
Principal Security AI Engineer
Axis Capital Holdings, Ltd.19 hours ago
Chicago, IL, USA +6 moreStaff+
Base Salary
$90k - $110k/yr
Responsibilities
- Design, develop, deploy, and maintain secure agentic AI capabilities and AI-powered security agents for detection, investigation, and response workflows.
- Identify high-value AI use cases and validate agent accuracy, reliability, explainability, failure modes, hallucination risk, false positives, false negatives, and operational impact.
- Secure enterprise AI platforms including Microsoft Copilot, Copilot Studio, and Azure AI Foundry against data leakage, prompt injection, oversharing, and unauthorized access.
- Deploy, govern, and optimize Microsoft Purview capabilities including DLP, Information Protection, and Insider Risk across Microsoft 365 and AI platforms.
- Define and enforce access controls, data handling policies, auditability, Zero Trust, least privilege, and human-in-the-loop oversight for AI agents and automated workflows.
- Monitor AI platform activity and data usage, detect anomalies and policy violations, and support incident response involving AI systems and data exposure.
- Integrate AI agent workflows with SIEM/XDR platforms for autonomous context enrichment and preliminary incident triage.
- Lead enterprise security architecture, strategy, roadmaps, reference architectures, cross-functional initiatives, and technical escalations.
- Build automation pipelines for detection, response, and data governance workflows using secure APIs and cloud-native services.
- Mentor junior engineers and support enterprise AI governance and data security program rollouts.
Requirements
- Bachelor's degree in Information Technology, Cybersecurity, or a related field, or equivalent experience leading enterprise-scale security engineering initiatives.
- At least five years of progressive experience in cybersecurity, data protection, or security engineering.
- Experience designing and securing enterprise AI platforms, including Microsoft Copilot, Copilot Studio, and Azure AI Foundry.
- Experience with AI governance, data grounding controls, prompt injection protections, AI risk management, and security controls for autonomous or agent-based systems.
- Hands-on expertise with Microsoft Purview, Microsoft 365, Azure, Entra ID, Exchange, SharePoint, and OneDrive, with a focus on data protection and insider risk.
- Proven expertise in DLP strategy and tuning, data classification, sensitivity labeling, lifecycle management, Insider Risk Management, and Information Protection.
- Ability to architect and lead enterprise security solutions, define strategy and roadmaps, drive cross-functional initiatives, and act as a technical authority.
- Proficiency in Python, PowerShell, TypeScript, or similar languages, plus secure API integration, Microsoft Graph, security platform APIs, CI/CD practices, and test automation.
- Experience deploying AI-enabled workflows using Azure Functions, Logic Apps, or comparable cloud-native services.
- Experience with security analytics and telemetry from Microsoft 365, Azure, endpoints, and AI systems, including detection engineering and threat-informed defense.
- Ability to assess risk, prioritize outcomes, make technical decisions in ambiguous environments, and mentor junior engineers.
- Preferred qualifications include prompt engineering or semantic caching experience, OWASP Top 10 for LLMs knowledge, DSPM tool experience, data leakage or insider threat program experience, and relevant cybersecurity certifications.
- Preferred certifications include AI-102, AI-900, SC-400, MS-102, CompTIA Security+, and CompTIA SecAI+.
Benefits
- Base salary is offered in the range of $90K-$110K, with additional competitive target incentive compensation.
- Benefits include medical plans, health and wellness programs, retirement plans, tuition reimbursement, paid vacation, and other benefits.
- The role is an existing vacancy and is exempt for FLSA purposes when based in the United States.
Tech Stack
Categories
About Axis Capital Holdings, Ltd.
AXIS Capital Holdings Limited is a Bermuda-based specialty insurer and reinsurer that underwrites commercial property and casualty lines and reinsurance for businesses and brokers worldwide. Founded in 2001 and headquartered in Pembroke, it is a public company listed on the NYSE (AXS). Its portfolio spans cyber and technology E&O, aviation, marine, political risk and credit, casualty, property, and accident & health, with underwriting platforms in the U.S., London, and Europe.