Senior Engineer - Genai Security

Bank of America Bank of America · Banking · New York, NY

This Senior Engineer role focuses on defining and leading the engineering approach for complex features within the Global Markets GenAI Technology team at Bank of America. The role involves designing and building a global generative AI platform that leverages LLMs and data to drive insights, revenue growth, and improved business processes. Key responsibilities include defining the security architecture, implementing access controls, establishing secure API patterns, defining AI guardrails and safety controls, leading threat modeling, and designing RAG and data security controls.

What you'd actually do

  1. Define and implement the security architecture for the GenAI platform
  2. Design and enforce identity and access control models
  3. Establish secure API and tool invocation patterns
  4. Define and implement AI guardrails and safety controls
  5. Lead threat modeling and risk assessment for GenAI systems

Skills

Required

  • 8+ years in cybersecurity, security architecture, or platform security engineering
  • Strong expertise in: Identity and access management (IAM), OAuth2, mTLS
  • API security, gateway enforcement, and zero-trust design
  • Threat modeling and risk assessment
  • Proven experience designing and securing: Distributed, cloud-native platforms
  • Multi-tenant systems with strict data access controls
  • Strong understanding of: Data protection, encryption, and access control principles
  • Auditability, logging, and compliance frameworks

Nice to have

  • Experience with GenAI / AI/ML security, including: Prompt injection and adversarial attacks
  • Data leakage and model misuse risks
  • Guardrails and safety evaluation frameworks
  • Experience securing: RAG architectures, vector databases, and retrieval pipelines
  • Agent-based or multi-agent systems
  • Experience in regulated environments (financial services strongly preferred)
  • Familiarity with: OWASP LLM / agentic security risks
  • Model governance, lineage, and compliance metadata

What the JD emphasized

  • GenAI Security
  • security architecture
  • AI guardrails
  • threat modeling
  • risk assessment
  • RAG
  • data security

Other signals

  • Generative AI presents an exciting opportunity to derive valuable insights from data and drive revenue growth, efficiencies, and improved business processes.
  • Define and implement the security architecture for the GenAI platform
  • Design and enforce identity and access control models
  • Establish secure API and tool invocation patterns
  • Define and implement AI guardrails and safety controls
  • Lead threat modeling and risk assessment for GenAI systems
  • Design and enforce RAG and data security controls