Skip to main content
Full-Time
On-Site

Engineer II (AI Security Infrastructure Engineer) B3617

View on Map

Description

This role at The Toronto-Dominion Bank involves leading security strategy and engineering solutions for Generative AI and Large Language Model (LLM) platforms, integrating advanced AI security into existing enterprise systems. The successful candidate will act as a key technical leader, bridging AI innovation with core infrastructure security. Key responsibilities include researching, evaluating, and conducting proof-of-concepts for new security technologies and protocols to protect assets across Azure, Google Cloud, and On-Premises environments. Focus areas include Agentic AI protocols (A2A, MCP), API security, Identity and Access Management, and securing third-party integrations for LLMs, AI models, and RAG applications. The role also involves partnering with AI Development, Dev-Sec-Ops, and Platform Engineering teams to translate successful security PoC's into robust, production-ready solutions.

What We're Looking For

Research, evaluate, and design AI Security Infrastructure solutions to address security control gaps and align with leadership strategy and roadmaps.,Conduct proof-of-concepts (PoC's) for new security technologies and protocols and support hardening efforts for mission-critical assets in Azure, Google Cloud, and On-Premises environments.,Evaluate and secure emerging standards for multi-agent workflows, such as Agent-to-Agent (A2A) and Model Context Protocol (MCP).,Perform deep security assessments and validation of infrastructure and connection points for third-party LLM and RAG (Retrieval-Augmented Generation) applications.,Support threat modeling exercises for new AI applications and pipelines to proactively identify design flaws and adversarial attack vectors (e.g., prompt injection paths).,Support the design, build, and testing of security controls to mitigate common AI/ML attacks based on frameworks like OWASP Top 10 for LLM Applications and Mitre Atlas.,Define and implement security designs for Identity and Access Management (IAM), with a focus on securing non-human identities, service principles, and cross-cloud access.,Own the security strategy for all AI service consumption, including hardening API Gateways and securing authentication flows (e.g., OAuth 2.0/OIDC) for model endpoints.,Design and conduct PoC's for secure storage, injection, and rotation of confidential data (API keys, model weights, database credentials) using solutions like Azure Key Vault and GCP Secret Manager.,Establish security configuration baselines and network segmentation (e.g., Private Link, VPC Service Controls) for AI-specific cloud resources on Azure and GCP.,Provide essential infrastructure security expertise and tooling to support the AI Red Team program.,Collaborate with DevOps, Governance, Vulnerability Management, and Platform Engineering partners to translate successful security PoC's and designs into robust, production-ready solutions and Infrastructure as Code (IaC) controls.

Ideal Candidate

7+ years of progressive experience in Cybersecurity, Cloud Security Engineering, Application Security, or AI Security and Automation.,2-3+ years of experience in machine learning / A.I.,Strong understanding of the AI/ML development lifecycle and the unique security risks associated with Generative AI, LLMs, and RAG architectures.,Familiarity with the security implications of emerging agent collaboration protocols (A2A and MCP).,Experience with risk assessment, vulnerability research, or threat modeling focused on AI systems.,Desired: Relevant professional certifications (e.g., Azure Security Engineer Associate, GCP Professional Cloud Security Engineer, CISSP, CCSP).,Desired: Experience securing containerized environments (Kubernetes/AKS/GKE).,Desired: Familiarity with Infrastructure as Code (IaC) tools such as Terraform or Pulumi.

Hard Skills

Cloud Security (Microsoft Azure
Google Cloud Platform
hybrid security models)
Identity & Access Management (IAM)
OAuth 2.0/OIDC
token-based authentication
API/Application Security (REST APIs
API Gateways
WAFs)
Secrets Management (Azure Key Vault
GCP Secret Manager
HashiCorp Vault
Hardware Security Modules)
Programming/Scripting (Python
Go
PowerShell)
AI security frameworks (OWASP Top 10 for LLM Applications
OWASP API Top 10
Mitre Atlas)
Generative AI
LLMs
RAG architectures
Agent-to-Agent (A2A) protocol
Model Context Protocol (MCP)
Threat Modeling
Infrastructure as Code (IaC)
Kubernetes/AKS/GKE
Terraform
Pulumi

Soft Skills

Excellent written communication
excellent verbal communication
ability to articulate complex technical risks
ability to design strategy to technical teams
ability to design strategy to non-technical stakeholders
collaboration

Work Hours

37.5 hours/week

Benefits

Base salary
variable compensation
health and well-being benefits
savings and retirement programs
paid time off
banking benefits and discounts
career development
reward and recognition programs
training and onboarding
regular career and development conversations
online learning platform
mentoring programs

Special Commitments

Job opportunity is subject to provincial regulation for employment purposes.

Also Available At

About the Company

T

The Toronto-Dominion Bank

The Toronto-Dominion Bank and its subsidiaries are collectively known as TD Bank Group, one of the largest banks in North America. TD provides a wide range of personal, commercial, and investment banking products and services to over 27 million customers globally. Headquartered in Toronto, Canada, the bank operates through key segments including Canadian Retail, U.S. Retail, and Wholesale Banking.

Inclusive
Community-focused
Professional
Growth-oriented
Caring
View all jobs at The Toronto-Dominion Bank

    We respect your privacy

    BerryMap uses cookies to provide essential features, analyze usage, and improve your experience. You can customize your preferences below.