AI and Cloud Security Engineer
Overview
TD SYNNEX (NYSE: SNX) is the world's largest IT distributor, and we are accelerating AI adoption across Azure AI Foundry, AWS Bedrock, Copilot Studio, Databricks, and self-hosted agent environments. Our security philosophy is distinctive: rather than slowing innovation with pre-approval gatekeeping, we operate a runtime-first, default-allow security posture โ every AI interaction is intercepted, analyzed, and enforced at the moment of execution. In our architecture, the traditional network perimeter no longer defines the defensive boundary: the AI agent is the perimeter.
The AI & Cloud Security team is chartered to make that vision operational. We are seeking senior technical owner of the AI security runtime control plane and detection fabric. You will build and integrate the inline enforcement pipeline (AI gateway โ runtime data protection โ intent-based enforcement), tune the policies that keep it fast and low-friction, and serve as the final escalation point for the most complex AI and cloud security incidents. You will also help implement and participate in operation of a closed-loop defensive system in which continuous red-team findings automatically improve runtime policies, detection logic, and SOC threat models. You join a team of two AI & Cloud Security Architects and will be the engineering force that turns strategy into operating controls โ across a multi-cloud estate (Azure, AWS, GCP).
This role involves collaborating with cross-functional teams to ensure the security of AI and cloud environments, AI applications and infrastructure, addressing potential threats, and maintaining compliance with regulatory standards. The ideal candidate will have a strong background in AI technologies and their implementation as well as cloud security, security principles and cybersecurity best practices. The ability to develop automation in both AI and cloud environments with infrastructure as code (IaC) or policy as code principles is required. The engineer will report to AI & Cloud Security leadership and have strong working relationships with IT and application development leadership.
Responsibilities
-
Integration โ build and own the AI runtime control plane. Engineer, deploy and operate the inline enforcement pipeline for AI traffic: an AI gateway chained with runtime data-protection and intent-based enforcement platforms, fronting LLMs, tools, and MCP servers across Azure AI Foundry, AWS Bedrock, GCP Vertex, Copilot Studio, Databricks, and self-hosted environments.
-
Harden the gateway layer for resilience : configure buffering and overload management, enforcement timeouts on external-processing filters, layered global/local rate limiting, and prompt-truncation filters to defend against token-exhaustion and "reasoning overload" denial-of-service attacks.
-
Integrate the wider AI security ecosystem into one coherent system : onboard AI asset-intelligence context (agent inventory, ownership, blast radius) into enforcement decisions; connect model-security and supply-chain telemetry and continuous red-team signals into SIEM correlation and SOC workflows; stream unified AI detections, decision logs, and policy events for forensics and audit.
-
Policy tuning โ enforce without friction. Author and calibrate runtime policies: prompt-injection and jailbreak prevention, PII detection/redaction and data masking, intent-based filtering, tool-call validation, MCP access control, and agent permission boundaries (including "lethal trifecta" prevention for low-code agents). Balance detection versus hard-block modes to minimize false positives, and tune per AI archetype โ embedded SaaS copilots, democratized low-code agents, homegrown agentic pipelines, device-based coding agents, and homegrown models.
-
Operate the closed loop : translate continuous adversarial-testing findings into runtime policy updates, new detection content, and guardrail tuning, then validate remediation through re-testing โ so defenses evol