Jobs and Careers
NE

Senior Associate - AI AppSec Engineer

New York Life Insurance Co
New York City, United Statesfull_timeVerifiedPosted 14 Aug 2026
💰 $177,000/yr($124,000/yr$177,000/yr)

About the role

 

Location Designation: Hybrid - 3 days per week 

 

 

Business Unit

Technology, Data, AI and Ventures (TDAV)

Business Unit Overview

Within the Tech, Data, AI, Ventures (TDAV) organization, our work is guided by a shared vision: deploying the power of technology, data, AI and ventures to accelerate sustainable competitive advantage for New York Life's businesses. We build solutions that power how we serve policy owners, agents, advisors and employees while delivering measurable business outcomes.

Across technology, data, AI, cyber, product, digital experience, architecture and infrastructure, TDAV combines the scale and investment of an industry leader, access to leading-edge technologies and the opportunity to help shape how a world-class financial services company competes in the AI era — all backed by the stability and purpose of a mutual company built to last.

Role Overview

New York Life is moving from AI experimentation into production, agentic, and automated decisioning systems. As an AI Application Security Engineer, you will help ensure these systems are built and operated securely by embedding application security controls, guardrails, and secure-by-default practices throughout the AI development lifecycle.

As part of the Application Security team, you will work hands-on to secure AI applications, agentic systems, and supporting AI platform services across development and production environments. Leveraging Google Cloud Vertex AI as the enterprise AI platform, you will partner closely with AI engineers, data scientists, MLOps platform teams, and Model Risk Management to integrate AI security into application development, CI/CD pipelines, infrastructure-as-code workflows, and cloud platforms. This individual contributor role requires strong technical expertise, collaborative problem solving, and a passion for building scalable security capabilities that enable innovation while reducing risk.

What You'll Do

  • Design and implement application security controls for AI applications, agentic systems, and tool-invoking workflows, ensuring secure-by-default patterns are embedded throughout the software development lifecycle.

  • Build and operationalize security guardrails that protect against emerging AI threats, including prompt injection, indirect prompt injection, unsafe tool invocation, data exfiltration, model abuse, and other evolving attack techniques.

  • Integrate AI security controls into existing application security, CI/CD, SSDLC, and infrastructure-as-code processes while helping secure AI platform workflows across data ingestion, model training, deployment, serving, and runtime execution with a primary focus on Google Cloud Vertex AI.

  • Partner with MLOps platform teams, AI engineers, data scientists, cloud engineering, and Model Risk Management to review identity architectures, automate security controls, remediate findings, and establish reusable security standards across enterprise AI initiatives.

  • Develop Python-based automation, security tooling, detection capabilities, and technical guidance that improve the organization's ability to securely deploy, monitor, and scale AI solutions in production.

What You'll Bring

Required Skills

  • Bachelor's degree in Computer Science, Engineering, or a related discipline (or equivalent practical experience) with 5+ years of experience in application security, cloud security, security engineering, or a closely related field.

  • Hands-on experience securing production AI platforms, with experience in Google Cloud Vertex AI preferred; comparable experience with Amazon SageMaker or Azure Machine Learning will also be considered.

  • Strong understanding of AI application and model lifecycles, including data ingestion, training, model registry, deployment, online and offline serving, and secure environment separation across development, training, staging, and production.

  • Experience implementing security controls within CI/CD pipelines and infrastructure-as-code environments, along with knowledge of cloud IAM, least-privilege principles, service accounts, workload identity, and non-human identity management.

  • Knowledge of modern application security practices including authentication and authorization, secure API design, software supply chain security (SLSA, SBOMs, signed artifacts), secrets management, and AI-specific threat models.

  • Proficiency

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

New York Life Insurance Co

View company profile →