Lead Information Security Engineer
Berwyn, United States · Hybrid · Full-time
- Posted 1mo ago
- From Envestnet’s careers page
- Location
- Berwyn, United States
- Work mode
- Hybrid
- Type
- Full-time
- Level
- Lead
- Department
- Engineering
Opens the listing on careers.envestnet.com
Let the right jobs find you
In your inbox every Wednesday and SaturdayPersonalised suggestions from verified career pages, matched to your role, location, level and skills.
About the role
Continuously assesses the organization’s security landscape, utilizing cutting-edge automation and offensive security techniques to validate controls and uncover potential areas of risk. Utilizes architecture and engineering insights into major cloud and on-premise workloads to integrate continuous monitoring, automated validation and offensive security into a cohesive strategy and strengthen the overall security posture. Works cross-organizationally to ensure that security controls are effective, risks are understood and mitigations properly addressed and validated.
- Provides Information Security Engineering support for broad areas of the company.
- Develops and executes security controls and reports, defenses and countermeasures to detect, analyze, investigate and respond to internal or external attacks and infiltration attempts.
- Leads or provides direction for Information Security Engineering projects.
- Provides complex analysis of potential risks to information systems security and recommends innovative solutions.
- Recommends and implements changes to procedures and systems to enhance information systems security.
- Integrates network security controls into an environment to identify risks and reduce their impact.
- Provides guidance and advice to less experienced team members.
- Secure AI platforms, agents, MCP integrations, plugins, toolchains, and agent-to-agent workflows through architecture reviews, risk assessments, and control validation.
- Implement and enhance AI security controls, including data protection, model governance, source code safeguards, and AI-specific risk mitigation capabilities.
- Develop and maintain AI security monitoring, detection, investigation, and incident response capabilities to identify and respond to threats across AI environments.
- Conduct and participate in adversarial testing, threat assessments, and red/purple team exercises involving AI systems, while evaluating emerging AI technologies, attack techniques, and security risks to enable secure adoption.
What You’ll Need to Bring
- Candidates should demonstrate the relevant experience, skills, and capabilities needed to successfully perform in the role. Relevant experience may be gained through current responsibilities, prior roles, project work, leadership opportunities, or other comparable experiences.
- Progressive experience in security engineering, security architecture, cloud security, application security, or identity/security platform engineering in enterprise cybersecurity roles.
- Hands-on experience securing AI/ML systems, AI-enabled applications, and agentic ecosystems — including AI governance, agent frameworks, RAG architectures, and LLM integrations — with experience leading the security architecture, implementation, and assessment of AI platforms such as AWS Bedrock, Claude, Microsoft Copilot, GitHub Copilot, Kiro, and MCP integrations. Broad familiarity with the evolving agentic landscape, including plugins, skills, routines, desktop integrations, agent marketplaces, tool-invocation frameworks, and orchestration platforms.
- Demonstrated experience securing and assessing authentication, authorization, and trust models across complex enterprise and AI environments, including delegated access, workload identities, service principals/accounts, API keys, OAuth/OIDC flows, token delegation, agent impersonation, consent models, permissions, delegated workflows, data access controls, autonomous actions, and cross-system trust relationships.
- AI-specific threat knowledge — experience identifying and mitigating AI-specific attack vectors: prompt injection, jailbreaking, model/data exfiltration, data poisoning, and insecure output handling in LLM-integrated systems.
- Securing AI-assisted development and product-line AI implementation — experience assessing risks AI tools and AI-driven features introduce across the software lifecycle, from code generation to production deployment.
- Strong analytical, troubleshooting, and problem-solving skills, with the ability to assess complex security risks and communicate recommendations to technical and business stakeholders.
Skills they ask for
Pick one to see other roles that ask for it.
About Envestnet
Wealth technology for financial advisorsEnvestnet provides wealth management technology and services that help financial advisors support clients and manage investments.
See all 44 roles at EnvestnetMore roles at Envestnet
See all 44- Associate Solutions ArchitectThiruvananthapuram · Entry Level · HybridInformation Technology · Entry Level · HybridThiruvananthapuram, India2w
- Lead Software Development EngineerThiruvananthapuram · Lead · HybridSoftware Development · Lead · HybridThiruvananthapuram, India2w
- Senior Data Intelligence AdvisorThiruvananthapuram · Senior · HybridData and Analytics · Senior · HybridThiruvananthapuram, India2w
- Client Service AssociateRaleigh · HybridCustomer Service · HybridRaleigh, United States2w
Let the right jobs find you
In your inbox every Wednesday and SaturdayPersonalised suggestions from verified career pages, matched to your role, location, level and skills.