Note: Please apply those candidate who can work on W2 Note: Please apply those candidate who can work on W2 Note: Please apply those candidate who can work on W2 Note: Please apply those candidate who can work on W2
Job Title: AI Engineer - Security
Location: Bolingbrook, IL (initial remote)
Duration: 12 months Contract
Job Description:
The AI Engineer will build and operationalize the tooling, pipelines, and controls that secure Ulta's growing portfolio of AI initiatives. This is a hands-on engineering role responsible for implementing AI/ML security controls, integrating AI risk detection into existing security tooling, and supporting secure-by-design AI development practices across the enterprise.
Key Responsibilities:
Design, build, and maintain tooling for AI/ML asset discovery, model inventory, and shadow-AI detection across the enterprise.
Implement security controls for AI pipelines, including data protection, access control, secrets management, and secure model deployment (MLOps/LLMOps security).
Integrate AI risk signals (e.g., prompt injection attempts, data exfiltration via AI tools, anomalous model behavior) into existing SIEM/SOAR and monitoring platforms.
Build automated testing and red-teaming harnesses for AI applications (adversarial testing, jailbreak/prompt-injection testing, data leakage testing).
Support secure integration of third-party and internally built AI/LLM services (API gateways, guardrail middleware, output filtering).
Collaborate with data science, platform engineering, and application teams to embed security requirements into the AI development lifecycle (secure-by-design, CI/CD gates).
Document control implementations, runbooks, and technical standards for AI security engineering.
Required Qualifications:
3+ years in security engineering, cloud engineering, or ML engineering, with direct hands-on exposure to AI/ML or LLM-based systems.
Proficiency in Python and experience with ML/LLM frameworks (e.g., LangChain, Hugging Face, TensorFlow/PyTorch) or AI security tooling (e.g., guardrail frameworks, model scanning tools).
Working knowledge of cloud platforms (Azure and/or AWS/Google Cloud Platform) and cloud-native security controls (IAM, network segmentation, key/secrets management).
Familiarity with AI-specific threat models: prompt injection, model inversion, data poisoning, insecure output handling, excessive agency (OWASP Top 10 for LLM Applications).
Experience with CI/CD pipelines, infrastructure-as-code, and integrating security tooling into automated pipelines.
Preferred Qualifications:
Experience with SIEM/SOAR platforms (Splunk, Sentinel, etc.) and scripting integrations.
Security certifications (Security+, GCIH, OSCP) or cloud certifications (AWS/Azure Security). Prior retail or PCI-regulated environment experience.