Senior Security Engineer
Cetera Financial Group
Job Description At Cetera, our Information Security organization protects employees, advisors, and clients from evolving cyber threats across cloud, SaaS, and emerging AI-enabled technologies. As artificial intelligence capabilities expand across the enterprise, Cetera is building a formal AI risk and compliance program - grounded in industry-recognized AI risk management frameworks - to ensure innovation aligns with regulatory, security, and third-party risk expectations. We are seeking an AI Risk and Compliance Engineer to operationalize AI governance controls, manage AI-related third-party and vendor risk, and lead adversarial threat modeling for AI/ML systems using the MITRE ATLAS framework. This role serves as a key bridge across IT Risk, Cloud Security, Legal/Procurement, and AI/ML Engineering teams, translating AI risk management framework requirements into practical, auditable processes within a regulated financial services environment. What will you do: • Operationalize AI governance controls: Implement and maintain controls aligned to recognized AI risk management frameworks (spanning governance, mapping, measurement, and management of AI risk), including control documentation, risk-control matrices (RCM), and evidence collection to support audits and regulatory exams.
• Lead AI third-party risk management: Evaluate and onboard third-party AI/ML tools and vendors against security, privacy, and compliance criteria; document AI-specific vendor and contract requirements, SLAs, and fourth-party disclosures; support due diligence for AI vendors and data provenance reviews.
• Maintain AI/vendor risk inventories: Build and maintain documentation of third-party AI components (models, datasets, APIs, pre-trained/foundation models) covering provenance, functionality, and known limitations, and map internal controls to those components.
• Run ongoing AI risk assessments: Conduct recurring vendor risk and compliance assessments covering AI system performance, data quality, algorithmic bias, and security controls; monitor pre-trained/foundation model drift and SLA adherence; assess concentration and dependency risk across AI vendors.
• Perform AI threat modeling: Design and execute threat models for AI/ML systems using the MITRE ATLAS framework to identify adversarial tactics and techniques - including prompt injection, data/model poisoning, model evasion, model extraction, and supply-chain risk in ML pipelines - across the AI development and deployment lifecycle.
• Coordinate adversarial testing: Plan and coordinate red-teaming, adversarial testing, and penetration testing of AI/ML systems, and drive ongoing threat assessments informed by current threat intelligence and prior incidents.
• Integrate AI into vulnerability management: Ensure AI-specific vulnerabilities and security findings are captured, prioritized, and remediated through existing enterprise vulnerability management processes.
• Identify and assess unsanctioned AI usage: Support discovery and risk assessment of unsanctioned (shadow) AI tool usage across the enterprise and recommend remediation or approval pathways.
• Partner cross-functionally: Work closely with IT Risk, Cloud Security, Legal, Procurement, and Application/AI Engineering teams to embed AI risk and compliance requirements into intake, procurement, and development processes.
• Support governance and audit activities: Develop and maintain AI risk standards, control narratives, and runbooks; support internal and external audits and regulatory compliance activities (e.g., FINRA) by producing control evidence tied to the organization's AI risk management framework. What you will have: • 8-10+ years of experience in IT/cyber risk, GRC, security engineering, or a related discipline, with direct exposure to AI/ML systems
• Working knowledge of AI risk and control frameworks (e.g., NIST AI RMF or similar industry AI risk management frameworks) and OWASP Top 10 for LLMs
• Practical experience with, or strong working knowledge of, threat modeling methodologies for AI/ML systems, including familiarity with MITRE ATT&CK and MITRE ATLAS
• Experience building or operating third-party/vendor risk management processes - due diligence, contracting/SLAs, ongoing monitoring, and issue remediation
• Understanding of AI-specific attack techniques (prompt injection, data/model poisoning, model evasion, model extraction/inversion) and associated mitigations
• Ability to translate technical risk findings into control objectives, policy language, and audit-ready documentation
• Experience in regulated environments (financial services or FINRA preferred)
• Strong communication skills across technical, risk, legal, and compliance stakeholders Preferred Qualifications: • Experience with GRC platforms (e.g., Archer, ServiceNow GRC) for control and risk-register management
• Certifications such as CRISC, CISSP, CCSP, or IAPP AIGP (AI Governance Professional)
• Experience with AWS Bedrock or other cloud AI/ML platforms and cloud-native AI security
• Familiarity with model cards, data lineage/provenance tooling, and AI bill-of-materials (AI-BOM) concepts
• Prior participation in red team, purple team, or adversarial testing exercises involving ML systems
• Exposure to AI governance committees or model risk management (MRM) functions About Us About Us What we give you in return: Not many teams can say that they support people's dreams coming to life. We happen to do that every day. And as important as we know your career is, we recognize that there's a whole lot more to life. To ensure that our employees can make the most of their time outside of working hours, we offer a competitive salary and for full-time roles, a benefits package including:
About Cetera Cetera Financial Group® (Cetera) is a leading network of independent retail broker-dealers and registered investment advisers empowering the delivery of objective financial advice to individuals, families, and company retirement plans across the country through trusted financial advisors and financial institutions. Cetera is one of the largest independent financial advisor networks in the nation and a leading provider of retail services to the investment programs of banks and credit unions. Advisor support resources offered through Cetera include award-winning wealth management and advisory platforms, comprehensive broker-dealer and registered investment adviser services, practice management support, and innovative technology. Cetera Financial Group (Cetera) is a network of independent retail firms, including those that are members of FINRA/SIPC: Cetera Advisors LLC; Cetera Wealth Services, LLC (formerly known as Cetera Advisor Networks); Cetera Investment Services LLC (marketed as Cetera Financial Institutions or Cetera Investors); and Cetera Financial Specialists LLC. Entities registered as investment advisers with the Securities and Exchange Commission include Cetera Investment Management LLC and Cetera Investment Advisers LLC. Cetera's principal office is located at 655 W. Broadway, 11th Floor, San Diego, CA 92101. Avantax Planning Partners, Inc. is an SEC registered investment adviser within the Aretec Group, Inc. (dba Cetera Holdings, an affiliate of Cetera). All the referenced entities are under common ownership. Cetera Financial Group is committed to providing an equal employment opportunity for all applicants and employees. For us, this is the only acceptable way to do business. Accordingly, all employment decisions at Cetera Financial Group, including those relating to hiring, promotion, transfers, benefits, compensation, and placement, will be made without regard to race, color, ancestry, national origin, citizenship, age, physical and/or mental disability, medical condition, pregnancy, genetic characteristics, religion, religious dress and/or grooming, gender, gender identity, gender expression, sexual orientation, marital status, U.S. military status, political affiliation, or any other class protected by state and/or federal law. Agencies please note : this recruitment assignment is being managed directly by Cetera's Talent Acquisition team. We will reach out to our preferred agency partners in the rare instance we require additional talent options. Your respect for this process is appreciated. Please review our Workforce Privacy Policy for further details on what information we collect and the purposes for collection.
• Lead AI third-party risk management: Evaluate and onboard third-party AI/ML tools and vendors against security, privacy, and compliance criteria; document AI-specific vendor and contract requirements, SLAs, and fourth-party disclosures; support due diligence for AI vendors and data provenance reviews.
• Maintain AI/vendor risk inventories: Build and maintain documentation of third-party AI components (models, datasets, APIs, pre-trained/foundation models) covering provenance, functionality, and known limitations, and map internal controls to those components.
• Run ongoing AI risk assessments: Conduct recurring vendor risk and compliance assessments covering AI system performance, data quality, algorithmic bias, and security controls; monitor pre-trained/foundation model drift and SLA adherence; assess concentration and dependency risk across AI vendors.
• Perform AI threat modeling: Design and execute threat models for AI/ML systems using the MITRE ATLAS framework to identify adversarial tactics and techniques - including prompt injection, data/model poisoning, model evasion, model extraction, and supply-chain risk in ML pipelines - across the AI development and deployment lifecycle.
• Coordinate adversarial testing: Plan and coordinate red-teaming, adversarial testing, and penetration testing of AI/ML systems, and drive ongoing threat assessments informed by current threat intelligence and prior incidents.
• Integrate AI into vulnerability management: Ensure AI-specific vulnerabilities and security findings are captured, prioritized, and remediated through existing enterprise vulnerability management processes.
• Identify and assess unsanctioned AI usage: Support discovery and risk assessment of unsanctioned (shadow) AI tool usage across the enterprise and recommend remediation or approval pathways.
• Partner cross-functionally: Work closely with IT Risk, Cloud Security, Legal, Procurement, and Application/AI Engineering teams to embed AI risk and compliance requirements into intake, procurement, and development processes.
• Support governance and audit activities: Develop and maintain AI risk standards, control narratives, and runbooks; support internal and external audits and regulatory compliance activities (e.g., FINRA) by producing control evidence tied to the organization's AI risk management framework. What you will have: • 8-10+ years of experience in IT/cyber risk, GRC, security engineering, or a related discipline, with direct exposure to AI/ML systems
• Working knowledge of AI risk and control frameworks (e.g., NIST AI RMF or similar industry AI risk management frameworks) and OWASP Top 10 for LLMs
• Practical experience with, or strong working knowledge of, threat modeling methodologies for AI/ML systems, including familiarity with MITRE ATT&CK and MITRE ATLAS
• Experience building or operating third-party/vendor risk management processes - due diligence, contracting/SLAs, ongoing monitoring, and issue remediation
• Understanding of AI-specific attack techniques (prompt injection, data/model poisoning, model evasion, model extraction/inversion) and associated mitigations
• Ability to translate technical risk findings into control objectives, policy language, and audit-ready documentation
• Experience in regulated environments (financial services or FINRA preferred)
• Strong communication skills across technical, risk, legal, and compliance stakeholders Preferred Qualifications: • Experience with GRC platforms (e.g., Archer, ServiceNow GRC) for control and risk-register management
• Certifications such as CRISC, CISSP, CCSP, or IAPP AIGP (AI Governance Professional)
• Experience with AWS Bedrock or other cloud AI/ML platforms and cloud-native AI security
• Familiarity with model cards, data lineage/provenance tooling, and AI bill-of-materials (AI-BOM) concepts
• Prior participation in red team, purple team, or adversarial testing exercises involving ML systems
• Exposure to AI governance committees or model risk management (MRM) functions About Us About Us What we give you in return: Not many teams can say that they support people's dreams coming to life. We happen to do that every day. And as important as we know your career is, we recognize that there's a whole lot more to life. To ensure that our employees can make the most of their time outside of working hours, we offer a competitive salary and for full-time roles, a benefits package including:
- Inclusive health, dental, vision, and life insurance plans built to support diverse lifestyles, offer preventative care, and protect against hardship.
- Easy access to mental health benefits to meet our team members and their families where they are.
- 20+ days of paid time off (PTO), paid holidays, and 2 paid wellness days to give our employees the time they need to stay close with their loved ones, recharge, and give back to their communities.
- 401(k) savings plan with a generous company contribution (up to 5%), and access to a financial professional to offer our employees the opportunity to plan-ahead for a strong financial future well beyond their working years.
- Paid parental leave to support all team members with birth, adoption, and fostering.
- Health Savings and Flexible Spending Account options to help you save money on healthcare, daycare, commuting, and more.
- Employee Assistance Program (EAP), LifeLock, Pet Insurance and more.
- Paid caregiver leave to provide time away from work when caring for an ill or recovering family member.
- Additional benefits such as an Employee Assistance Program (EAP), identity theft protection (LifeLock), pet insurance, and other voluntary benefits to provide extra peace of mind
About Cetera Cetera Financial Group® (Cetera) is a leading network of independent retail broker-dealers and registered investment advisers empowering the delivery of objective financial advice to individuals, families, and company retirement plans across the country through trusted financial advisors and financial institutions. Cetera is one of the largest independent financial advisor networks in the nation and a leading provider of retail services to the investment programs of banks and credit unions. Advisor support resources offered through Cetera include award-winning wealth management and advisory platforms, comprehensive broker-dealer and registered investment adviser services, practice management support, and innovative technology. Cetera Financial Group (Cetera) is a network of independent retail firms, including those that are members of FINRA/SIPC: Cetera Advisors LLC; Cetera Wealth Services, LLC (formerly known as Cetera Advisor Networks); Cetera Investment Services LLC (marketed as Cetera Financial Institutions or Cetera Investors); and Cetera Financial Specialists LLC. Entities registered as investment advisers with the Securities and Exchange Commission include Cetera Investment Management LLC and Cetera Investment Advisers LLC. Cetera's principal office is located at 655 W. Broadway, 11th Floor, San Diego, CA 92101. Avantax Planning Partners, Inc. is an SEC registered investment adviser within the Aretec Group, Inc. (dba Cetera Holdings, an affiliate of Cetera). All the referenced entities are under common ownership. Cetera Financial Group is committed to providing an equal employment opportunity for all applicants and employees. For us, this is the only acceptable way to do business. Accordingly, all employment decisions at Cetera Financial Group, including those relating to hiring, promotion, transfers, benefits, compensation, and placement, will be made without regard to race, color, ancestry, national origin, citizenship, age, physical and/or mental disability, medical condition, pregnancy, genetic characteristics, religion, religious dress and/or grooming, gender, gender identity, gender expression, sexual orientation, marital status, U.S. military status, political affiliation, or any other class protected by state and/or federal law. Agencies please note : this recruitment assignment is being managed directly by Cetera's Talent Acquisition team. We will reach out to our preferred agency partners in the rare instance we require additional talent options. Your respect for this process is appreciated. Please review our Workforce Privacy Policy for further details on what information we collect and the purposes for collection.
Vacancy posted 12 hours ago
Similar jobs that could be interesting for youBased on the Senior Security Engineer in Dallas, TX vacancy
$115k - $160k
...and a commitment to absolute integrity. East West Bank gives people the confidence to reach further. Overview The Cyber Security Engineer supports the development and maintenance of a corporate-wide information security program to help protect the organization’s...SeniorFull time$112k - $209k
...and your search for important and impactful work lead to the same place.The global law firm of K&L Gates LLP is seeking a Senior Security Engineer to join the firm. The Senior Security Engineer develops, automates, and enhances security capabilities for cloud, on-premises...SeniorFull timeTemporary workWork experience placementLocal areaRemote work$148.5k - $260.1k
...! Agentforce is the future of AI, and you are the future of Salesforce.The ExperienceSalesforce Enterprise Security is hiring a Senior and Lead Security Engineer for our Secure AI team to help assess and maintain the security of using AI tooling securely.In this role,...SeniorFull time$131k - $169k
...Senior Security Engineer Seeking a development & cloud focused Senior Security Engineer to join our expanding security team. The ideal candidate will have passion for AppSec, Cloud and AI. They will be a skilled communicator and relationship builder capable of promoting...SeniorWork at officeWork from homeFlexible hoursDay shift- ...Job Title Under general direction of IT Network Team Leader or the Sr. Security Engineering Manager, works closely with the other members of the team to execute and manage a comprehensive information security program. This includes the tactical management and configuration...SeniorWork at office
- ...Job Description Job Description Global Software Firm seeks a Sr Network Security Engineer. We're looking for an engineer with strong Palo Alto, F5, and WAF experience. Experience in threat hunting and pen testing would be a plus. This is a permanent direct...SeniorPermanent employmentRemote work
- ...Job Description Job Description Senior Network Security Engineer Location: Dallas, TX (Hybrid – Uptown) Type: Direct Hire • Base salary + performance bonus • 100% company-paid benefits Overview This organization operates at the forefront of high-performance...Senior
- ...Job Description Job Description Job Title: Senior Security Engineer Duration : Full Time Location : Cleveland, OH, Pittsburgh, PA, or Dallas, TX. Work Mode : 5 Days Onsite Years Of Exp : 8+ Yrs Future duties and responsibilities Vulnerability Triage...SeniorFull timeImmediate start
$136k - $204k
...purpose, and a team that welcomes you—because when you feel valued, you’re empowered to do your best work.Job Summary:The Identity Security Engineer, Identity platform (Ping) at Equinix is responsible for designing, implementing, and supporting authentication, authorization,...SeniorFull timeWork at office$136k - $204k
...because when you feel valued, you’re empowered to do your best work.Job SummaryWe are seeking a SailPoint IdentityNow Engineer to join the Identity Security team. This role will lead the design, implementation, and operation of modern Identity Governance (IGA) solutions,...SeniorFull timeWork at office$105.4k - $207.8k
Position Summary Cisco Network Security Engineer/ Senior Consultant, Strategy, Growth, and TransformationDeloitte’s Cyber business is passionate about making an impact with lasting change. Delivering our industry leading services requires fresh thinking and a creative...SeniorWork experience placementLocal areaVisa sponsorship- ...a crucial role in monitoring and analyzing our organization's security infrastructure, detecting and responding to potential threats... ...Collaborate closely with internal technology teams-including Cloud Engineering, Network Security, IAM, DevOps, and Governance/Risk/Compliance...SeniorFull timeWork at officeFlexible hours
$116.1k - $158.2k
...subscription design, governance, and onboarding standardsEstablish engineering standards for identity, networking, monitoring, resiliency,... ...with architecture, infrastructure, networking, and security teams to deliver scalable cloud solutionsEnable and integrate...SeniorFull timeContract workLocal areaFlexible hours- Senior Security Operations Center Engineer Contract Job Title: Senior Security Operations Center Engineer Client: Telecommunication Location: Dallas, TX, USA Rate: Market Rate Job Scope: Manages / administers the company's day-to-day information security infrastructure...SeniorContract work
$77k - $202k
...ApplicableSpecialismCybersecurity & PrivacyManagement LevelSenior AssociateJob Description & SummaryThe OpportunityAs a Security Risk & Engineering - Tech and Cyber Risk & Compliance - Senior Associate, you will focus on maintaining regulatory compliance and managing risks for clients,...SeniorFull timeH1b- ...Business Continuity & Disaster Recovery• Security & PrivacySpecialties• Contract Staffing... ...operational support for customers. The Security Engineer also plays a key role in the daily... ...TechnologyExperience level: Mid-Senior LevelIndustry: Staffing And RecruitingSeniorPermanent employmentContract workFor contractorsH1bRemote work
- ...inspiration and expand your capabilities, then consider a career in Advisory.KPMG is currently seeking a Senior Associate, SailPoint Identity Security Cloud Engineer to join our Advisory Technology Organization.Responsibilities:Support SailPoint Identity Security Cloud...SeniorH1bLocal area
- ...Basic Function HF Sinclair is seeking a Senior Data Security Engineer in Dallas, Texas. Serves as the technical authority responsible for defining and operationalizing the enterprise data security execution model. This role is accountable for translating data security...SeniorWork at office
$174k - $252k
Conduct security assessments of Cloud security and vulnerability reports to assess risk and impact and ensure prompt and proper mitigations... ...with stakeholders across Google, including legal, engineering, and communications teams.Investigate impact to Google Cloud and...Senior- LTIMindtree in the United States seeks an Application Security Engineer for a hybrid Fort Worth, TX role with in-person interviews for shortlisted candidates. You will design and implement cloud security solutions, oversee the SOC, and align cybersecurity initiatives with...Senior
- Digipulse Technologies, Inc. invites a senior IT infrastructure expert with 10+ years in IT infrastructure, security and architecture to join our team. The role emphasizes operations and problem solving, with hands-on work in virtual networks and security constructs for...Senior
- ...Role - Senior AWS Cloud, DevOps & Security Engineer Contract Dallas, TX Role Summary The engineer will design, build, secure, automate, operate, and support AWS environments for the HMS Modernization and Teradata Migration programs. This is a broad...SeniorContract work
$155k - $200k
...You will ensure our enterprise network is secure, running, and optimized. Linux Network... ...logo and follow our LinkedIn page! Seniority level Seniority level Not Applicable Employment... ...about new Senior Network Security Engineer jobs in Dallas, TX . Mesquite, TX $155,0...SeniorFull timeLocal areaRemote work$105.4k - $207.8k
Position Summary Cyber Palo Alto Networks Security Engineer/ Senior Consultant, Strategy, Growth, and TransformationDeloitte’s Cyber business is passionate about making an impact with lasting change. Delivering our industry leading services requires fresh thinking...SeniorWork experience placementLocal areaRemote work$134.5k - $265.1k
...confidence, and proactively manage their security posture.Recruiting for this role ends on... ...you will do:As a Cyber Forward Deployed Engineer (FDE) Sr Consultant, you will drive... ...goals.5+ Years experience working with senior client stakeholders to translate requirements...SeniorLocal areaVisa sponsorship$134.5k - $265.1k
...Join Deloitte’s Cloud Cyber Risk practice as a Forward Deployed Security Engineer and help organizations secure their Amazon Web Services (AWS)... ...Professional development From entry-level employees to senior leaders, we believe there’s always room to learn. We offer opportunities...SeniorVisa sponsorship- o9 Solutions is seeking a Senior AI Security & MLSecOps Architect to own the security architecture for its GenAI platform. You will design agent identity controls, SBOM pipelines, and RAG security, while aligning with ISO/NIST/OWASP standards across the enterprise. You...Senior
- HF Sinclair is seeking an IT Security Architect to define and govern enterprise cybersecurity architecture standards across IT and OT. You will drive secure-by-design decisions, lead architecture reviews, and map risk to capabilities while guiding multiple teams and stakeholders...SeniorWork at office
- ...Senior Network Engineer (Fortinet / Cisco) DETAILS Location : Irving, TX 75039 (hybrid 4days [M-TH] per week onsite) Position Type :... ...standardization, and migration activities across network and security environments. The Senior Network Engineer (Fortinet /...SeniorHourly payWork at officeLocal area
$130k - $150k
Dallas, TexasOpen to RemoteFull Time$130k - $150k A cybersecurity consulting company is looking for a Mid to Senior Network Penetration Tester who has extensive experience with manual network pentesting experience and NSA/nation state. This is a high performing, collaborative...SeniorRemote work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior Security Engineer. Be the first to apply!
Related searches
- security infrastructure engineer Dallas, TX
- sr information security engineer Dallas, TX
- senior cloud security engineer Dallas, TX
- entry level security engineer Dallas, TX
- security engineer Dallas, TX
- senior security operations engineer Dallas, TX
- information technology security engineer Dallas, TX
- application security engineer Dallas, TX
- network security engineer Dallas, TX
- security engineering manager Dallas, TX



