentoring junior engineers and elevating overall team capability
What we prefer you to have:
- Experience with prompt engineering techniques or semantic caching.
- A firm understanding of the OWASP Top 10 for LLMs.
- Experience working with Data Security Posture Management (DSPM) tools.
- Experience supporting data leakage or insider threat programs
- Relevant Cybersecurity certifications AI-102 (Azure AI Engineer Associate)
- AI-900 (Microsoft Azure AI Fundamentals)
- SC-400 (Information Protection Administrator)
- MS-102 (Microsoft 365 Administrator)
- CompTIA Security+
- CompTIA SecAI+
Role Factors:
In this role, you will support enterprise-wide data protection and governance initiatives leveraging Microsoft 365 platforms. This includes safeguarding sensitive data, enabling secure collaboration, and supporting emerging AI technologies like Copilot by ensuring proper data classification and protection standards are in place. The work is highly visible and directly impacts how the organization securely manages and scales its data environment.
What we offer:
For this position, we currently expect to offer a base salary in the range of $90K - $110K Your salary offer will be based on an assessment of a variety of factors including your specific experience and work location.
In addition, you will be offered competitive target incentive compensation, with awards based on overall corporate and individual performance. On top of this, you will be eligible for a comprehensive and competitive benefits package which includes medical plans for you and your family, health and wellness programs, retirement plans, tuition reimbursement, paid vacation, and much more.
Where this role is based in the United States of America, this role is exempt for FLSA purposes.
This posting is for an existing vacancy.