NextRaiseNextRaiseFind jobs
Sign inSign up free
Jobs / Security Engineer in United States of America
10 days ago
Apply with autofill
Apply with autofill
ES
Esswd·10 days ago
10 days ago

Senior Information Security Engineer – AI & Application Security

New York City, United States of AmericaFull-timeHybridMid · 3+ yearsSecurity Engineer

Sign up free to see how well your resume matches this role.

Boost your chances at esswd

How you compare FREE

?
Your scoreYour score: not yet known
→
49
Top 10%Top 10%: 49 out of 100

Top 10% of NextRaise users matched against Security Engineer roles in United States.

Must-have skills for this role

  • application security
  • information security
  • owasp top 10
  • owasp top 10 for llms

PDF or DOCX · no account needed

Apply faster with autofill FREEThe NextRaise extension autofills your application in one click.careers.example.com/applyAutofillingFull namePriya SharmaEmailpriya.sharma@example.comPhone+49 30 1234567LocationBerlGet the extension

What you'll do

  • Owns security assessment of the firm’s AI platforms and AI-enabled tools, including vendor-provided platforms such as Harvey and Microsoft Copilot, applying the OWASP Top 10 for LLMs and the firm’s AI governance framework as the baseline evaluation standard
  • Designs and executes testing for prompt injection, jailbreaking, data leakage, and cross-client isolation in retrieval-augmented and agentic AI platforms, producing evidence that one client’s data cannot influence another client’s outputs in support of the firm’s information barrier and privilege obligations
  • Evaluates and hardens API and integration security across AI platforms, automation tooling, and connected data systems, including authentication and authorization, gateway policies, rate limiting, and anomaly detection for misuse or exfiltration through legitimate channels
  • Conducts ongoing security and configuration assessments of the firm’s Azure, SaaS, and on-premises applications and services to identify misconfigurations, design weaknesses, and development errors
  • Serves as the embedded security partner to the Catalyst Studio and AI and Automation teams, participating in design reviews and ensuring security requirements are defined before build begins
  • Builds and reports metrics on application and AI security posture in business terms relevant to legal operations
  • Special projects and other duties as assigned

What they're looking for

  • Bachelor’s degree in computer science, cybersecurity, or a related field, or equivalent years of experience
  • Eight years or more of relevant experience in application security, secure software development, or information security, including at least three years focused on application security
  • Strong understanding of the OWASP Top 10 and secure coding principles, and demonstrated familiarity with the OWASP Top 10 for LLMs
  • Hands-on experience with application security testing, including threat modeling, secure code review, and static and dynamic testing, and managing findings through remediation
  • Working knowledge of the software development lifecycle and experience embedding security into development and deployment pipelines in cloud or hybrid environments
  • Proficiency in at least one programming or scripting language sufficient to review code and build testing tooling
  • Experience designing or assessing API security controls, including authentication, authorization, and gateway policies
  • Working knowledge of AI and LLM security risks, including prompt injection, data leakage, and cross-tenant isolation in retrieval-augmented architectures
  • Experience assessing third-party and SaaS vendor security architectures
  • Detailed technical knowledge of application, operating system, and network security fundamentals
  • Thorough understanding of current security principles, techniques, and protocols.
  • Ability to effectively communicate information security issues, risks, and recommendations to both technical and non-technical peers and management, including through well-written reports

Summarised by NextRaise from the employer’s description, which follows in full below.

Full description from employer

Faegre Drinker is a firm designed for clients and designed for you. We understand that our people are critical to our success and we are committed to investing in our paraprofessional, administrative and operations professionals. We are always looking for talented, service-focused individuals to join our flexible and high-performing culture. With technology tools and resources that support our hybrid work environment, our colleagues enjoy a culture of learning, support for work and personal goals, opportunities to give back to our communities, and competitive benefits and rewards programs. At Faegre Drinker, you will have the opportunity to share your expertise within and across teams and contribute to our success.

Job Description Summary:

Faegre Drinker has an opportunity for a Senior Information Security Engineer – AI & Application Security to work with our Technology & Innovation team in our Philadelphia, New York City, or Washington, D.C. offices. You will be part of a dynamic team responsible for owning the AI security for the firm and leading the application security function. This position will work with other talented individuals who share a passion for doing great work in the best interest of our clients.

Job Description:

What you would do:

  • Owns security assessment of the firm’s AI platforms and AI-enabled tools, including vendor-provided platforms such as Harvey and Microsoft Copilot, applying the OWASP Top 10 for LLMs and the firm’s AI governance framework as the baseline evaluation standard
  • Designs and executes testing for prompt injection, jailbreaking, data leakage, and cross-client isolation in retrieval-augmented and agentic AI platforms, producing evidence that one client’s data cannot influence another client’s outputs in support of the firm’s information barrier and privilege obligations
  • Evaluates and hardens API and integration security across AI platforms, automation tooling, and connected data systems, including authentication and authorization, gateway policies, rate limiting, and anomaly detection for misuse or exfiltration through legitimate channels
  • Conducts ongoing security and configuration assessments of the firm’s Azure, SaaS, and on-premises applications and services to identify misconfigurations, design weaknesses, and development errors
  • Serves as the embedded security partner to the Catalyst Studio and AI and Automation teams, participating in design reviews and ensuring security requirements are defined before build begins
  • Builds and reports metrics on application and AI security posture in business terms relevant to legal operations
  • Special projects and other duties as assigned

What is expected:

  • Ability to problem-solve
  • Excellent interpersonal, verbal and written communication skills, including the ability to communicate effectively in a virtual environment (e.g., via phone, web/videoconference)
  • Ability to concentrate on tasks, make decisions and work calmly and effectively in a high-pressure, deadline-orientated environment
  • Demonstrated ability to use good judgment in taking initiative while asking for direction or clarification and consulting others, as appropriate
  • Willingness to be flexible with time and adjust to a changing work environment
  • Ability to build and maintain positive relationships, both internally and externally, while maintaining a client service orientation
  • Ability to use sound judgment and discretion in dealing with highly confidential information
  • Ability to take direction and accept supervision
  • Demonstrated ability to work independently, organize and accurately prioritize work, be detail-oriented, understand when urgency is required and use good judgment in varied situations
  • Ability to work effectively with co-workers in a team oriented collaborative environment

What we offer:

  • Flexible working environment for work-life success
  • Opportunity to participate in firm-sponsored volunteer events
  • Wellness programming with personalized content and activities
  • Professional environment and the opportunity to work with experts at the top of their fields
  • Variety of health plan options, as well as dental, vision and 401(k) plans
  • Generous paid time off

The anticipated initial salary for someone who is hired into this position is $160,200 - $183,100.

Actual initial salary may be above or below the above-identified range and will be based on the relevant skills, training, experience, and other job-related factors, including the location where the position is filled, in all cases consistent with applicable law.  This is an exempt role and the initial salary range listed above is just one component of Faegre Drinker's total compensation and benefits package for professional staff, which includes, but is not limited to, a discretionary bonus; life, health, accident, and disability insurance; and a 401(k) plan.

What is required:

  • Bachelor’s degree in computer science, cybersecurity, or a related field, or equivalent years of experience
  • Eight years or more of relevant experience in application security, secure software development, or information security, including at least three years focused on application security
  • Strong understanding of the OWASP Top 10 and secure coding principles, and demonstrated familiarity with the OWASP Top 10 for LLMs
  • Hands-on experience with application security testing, including threat modeling, secure code review, and static and dynamic testing, and managing findings through remediation
  • Working knowledge of the software development lifecycle and experience embedding security into development and deployment pipelines in cloud or hybrid environments
  • Proficiency in at least one programming or scripting language sufficient to review code and build testing tooling
  • Experience designing or assessing API security controls, including authentication, authorization, and gateway policies
  • Working knowledge of AI and LLM security risks, including prompt injection, data leakage, and cross-tenant isolation in retrieval-augmented architectures
  • Experience assessing third-party and SaaS vendor security architectures
  • Detailed technical knowledge of application, operating system, and network security fundamentals
  • Thorough understanding of current security principles, techniques, and protocols.
  • Ability to effectively communicate information security issues, risks, and recommendations to both technical and non-technical peers and management, including through well-written reports

Apply now if you are ready to join the Faegre Drinker team!

Faegre Drinker Biddle & Reath LLP participates in the federal government's E-Verify program. With all new hires, we provide the Social Security Administration and, when applicable, the US Department of Homeland Security with information from each new employee's Form I-9 to confirm work authorization.

Faegre Drinker Biddle & Reath LLP is an Equal Opportunity Employer and is committed to providing equal employment opportunities to all employees and applicants for employment. We do not discriminate on the basis of race, color, religion, age, national origin, disability, sex, sexual orientation, gender, gender identity, gender expression, marital status, veteran or military status, or any other characteristic made unlawful by applicable federal, state or local laws. Equal employment opportunity will be extended to all persons in all aspects of employment, including retirement, hiring, training, promotion, transfer, compensation, benefits, discipline and termination.

Notice to Recruiters and Staffing Agencies: Faegre Drinker Biddle & Reath (and any subsidiary) has an internal recruiting department and does not accept unsolicited resumes.

Company

ES
Esswd
New York City, United States of America

Company facts come from this company's own listings. We only show what the postings themselves carry.

Sourced from Esswd's careers site·first seen 12 Sept 2026·last verified 12 Sept 2026·How we source jobs

Similar jobs

  • Staff Security Engineer at robotsandpencilsUS - Remote–match not yet calculated
  • IT Security Engineer at zollChelmsford, United States of America–match not yet calculated
  • Cybersecurity Summer 2027 Intern (Undergraduate) at centeneRemote-MO–match not yet calculated
  • AI Security Engineer at trimbleUS - Remote, CO–match not yet calculated
  • Medical Device Cybersecurity Co-Op at Johnson & JohnsonDanvers, United States of America–match not yet calculated

Browse more jobs

  • Security Engineer jobs in United States
  • Security Analyst jobs in United States
  • Cloud Security Engineer jobs in United States
  • Penetration Tester jobs in United States
  • Security Engineer jobs in India
  • Security Engineer jobs in United Kingdom