ForgeApply · Job listing
Associate Director, AI & Application Security - HYBRID ROLE
Vertex
Tailor your resume for this Vertex job in about a minute.
ForgeApply tailors your resume and cover letter to this exact posting, then hands you a ready-to-submit application for Vertex's site. Free trial, no card required.
About this role
Job Description This is a hybrid position that requires 3 days a week in our Boston office Vertex is seeking an Associate Director, AI & Application Security, to lead security for AI-enabled applications, platforms, and services across the enterprise. This role is responsible for securing AI throughout the full lifecycle—from design and development to deployment and ongoing operations—including generative AI, agentic workflows, traditional machine learning, and AI embedded in enterprise applications.
This leader will help define how Vertex securely adopts and scales AI across Azure, AWS, and GCP, as well as third-party and foundation model platforms such as Microsoft Copilot / Azure OpenAI, Anthropic, Google Gemini, and AWS Bedrock. The role will partner closely with technical and business stakeholders to establish pragmatic guardrails, strengthen secure development practices, and reduce risk without slowing innovation. The ideal candidate brings deep expertise in cloud security and application security, along with strong judgment, technical credibility, and the ability to influence decisions in fast-moving, evolving environments. This role also requires practical experience applying security and risk frameworks relevant to AI and modern application environments.
Key Duties and Responsibilities • Lead AI and application security across the full lifecycle of AI-enabled systems, from design and development through deployment and operations. • Define and evolve security standards, guardrails, and control expectations for AI systems used across Vertex. • Apply and operationalize industry-recognized security frameworks and control models, including: • NIST AI Risk Management Framework (AI RMF) • NIST Cybersecurity Framework (CSF) • OWASP Top 10 • OWASP Top 10 for LLM and Generative AI Applications
• Secure AI workloads and AI-enabled applications across cloud and SaaS environments, with emphasis on: • policy enforcement • data protection • logging and telemetry • monitoring and operational visibility
• Lead threat modeling and misuse-case analysis for AI systems, including risks such as: • prompt injection and prompt abuse • sensitive data leakage • tool or action abuse • unsafe outputs • model misuse
• Define and mature AI guardrails, including monitoring, detection, logging, and misuse or negative testing practices. • Establish secure development expectations for AI-enabled applications and services, including secure coding practices and appropriate separation of development and production environments. • Build and lead application security testing practices for AI-enabled applications and supporting services, including SAST, DAST, automated scanning, and retesting processes. • Partner with Cloud Security, Security Operations, Privacy, Legal, Data Science, and Engineering teams to align security controls with business, technical, and regulatory requirements. • Influence architecture and platform decisions through practical, risk-based guidance that can scale with AI adoption. • Communicate risks, tradeoffs, and recommendations clearly to both technical teams and senior leadership.
Knowledge and Skills • Cloud security architecture and controls across Azure and AWS • Familiarity with GCP security concepts and services • Secure software development lifecycle (SDLC) practices • Secure coding standards and code review practices • SAST, DAST, automated security scanning, and remediation workflows • OWASP Top 10 and common application and API security risks • Familiarity with OWASP guidance for LLM/GenAI applications • API security, identity and access management, secrets management, and service-to-service trust • Logging, telemetry, monitoring, and detection for cloud-native environments • Threat modeling and misuse-case analysis • Familiarity with AI security risks, including: • prompt injection • data leakage • model misuse • tool or action abuse • unsafe outputs • policy enforcement
• Familiarity with AI platforms and providers such as: • Microsoft Copilot / Azure OpenAI • Anthropic • Google Gemini • AWS Bedrock • emerging AI platforms and services
Education and Experience • Bachelor’s degree in Computer Science, Information Security, Engineering, or a related field or equivalent experience. • Significant experience in application security, product security, cloud security, or a related cybersecurity discipline. • Strong experience securing cloud environments, particularly Azure and AWS; familiarity with GCP is a plus. • Deep knowledge of application security fundamentals and secure software development practices. • Experience securing APIs, platforms, and complex distributed systems. • Experience leading threat modeling, architecture reviews, and risk-based security assessments. • Experience applying security and risk frameworks in engineering environments, including familiarity with NIST AI RMF, NIST CSF, and common application security standards. • Demonstrated ability to partner effectively with engineering and platform teams to embed security into design and delivery processes. • Experience securing generative AI applications, agentic workflows, or machine learning-enabled services. • Experience defining AI guardrails and monitoring strategies at scale. • Excellent communication and influence skills, with the ability to engage both technical teams and senior leaders.
Preferred Qualifications • Experience working in biopharmaceutical or other GxP-regulated environments with strong privacy and data protection requirements.
#LI-HYBRID
Pay Range: $172,000 - $258,000 Disclosure Statement: The range provided is based on what we believe is a reasonable estimate for the base salary pay range for this job at the time of posting. This role is eligible for an annual bonus and annual equity awards. Some roles may also be eligible for overtime pay, in accordance with federal and state requirements. Actual base salary pay will be based on a number of factors, including skills, competencie
Salary insight
The midpoint of this range ($215k) is about 33% above the median disclosed salary for Boston roles listed on ForgeApply ($161k across 1,215 jobs).
See full Security Engineer salary data for Boston →
Based on live postings with disclosed pay on ForgeApply; refreshed daily. Not an estimate of this employer's offer.
Tailor your resume for this Vertex role before you apply.
Tailor my resume for this jobSimilar jobs
- Director, AI Security Specialist — Zscaler · Remote
- Senior Application Security Engineer, AI and Machine Learning — Lightningai · San Francisco, California, United States; Seattle, Washington, United States
- Director, AI Security — International Rescue Committee · Remote
- Senior Security Engineer - AI, Vice President — MUFG · Jersey City, NJ | Tampa, FL
- Associate Director - Security Technology — Northeastern University · Boston, MA (Main Campus)
- Senior Security Engineer, AI & DevSecOps — Atlasxhm · Canada; United States of America
- Director, AI & Security Development — Bb Insurance · Remote
- Senior Security Engineer (AI Security) — Justworks · New York, New York
More like this: Security & Cybersecurity Jobs · Security & Cybersecurity Jobs in Boston · More jobs at Vertex · Browse all jobs
Free ATS checker · How to Tailor Your Resume to a Job Description (Step by Step)