AI Information Security Engineer
Who is Tenable?
Tenable® is the Exposure Management company. Over 40,000 organizations around the globe rely on Tenable to understand and reduce cyber risk. Our global employees support 65 percent of the Fortune 500, 50 percent of the Global 2000, and large government agencies. Come be part of our journey!
What makes Tenable such a great place to work?
Ask a member of our team and they’ll answer, “Our people!” We work together to build and innovate best-in-class cybersecurity solutions for our customers; all while creating a culture of belonging, respect, and excellence where we can be our best selves. When you’re part of our #OneTenable team, you can expect to partner with some of the most talented and passionate people in the industry, and have the support and resources you need to do work that truly matters. We deliver results that exceed expectations and we win together!
Applicants must be authorized to work for any employer in the U.S. without sponsorship. We are unable to provide sponsorship for work visas of any kind at the time of hire, or at any point during employment. This includes, but is not limited to: F1-OPT, F1-CPT, H-1B, TN, J-1, etc
Your Role:
As an AI Security Engineer on Tenable's Information Security team, you will help shape and mature our approach to securing AI both within Tenable's products and across the enterprise. AI introduces a new class of risk at the intersection of application security, cloud risk, and data governance, and you will be on the front lines of defining how we assess, test, and address it.
You will apply hands-on AI engineering experience alongside deep product security and application security skills to design security controls for AI systems, lead assessments, and help engineering teams ship AI features securely. You will establish security standards for responsible AI use, influence decisions across the organization, and build tooling that raises our security posture.
This role is ideal for a practitioner who has spent real time building with AI systems, looking under the hood of model internals, and wants to channel that experience into a security specialty.
Your Opportunity:
- Design, implement, and maintain end-to-end security controls across the AI/ML lifecycle.
- Conduct safety research, inspecting model internals (e.g., detecting hidden deception, latent knowledge, or unwanted concepts across layers) as a core methodology.
- Perform AI safety assessments and threat modeling for AI/ML systems, identifying risks such as data poisoning, model evasion, model extraction, adversarial inputs, and integrity attacks.
- Design and implement robust security guardrails, controls, and boundary mechanisms for Large Language Models (LLMs), Small Language Models (SLMs), and open-source models.
- Act as a subject matter expert in AI safety research by inspecting model internals to detect hidden deception, latent knowledge, or unwanted concepts, ensuring highly transparent and aligned AI outputs.
- Continuously monitor the AI landscape for novel vulnerabilities and attack techniques, applying deep engineering experience to proactively defend enterprise AI deployments.
- Develop security reference architectures for AI deployment patterns, including MCP servers and agentic AI workflows and harnesses.
- Deploy controls to ensure model integrity, governance, and proper access control across models and feature stores.
- Build AI-driven tooling to strengthen cybersecurity posture across identity, incident management, vulnerability management, third-party risk, and emerging AI threat vectors.
- Perform AI safety, security assessments, threat modeling for AI/ML systems, identifying risks such as data poisoning, model evasion, model extraction, adversarial inputs, and integrity attacks.
- Collaborate with software engineers, and product teams to integrate security best practices into AI development, training, validation, and deployment processes.
- Drive Secure Software Development Lifecycle (SSDLC) and DevSecOps practices for AI-powered products, including threat modeling, security testing, penetration testing, and CI/CD pipeline security automation.
- Create security guidance, documentation, and training for internal engineering and development teams; develop metrics that drive desired security behaviors and outcomes.
- Research emerging trends in AI security and contribute to innovative solutions that support Tenable's AI initiatives.
What You'll Need:
- 5 or more years of professional experience in information security or application security, with at least 1–2 years focused on securing AI/ML systems.
- Master’s Degree in Computer Science, Cybersecurity, Data Science, or a related field preferred; advanced degree preferred.
- Deep understanding of AI-specific security threats, including adversarial ML, data poisoning, prompt injection, model inversion, model evasion, and inference attacks.
- Strong coding experience in Python and/or Go.
- Experience with frameworks & libraries such as PyTorch, Hugging Face Transformers, TensorFlow or similar.
- Experience using specialized interpretability and probing tools/libraries such as TransformerLens, NNsight, Captum, or LIT (Learning Interpretability Tool).
- Familiarity with mechanistic & Architectural Concepts: inspecting internal model states, residual streams, attention patterns, activation steering, Sparse Autoencoders (SAEs), or feature attribution.
- Strong understanding of the ML/AI lifecycle and the security risks associated with each stage.
- Knowledge of cloud security platforms: AWS, Azure, or GCP including AI/ML-related services.
- Knowledge of data security principles, including encryption, masking, and tokenization.
- Knowledge of SSDLC, DevSecOps, and security testing practices, including SAST, DAST, SCA, and threat modeling.
- Knowledge of application security architecture best practices and patterns, including modern web applications, Docker, and microservices.
- Ability to work cross-functionally across engineering, product, and business teams.
- Strong written and verbal comAAmunication skills; able to clearly translate complex AI security risks for both technical and non-technical audiences.
- Strong problem-solving skills, attention to detail, and ability to lead projects with end-to-end ownership.
- Self-motivated and effective working independently and across distributed teams.
And Ideally:
- Hands-on experience with AI red teaming, adversarial prompt testing, or LLM security assessments.
- Familiarity of AI security frameworks and standards, including OWASP LLM Top 10 and the NIST AI Risk Management Framework.
- Experience with application security assessment tools (Burp Suite, ZAP, Tenable WAS, etc).
- Familiarity with AI governance frameworks (EU AI Act, NIST AI RMF, etc).
- Background in cloud security or large-scale SaaS product environments.
- Security certifications: CISSP, CSSLP, SANS GIAC, CEH, or AI-focused security certifications are a plus, but not necessary.
#LI-Hybrid
#LI-MS1
This is the base pay range for this position. Compensation for the role will depend on a number of factors, including the candidate's qualifications, skills, competencies, location and experience, and may fall outside of the range shown. Employees are also eligible for variable compensation in addition to base pay (commission for sales roles, bonus for non-sales roles), depending on company and individual performance. Tenable also offers a variety of comprehensive and competitive benefits which include: medical, dental, vision, disability and life insurance; 401(k) retirement savings with company match; an employee stock purchase plan; an employee referral program; flexible spending accounts; an Employee Assistance Program (EAP); education assistance; parental leave; paid time off (PTO); company-paid holidays; health and wellness events; and community programs.
US Pay Range
$122,500 - $163,166.67 USD
We’re committed to promoting Equal Employment Opportunity (EEO) at Tenable - through all equal employment opportunity laws and regulations at the international, federal, state and local levels. If you need a reasonable accommodation due to a disability during the application or recruiting process, please contact Recruiting@Tenable.com for further assistance.
Tenable Data Consent Statement
Tenable is committed to protecting the privacy and security of your personal data. Depending on your location, one or more of the following notices may apply to you:
General Applicant Privacy Notice
California Applicant Privacy Notice
EU/EEA/UK Applicant Privacy Notice
Create a Job Alert
Interested in building your career at Tenable, Inc.? Get future opportunities sent straight to your email.
Apply for this job
*
indicates a required field