
Principal AI Security Automation Engineer
Depository Trust & Clearing Corporation (DTCC)2 months ago
Jersey City, NJ, USAStaff+
Responsibilities
- Design and implement automation workflows supporting AI-powered vulnerability discovery and remediation.
- Develop integrations between AI scanning platforms, security tools, and SDLC platforms.
- Build and maintain findings ingestion, normalization, and enrichment pipelines.
- Integrate AI scanning outputs into ASPM, vulnerability management, and developer workflows.
- Develop automated triage, prioritization, and remediation orchestration capabilities.
- Create dashboards, metrics, and reporting capabilities for security decision-making.
- Build APIs and automation services connecting enterprise security tooling.
- Partner with Application Security, Vulnerability Operations, and Development teams to operationalize findings.
- Improve scanning efficiency through workflow optimization and intelligent automation.
- Support secure deployment and operation of AI-based security capabilities.
- Contribute to governance, auditability, and operational controls for AI-driven security processes.
- Evaluate emerging AI security technologies and identify automation opportunities.
Requirements
- A minimum of 8 years of related experience.
- At least 6 years of software engineering, DevSecOps, Application Security, or security automation experience.
- Strong hands-on Python development experience for production-grade security tooling, automation frameworks, and integrations.
- Experience designing and operating application security tooling including SAST, DAST, SCA, secrets scanning, ASPM, or vulnerability management platforms.
- Experience integrating security controls into CI/CD pipelines and developer workflows.
- Strong understanding of secure software development, OWASP Top 10, secure coding, threat modeling, and vulnerability remediation.
- Experience developing API integrations using REST APIs, SDKs, and event-driven architectures.
- Experience with AI/LLM platforms such as Claude, OpenAI, Bedrock, or similar.
- Experience building automated workflows for vulnerability discovery, triage, prioritization, and remediation.
- Experience with Docker, Kubernetes, and OpenShift.
- Familiarity with AWS security services, IAM, Security Hub, GuardDuty, and cloud-native security controls.
- Experience with Git, Bitbucket, Jira, Jenkins, GitHub Actions, Maven, and related platforms.
- Understanding of AI security risks including prompt injection, model abuse, AI supply chain security, and agent security.
- Experience working in Agile delivery environments.
- A bachelor's degree is preferred and equivalent experience may be accepted.
- Preferred certifications include CISSP, TAISE, OSCP, CSSLP, or similar.
- Preferred experience includes Apiiro, Veracode, SonarQube, Semgrep, Burp Suite, policy-as-code, security guardrails, and enterprise-scale vulnerability management.
Benefits
- Competitive compensation including base pay and annual incentive.
- Comprehensive health and life insurance and well-being benefits, based on location.
- Pension and retirement benefits.
- Paid time off, personal and family care, and other leaves of absence.
- Flexible hybrid work model with three days onsite and two days remote; onsite days are Tuesdays, Wednesdays, and a third team- or employee-specific day.
- Professional development investment and a supportive internal community.