Tenable

AI Information Security Engineer

Tenable
Apply
5 days ago
Boston, MA, USA or Columbia, MD, USASenior

Base Salary

$123k - $163k/yr

Responsibilities

  • Design, implement, and maintain security controls across the AI/ML lifecycle.
  • Conduct AI safety research by inspecting model internals for hidden deception, latent knowledge, unwanted concepts, and other risks.
  • Perform AI safety assessments and threat modeling for risks including data poisoning, model evasion, model extraction, adversarial inputs, and integrity attacks.
  • Design security guardrails and boundary mechanisms for LLMs, SLMs, and open-source models.
  • Monitor emerging AI vulnerabilities and attack techniques and develop proactive defenses.
  • Create security reference architectures for AI deployments, MCP servers, and agentic AI workflows.
  • Deploy controls for model integrity, governance, and access control across models and feature stores.
  • Build AI-driven cybersecurity tooling for identity, incident management, vulnerability management, third-party risk, and emerging AI threats.
  • Collaborate with engineering and product teams to integrate security into AI development, training, validation, and deployment.
  • Drive SSDLC and DevSecOps practices, including threat modeling, security testing, penetration testing, and CI/CD security automation.
  • Create security guidance, documentation, training, and metrics for engineering and development teams.
  • Research emerging AI security trends and contribute to Tenable’s AI initiatives.

Requirements

  • At least 5 years of professional information security or application security experience, including 1–2 years focused on securing AI/ML systems.
  • Strong coding experience in Python and/or Go.
  • Experience with PyTorch, Hugging Face Transformers, TensorFlow, or similar frameworks and libraries.
  • Experience with TransformerLens, NNsight, Captum, LIT, or similar interpretability and probing tools.
  • Understanding of model internals, residual streams, attention patterns, activation steering, sparse autoencoders, and feature attribution.
  • Strong understanding of AI-specific threats including adversarial ML, data poisoning, prompt injection, model inversion, model evasion, and inference attacks.
  • Understanding of the AI/ML lifecycle and its associated security risks.
  • Knowledge of AWS, Azure, or GCP and AI/ML-related cloud services.
  • Knowledge of data security principles including encryption, masking, and tokenization.
  • Knowledge of SSDLC, DevSecOps, SAST, DAST, SCA, threat modeling, and security testing practices.
  • Knowledge of application security architecture for modern web applications, Docker, and microservices.
  • Ability to work cross-functionally, communicate complex AI security risks clearly, solve problems, and lead projects with end-to-end ownership.
  • Preferred master’s degree in Computer Science, Cybersecurity, Data Science, or a related field.
  • Preferred experience with AI red teaming, adversarial prompt testing, LLM security assessments, AI security frameworks, OWASP LLM Top 10, NIST AI Risk Management Framework, Burp Suite, ZAP, Tenable WAS, AI governance frameworks, cloud security, or large-scale SaaS environments.
  • Security certifications such as CISSP, CSSLP, SANS GIAC, CEH, or AI-focused security certifications are a plus.

Benefits

  • Hybrid work arrangement.
  • Medical, dental, vision, disability, and life insurance.
  • 401(k) retirement savings plan with company match.
  • Employee stock purchase plan and employee referral program.
  • Flexible spending accounts and Employee Assistance Program.
  • Education assistance, parental leave, paid time off, and company-paid holidays.
  • Health and wellness events and community programs.
  • Employees are eligible for variable compensation in addition to base pay.

Tech Stack

AWSAzureDockerGoGoogle Cloud PlatformHugging Face TransformersPythonPyTorchTensorFlow

Categories

Tenable

About Tenable

1,001-5,000 employees

Tenable builds an exposure management and vulnerability detection platform used by enterprises and government agencies to find, prioritize, and remediate cyber risk across IT, cloud, containers, and operational technology. Its portfolio includes Nessus, Tenable.io, and Tenable.sc, delivered primarily via subscriptions and enterprise licenses. Founded in 2002 and headquartered in Columbia, Maryland, Tenable is a public company traded on NASDAQ (TENB).

Contact me