Member of Technical Staff - AI Security Engineering [Bay Area]
Ntt Data Aivista
| Company | Ntt Data Aivista |
| Category | Engineering |
| Location | Palo Alto |
| Remote | On-site (inferred) |
| Employment | Not stated |
| Level | Not stated |
| Salary | Not stated by the employer |
| Posted | 30 Jul 2026 |
| Last verified | 8 Aug 2026 |
| Source | Employer ATS (ashby) |
Description
MEMBER OF TECHNICAL STAFF -AI SECURITY ENGINEERING [BAY AREA]
Palo Alto, CA | Onsite
NTT DATA AIVista, Inc., a wholly owned subsidiary of NTT DATA, is based in Silicon Valley. We develop AI products that operationalize AI across enterprises operating in complex regulatory environments. We partner with other NTT companies (NTT DATA Inc., NTT DATA Japan, NTT Docomo) to ensure successful deployment to NTT clients. Our clients benefit from AIVista’s deep product AI expertise combined with the industry domain and systems integration experience of NTT DATA.
ROLE DESCRIPTION
The Principal Security Engineer will own the entire security function at NTT DATA AIVista, from the security of our AI products to our cloud environments, our corporate security posture, and our compliance programs. You will set the standard for what “secure” means across the company and be accountable for the security of products deployed into some of the world’s most regulated enterprises.
This is a hands-on, senior individual-contributor role to start: you will personally do the architecture, threat modeling, and security engineering. As the company and the security surface grow, you will build and lead a small security team, hiring and mentoring engineers and directing external specialists. We are looking for someone who wants to own security end-to-end now and grow into a security leader.
Because our products are agentic AI systems, this role carries a threat model that does not map cleanly onto traditional application security; multi-agent orchestration, sandboxed code execution, agents holding delegated credentials, and untrusted tool output crossing trust boundaries. You will define how we secure these systems.
RESPONSIBILITIES
PRODUCT & AI SECURITY
- Lead secure design reviews and threat modeling for our AI products, including agentic and multi-agent systems, identifying risks that don’t map to existing frameworks.
- Define security architecture and secure-by-design standards for AI agents, tool use, sandboxing, and delegated-credential and identity boundaries.
- Partner with Engineering and the CTO organization to embed security into the product and development lifecycle (secure SDLC, code review, dependency and supply-chain security).
- Build or introduce security tooling and guardrails that let product security scale with the business.
CLOUD & INFRASTRUCTURE SECURITY
- Own cloud security architecture and posture across AWS, Azure, and/or Google Cloud Platform — IAM design, network security, secure baselines, logging, monitoring, and vulnerability management.
- Define the security standards that IT and DevOps implement and operate against.
- Lead threat detection, posture management, and remediation prioritization across cloud environments.
SECURITY PROGRAM & COMPLIANCE
- Own the company security program, roadmap, risk register, and security policies.
- Direct the SOC 2 and ISO 27001 programs — setting the control framework and audit strategy while IT operates day-to-day compliance tooling and evidence collection.
- Own vendor security reviews, security architecture standards, and NTT DATA group security requirements.
- Oversee security awareness and training across the company.
INCIDENT RESPONSE & RISK
- Own incident response and disaster recovery planning, and lead response to security incidents.
- Establish how security risk is measured, quantified, and reported to leadership.
TEAM & LEADERSHIP (AS WE SCALE)
- Hire, mentor, and lead a small security team over time; direct external consultants and specialists.
- Represent security to executives, customers, auditors, and NTT DATA group stakeholders.
QUALIFICATIONS
- 10+ years in security engineering, with deep expertise in application/product security and cloud security.
- Hands-on experience leading threat modeling and secure design reviews for complex, distributed systems.
- Strong cloud security expertise (AWS, Azure, or Go