
AI Application Security Architect
ACV Auctions26 days ago
Buffalo, NY, USAStaff+
Responsibilities
- Define target-state secure architecture and reference patterns for AI/ML systems, LLM features, retrieval pipelines, agentic workflows, and computer vision models.
- Protect vision-based vehicle condition and pricing pipelines from adversarial inputs, manipulated imagery, and AI-generated imagery.
- Establish secure-by-default standards for prompt injection defense, output handling, agent and tool permissions, and model and training-data supply chains.
- Threat model and review high-risk AI and application designs using MITRE ATLAS and OWASP Top 10 frameworks.
- Own security architecture for AI-assisted engineering, including coding assistants, MCP servers, and autonomous agents.
- Build AI security testing capabilities covering adversarial testing, red-teaming, evaluation harnesses, and runtime guardrails.
- Advise leadership on multi-year AI security strategy and translate AI governance policy into technical controls.
- Scale AI security expertise through the Security Champions program, mentor Staff and Principal engineers, and represent ACV’s AI security architecture externally.
Requirements
- Bachelor’s degree in a related field or commensurate experience.
- 12+ years of security experience with a degree, or 15+ years without a degree, including deep application security architecture.
- Hands-on GenAI/LLM security experience demonstrated through production work, red-team engagements, research, tooling, open-source contributions, or AI security competition results.
- At least 2 years of production AI security experience preferred.
- Deep knowledge of LLM application threats and model-level threats including prompt injection, data leakage, excessive agency, poisoning, evasion, extraction, and malicious pre-trained models.
- Ability to read and write code, with Python preferred, and hands-on experience using AI security tooling.
- Working fluency with OWASP Top 10 for LLM Applications, OWASP Top 10 for Agentic Applications, MITRE ATLAS, and NIST AI RMF.
- Experience defining secure reference architectures and paved-road standards, including for AI-assisted development.
- Application security experience with secure code review, threat modeling, and SAST/DAST/SCA tooling.
- Cloud security experience with AWS, Kubernetes, infrastructure-as-code, and familiarity with ML platforms and inference infrastructure preferred.
- Strong written and verbal communication and the ability to align engineering and ML leadership.
- SABSA or equivalent architecture credentials, CCSP, cloud security specialization, or demonstrated AI security work are preferred but not required.
Benefits
- Multiple medical plans, including a high-deductible low-cost health plan.
- Company-sponsored short-term disability, long-term disability, and life insurance.
- Optional dental, vision, supplemental life/AD&D, legal/ID protection, accident, and critical illness insurance.
- Uncapped vacation days, paid sick leave, company holidays, floating holidays, parental leave, bereavement leave, jury duty leave, voting leave, and other legally required paid leave.
- Employee Stock Purchase Program and additional opportunities to earn company stock.
- 401(k) retirement planning.