ForgeApply · Job listing
Staff AI Security Engineer
Fanduel
Apply in about a minute — without sacrificing quality.
ForgeApply autofills this application and tailors your resume to this exact posting. You review everything before it's sent. Free trial, no card required.
About this role
THE POSITION Our roster has an opening with your name on it
As a Staff AI Security Engineer, you'll drive how FanDuel builds and uses AI securely, from the engineers shipping production agents and models to the business use cases they power. You'll turn security into the path of least resistance and catch risk before it reaches production, across FanDuel's AI gateway, agent orchestration layer, and the growing MCP tool ecosystem.
This role sits within Security and works in close, day-to-day partnership with the teams building and operating FanDuel's AI platform. You'll help shape platform security standards, red team the agents and reference workflows running on it, and make sure security controls are built into the platform itself as it matures, rather than left to individual application teams.
Success in this role means AI/LLM and agentic security is treated as a property of the platform, enforced at the gateway and orchestration layer, not something each team reinvents.
In addition to the specific responsibilities outlined above, employees may be required to perform other such duties as assigned by the Company. This ensures operational flexibility and allows the Company to meet evolving business needs.
THE GAME PLAN
• Define the AI security roadmap: Own the multi-year AI and agentic security roadmap for FanDuel—the vision, strategy, and standards—developed jointly with the teams building the AI platform, so platform and security standards are one bar, not two.
• Secure the inference and agent stack: Drive AI/LLM and agentic security architecture across the platform as it's built out: the AI gateway and MCP tool registry, the agent orchestration layer, the skills and capability catalogue, and the evals and observability pipeline. Define controls, guardrails, and monitoring for prompt injection, jailbreaking, insecure output handling, training and retrieval data poisoning, model and data supply-chain risk, and excessive agent agency.
• Own the MCP and tool-use attack surface: Define security requirements for MCP server registration, tool authentication and authorization, and agent-to-tool trust boundaries—from tool poisoning and confused-deputy patterns to unauthenticated or over-privileged tool access.
• Stand up AI red-teaming: Build and run AI red-teaming and adversarial testing so failure modes are found before they reach production, and partner with the platform teams to feed those results into the platform's review process.
• Own the AI security governance model: defining assessment frameworks using OWASP LLM Top 10, MITRE ATLAS, and NIST AI RMF to give engineering teams a clear path to shipping AI features safely.
• Automate and scale: Build automation and tooling—automated red-team and adversarial test suites, policy-as-code for the gateway—that turns AI security into a scalable, repeatable, secure-by-default system rather than manual review.
• Partner and mentor: Partner across Security, the AI platform teams, and the business to shape direction and trade-offs. Mentor engineers on both sides and help grow AI security capability across the organization.
THE STATS What we're looking for in our next teammate
• Deep, hands-on security engineering experience embedded in the software development lifecycle, from design and code review through CI/CD, deployment, and production.
• Hands-on AI/LLM and agentic security experience: you understand how these systems fail in practice (prompt injection, jailbreaking, insecure output handling, data and model poisoning, excessive agency, tool-use exploits) and have strong, defensible opinions on how to secure them.
• Working knowledge of the AI-specific security frameworks (OWASP LLM Top 10, MITRE ATLAS, NIST AI RMF), and a pragmatic view on how established frameworks (NIST, ISO 27001, OWASP, MITRE ATT&CK, SOC 2) extend to AI systems.
• Experience securing AI or agent infrastructure such as API gateways, agent orchestration platforms, or MCP/tool-registry architectures is strongly preferred.
• Familiarity with LLM red-teaming and adversarial testing tooling (e.g., Garak, PyRIT, Rebuff, Lakera Guard, or equivalent) and LLM eval/observability platforms, or a real eagerness to build depth here.
• A demonstrated track record of defining and delivering multi-year security strategy in ambiguous, fast-moving environments.
• Strong experience building and scaling reusable security patterns and assets across an engineering organization.
• A track record of building automation and tooling that scales security capabilities and reduces manual toil.
• Familiarity with modern cloud infrastructure (AWS, GCP, or Azure), CI/CD pipelines, and software development environments at scale.
• Solid coding skills in at least one modern programming language (Python, Go, or similar).
• Experience mentoring senior engineers and shaping technical culture across an organization.
• Comfortable partnering closely with a platform engineering org (not just application teams) to embed controls at the infrastructure level.
This is a new and fast-moving field. If you bring strong security engineering fundamentals and a real track record extending into AI, we'd like to hear from you even if you don't check every box above.
ABOUT FANDUEL
FanDuel Group is the premier mobile gaming company in the United States and Canada. FanDuel Group consists of a portfolio of leading brands across mobile wagering including: America’s #1 Sportsbook, FanDuel Sportsbook; its leading iGaming platform, FanDuel Casino; the industry’s unquestioned leader in horse racing and advance-deposit wagering, FanDuel Racing; and its daily fantasy sports product.
In addition, FanDuel Group operates FanDuel TV, its broadly distributed linear cable television network and FanDuel TV+, its leading direct-to-consumer OTT platform. FanDuel Group has a presence across all 50 states, Canada, and Puerto Rico.
The company is based in New York with US offices in Los Angeles, Atlanta, and Jersey Ci
Salary insight
The midpoint of this range ($213k) is about 21% above the median disclosed salary for New York roles listed on ForgeApply ($177k across 4,669 jobs).
See full Security Engineer salary data for New York →
Based on live postings with disclosed pay on ForgeApply; refreshed daily. Not an estimate of this employer's offer.
Ready to apply to Fanduel?
Apply in about a minuteSimilar jobs
- Staff AI Security Engineer — Fanduel · Atlanta, Georgia, United States
- Staff AI Security Engineer — Springhealth66 · San Francisco, CA (Hybrid)
- Staff AI Security Engineer — Springhealth66 · Seattle, WA (hybrid)
- Staff AI Security Engineer — Okta · Bellevue, Washington; Chicago, Illinois; New York, New York; San Francisco, California; Washington, DC
- Staff AI Engineer — Crunchyroll · Dallas, Texas, United States
- Staff AI Engineer — Drata · Remote
- Staff AI Engineer — Workato · Palo Alto, California
- Staff AI Engineer — Greenlitecareers · New York City
More like this: Security & Cybersecurity Jobs · Security & Cybersecurity Jobs in New York · More jobs at Fanduel · Browse all jobs