Logo for Cetera Financial Group

Principle Security Engineer

Role overview

Qualifications

  • 10+ years of experience in IT/cyber risk, GRC, security engineering, or a related discipline with direct exposure to AI/ML systems
  • Working knowledge of AI risk and control frameworks (e.g., NIST AI RMF)
  • Practical experience with threat modeling methodologies for AI/ML systems
  • Experience in regulated environments (financial services or FINRA preferred)

Responsibilities

  • Operationalize AI governance controls and maintain documentation
  • Lead AI third-party risk management including vendor evaluations
  • Run ongoing AI risk assessments for AI system performance and security
  • Perform AI threat modeling using the MITRE ATLAS framework

Key facts

Hard skills

Other skills

  • Communication
  • Collaboration

About the company

Cetera Financial Group logo

Cetera Financial Group

Financial Services

An at-scale wealth hub, Cetera Financial Group® (Cetera) offers financial professionals and institutions the latest solutions, support, and services. Breaking away from a commoditized and homogenous IBD model, Cetera instead creatively addresses advisors' and institutions' unique needs, whether they are seeking to grow, scale, or transition with a merger, sale, investment, or succession plan. Cetera proudly serves independent financial advisors, tax professionals, licensed administrators, large enterprises, as well as institutions, such as banks and credit unions, providing an established and repeatable blueprint for scalable growth. Cetera's approach empowers advisors to affiliate in whichever way they deem most appropriate. During the professional life cycle of their practice, the Cetera wealth hub helps to ensure each advisor's affiliation model identifies and ignites growth levers in a way that helps increase the value of their practice, people, and legacy. Cetera delivers holistic, unbiased financial planning and advice to Main Street investors, helping them achieve their version of financial wellbeing at all life stages. For financial professionals, Cetera provides growth and succession resources, an enhanced advisor tech stack and importantly, an experience where financial professionals don't feel like a number, but an integral part of Cetera's rich and thriving ecosystem. Home to more than 8,000 financial professionals and their teams, Cetera oversees approximately $322 billion in assets under administration and $115 billion in assets under management, as of December 31, 2022. In a recent advisor satisfaction survey of more than 14,000 reviews, Cetera's Voice of Customer (VoC) program vigorously measures advisor experience and satisfaction 24/7. Currently, it's ranked 4.7 out of 5 stars.

Company details

Company typeLarge
IndustryFinancial Services
Company size1001 - 5000

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

At Cetera, our Information Security organization protects employees, advisors, and clients from evolving cyber threats across cloud, SaaS, and emerging AI-enabled technologies. As artificial intelligence capabilities expand across the enterprise, Cetera is building a formal AI risk and compliance program — grounded in industry-recognized AI risk management frameworks — to ensure innovation aligns with regulatory, security, and third-party risk expectations. 
We are seeking an AI Risk and Compliance Engineer to operationalize AI governance controls, manage AI-related third-party and vendor risk, and lead adversarial threat modeling for AI/ML systems using the MITRE ATLAS framework. This role serves as a key bridge across IT Risk, Cloud Security, Legal/Procurement, and AI/ML Engineering teams, translating AI risk management framework requirements into practical, auditable processes within a regulated financial services environment. 
 

What will you do: 
•    Operationalize AI governance controls: Implement and maintain controls aligned to recognized AI risk management frameworks (spanning governance, mapping, measurement, and management of AI risk), including control documentation, risk-control matrices (RCM), and evidence collection to support audits and regulatory exams. 
•    Lead AI third-party risk management: Evaluate and onboard third-party AI/ML tools and vendors against security, privacy, and compliance criteria; document AI-specific vendor and contract requirements, SLAs, and fourth-party disclosures; support due diligence for AI vendors and data provenance reviews. 
•    Maintain AI/vendor risk inventories: Build and maintain documentation of third-party AI components (models, datasets, APIs, pre-trained/foundation models) covering provenance, functionality, and known limitations, and map internal controls to those components. 
•    Run ongoing AI risk assessments: Conduct recurring vendor risk and compliance assessments covering AI system performance, data quality, algorithmic bias, and security controls; monitor pre-trained/foundation model drift and SLA adherence; assess concentration and dependency risk across AI vendors. 
•    Perform AI threat modeling: Design and execute threat models for AI/ML systems using the MITRE ATLAS framework to identify adversarial tactics and techniques — including prompt injection, data/model poisoning, model evasion, model extraction, and supply-chain risk in ML pipelines — across the AI development and deployment lifecycle. 
•    Coordinate adversarial testing: Plan and coordinate red-teaming, adversarial testing, and penetration testing of AI/ML systems, and drive ongoing threat assessments informed by current threat intelligence and prior incidents. 
•    Integrate AI into vulnerability management: Ensure AI-specific vulnerabilities and security findings are captured, prioritized, and remediated through existing enterprise vulnerability management processes. 
•    Identify and assess unsanctioned AI usage: Support discovery and risk assessment of unsanctioned (shadow) AI tool usage across the enterprise and recommend remediation or approval pathways. 
•    Partner cross-functionally: Work closely with IT Risk, Cloud Security, Legal, Procurement, and Application/AI Engineering teams to embed AI risk and compliance requirements into intake, procurement, and development processes. 
•    Support governance and audit activities: Develop and maintain AI risk standards, control narratives, and runbooks; support internal and external audits and regulatory compliance activities (e.g., FINRA) by producing control evidence tied to the organization's AI risk management framework. 
 

What you will have: 
•    10+ years of experience in IT/cyber risk, GRC, security engineering, or a related discipline, with direct exposure to AI/ML systems 
•    Working knowledge of AI risk and control frameworks (e.g., NIST AI RMF or similar industry AI risk management frameworks) and OWASP Top 10 for LLMs 
•    Practical experience with, or strong working knowledge of, threat modeling methodologies for AI/ML systems, including familiarity with MITRE ATT&CK and MITRE ATLAS 
•    Experience building or operating third-party/vendor risk management processes — due diligence, contracting/SLAs, ongoing monitoring, and issue remediation 
•    Understanding of AI-specific attack techniques (prompt injection, data/model poisoning, model evasion, model extraction/inversion) and associated mitigations 
•    Ability to translate technical risk findings into control objectives, policy language, and audit-ready documentation 
•    Experience in regulated environments (financial services or FINRA preferred) 
•    Strong communication skills across technical, risk, legal, and compliance stakeholders 
 

Preferred Qualifications: 
•    Experience with GRC platforms (e.g., Archer, ServiceNow GRC) for control and risk-register management 
•    Certifications such as CRISC, CISSP, CCSP, or IAPP AIGP (AI Governance Professional) 
•    Experience with AWS Bedrock or other cloud AI/ML platforms and cloud-native AI security 
•    Familiarity with model cards, data lineage/provenance tooling, and AI bill-of-materials (AI-BOM) concepts 
•    Prior participation in red team, purple team, or adversarial testing exercises involving ML systems 
•    Exposure to AI governance committees or model risk management (MRM) functions 
 

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Security Engineer Related jobs

Other jobs at Cetera Financial Group

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.