# AI Security Work in the United States, 2026: Requirements in Current Vacancies

> Evidence from 113 current U.S.-eligible employer vacancies describes the duties, outputs, skills and decision boundaries of AI-security work, with transparent sampling limits.

- Canonical page: https://mtfinstitute.com/insights/ai-security-us-vacancy-requirements-2026/
- Content type: Article
- Editorial category: Research &amp; Reports
- Publisher: MTF Institute of Management, Technology and Finance
- Author: MTF Institute Research Team- Published: 2026-10-05
- Updated: 2026-10-05
- Language: English
- Topics: AI Security, Prompt Injection, LLM Risk, Agent Security, Cybersecurity Careers

## AI Security Work in the United States, 2026: Requirements in Current Vacancies

*MTF Institute Research Team · 5 October 2026*

**Research archive:** The [exact versioned Zenodo record](https://doi.org/10.5281/zenodo.23171618) contains the [six-page PDF report](https://zenodo.org/records/23171618/files/ai-security-us-vacancy-requirements-2026.pdf?download=1), the [113-row vacancy source index](https://zenodo.org/records/23171618/files/accepted-vacancy-index-rights-safe-v2.csv?download=1), an aggregate Role Requirements Matrix and methodology notes.

## Executive summary

This report reads a structured, purposive sample of **113 current, U.S.-eligible employer requisitions from 90 employers**. The roles involve technical security work on AI, large language model (LLM), retrieval, or agent-enabled systems. They do not form a representative sample of U.S. hiring, and the counts below describe only the reviewed postings. A mention is evidence that a posting explicitly states a requirement or duty; silence is not evidence that an employer rejects it.

The central work pattern is broader than testing prompts. Security practitioners have to identify where instructions, retrieved material, data, identities, and external tools cross trust boundaries; assess how an attacker could redirect a model or agent; design controls; test their behavior; and turn findings into decisions that engineers can implement. Among the 113 reviewed requisitions, 79 explicitly assign security architecture or control implementation, 57 AI-system threat modeling or security review, 39 agent tool or action authorization, 38 AI-security detection, monitoring, or incident response, and 37 guardrail or runtime policy design. These categories overlap: a single requisition may contribute to several counts.

The specialist layer rests on established engineering and security skills. In the same 113-requisition sample, 81 explicitly mention identity, authentication, or authorization; 77 secure coding or programming; 77 cloud, container, or platform security; and 62 application or API security in any coded context. Across the whole sample, 80 explicitly mention prompt-injection attack or defense in any coded context; 17 of the 62 requisitions with a stated required-criteria field classify it as required, and 15 of the 84 with a stated preferred-criteria field classify it as preferred. Assigned duties, required applicant criteria, and preferred criteria are different kinds of evidence. The required and preferred field groups can overlap.

These vacancies span AI-system security engineering, application and product security with an AI remit, adversarial evaluation and research, platform architecture, and technical assurance. They include senior, staff, principal, lead, and other levels as well as some engineer roles. A staff-level posting is evidence about that role, not a universal entry-level threshold. The practical implication is to build a portfolio of evidence: a threat model tied to an actual trust boundary, a test that demonstrates a failure mode, a guardrail or authorization decision with its limits, and a concise handoff to the team that owns the system. It is not possible to infer job placement or market-wide demand from this sample.

## What the work covers

The reviewed roles protect AI-enabled workflows, not merely models in isolation. An application may combine a system instruction, user request, retrieved content, tools, and an answer or action. Each transition raises questions about provenance and privilege. An attacker may control a lower-trust document, page, message, or tool response and try to turn its contents into an instruction. Other risks include excessive tool permissions, exposed sensitive context, weak isolation between users, and monitoring that misses an unsafe action.

| Explicitly assigned duty in reviewed postings | Requisitions |
|---|---:|
| Security architecture or control implementation | 79 of 113 |
| AI-system threat model or security review | 57 of 113 |
| Agent tool or action authorization | 39 of 113 |
| AI-security detection, monitoring, or incident response | 38 of 113 |
| Guardrail or runtime policy design | 37 of 113 |
| Sensitive-data exposure or exfiltration control | 40 of 113 |
| Prompt-injection or jailbreak testing | 11 of 113 |
| Adversarial evaluation or red teaming | 28 of 113 |
| Retrieval or context security | 19 of 113 |

Every row counts a requisition once when the source assigns the coded duty; the rows are not mutually exclusive. The distinction between the 11 postings that assign prompt-injection or jailbreak testing and the 80 that mention prompt-injection attack or defense in any coded context matters. A posting can recognize the attack class without assigning a discrete testing duty. Similarly, a role can assign control implementation while leaving the exact control design open to the hire and its engineering partners.

Representative employer postings show the range. [OpenAI&#039;s agent-security engineer](https://jobs.ashbyhq.com/openai/e9bea775-7eb6-438a-ab96-27d5f941e69d) connects agent infrastructure, product, research, safety, and security work. [Notion&#039;s AI product-security engineer](https://jobs.ashbyhq.com/notion/def3f337-5593-491c-b34d-e0b53f2a5cac) addresses security architecture for customer-workspace AI features, including tool execution, retrieval, content writes and permission checks. [Databricks&#039; agentic-security engineer](https://job-boards.greenhouse.io/databricks/jobs/7882009002) reflects platform engineering around agent systems. [The University of Washington&#039;s AI security engineer](https://uw.wd5.myworkdayjobs.com/en-US/UWHires/job/Seattle-WA/AI-Security-Engineer_REQ-0000135281) combines Azure AI platform security controls with identity and access work, CI/CD, and code-security tooling. These examples illustrate tasks in particular postings; they are not evidence of how often all U.S. employers assign them.

### Trust boundaries, testing, and controls

The most distinctive tasks concern which inputs an AI system may trust and which actions it may take. A useful review maps the origin of system instructions, user requests, retrieved documents, tool output, and stored memory; identifies which party can alter each surface; and traces the permissions available after the content reaches a model or agent. The security question is whether lower-trust material can cross into a higher-trust instruction or authorization role. In the sample, 57 of 113 reviewed requisitions explicitly assign AI-system threat modeling or security review, 39 agent tool or action authorization, and 19 retrieval or context security.

Testing then needs to be tied to a decision. As a practical example, a prompt-injection test can specify the attacker-controlled surface, desired deviation, expected boundary, observed behavior, and the owner of remediation. A jailbreak or adversarial evaluation may assess whether a safeguard is robust across variants, whether the model&#039;s output appears safe while a tool call is unsafe, or whether a retrieved passage can trigger disclosure. In the sample, 11 of 113 requisitions explicitly assign prompt-injection or jailbreak testing, and 28 of 113 assign adversarial evaluation or red teaming. [Cloudflare&#039;s AI security research and red-team role](https://job-boards.greenhouse.io/cloudflare/jobs/8097321) illustrates the handoff from offensive findings to detection and response teams; [Anthropic&#039;s cyber-evaluations role](https://job-boards.greenhouse.io/anthropic/jobs/5406367008) illustrates evaluation before major model releases and translation of results into safeguards.

Control design appears at several layers. Authorization can constrain the tool an agent may call, the resource scope, the user identity on whose behalf it acts, and whether a sensitive action needs a human decision. Retrieval controls can limit which content enters context and prevent a document&#039;s text from becoming authority. Runtime policies can intercept or constrain an action; data controls can reduce disclosure or exfiltration. Monitoring should make misuse and control failure observable. Of the 113 postings, 37 explicitly assign guardrail or runtime policy design, 40 sensitive-data exposure or exfiltration control, 38 AI-security detection, monitoring, or incident response, and 16 secure AI development or release-gate work. These are related but non-identical assignments, and none of the counts establishes the effectiveness of a control.

### What employers expect the work to produce

Job advertisements often describe work more readily than deliverable formats. The coded outputs nevertheless show artifacts that another team can inspect, implement, or use in a decision. Each row below counts an explicitly assigned output; categories can overlap.

| Assigned output | Requisitions |
|---|---:|
| Guardrail policy or reference pattern | 35 of 113 |
| Adversarial test suite or result | 15 of 113 |
| Threat model | 15 of 113 |
| Detection rule or monitoring signal | 13 of 113 |
| Security architecture review | 13 of 113 |
| Risk assessment or evidence pack | 10 of 113 |
| Incident runbook or postmortem | 5 of 113 |
| Remediation plan or ticket | 0 of 113 |
| Release or exception decision record | 0 of 113 |

The low explicit count for an artifact should not be read as a judgment that it is unimportant. Many advertisements describe assessment, building, and collaboration without naming the eventual document or workflow object. A reader should distinguish **what the posting establishes** from plausible professional practice. For example, a test report with reproducible steps can make a finding actionable, but the report cannot claim all reviewed employers prescribe that format.

## Technical capabilities: AI-specific and foundational

The coding distinguishes any explicit mention of a capability from an assigned duty and from a classified hiring criterion. The first compact table uses the full 113-requisition denominator and combines all coded contexts. The second uses the 62 postings that state required criteria and the 84 that state preferred criteria. These disclosed-field groups can overlap, and their columns must not be added.

| Capability in any coded context | Requisitions |
|---|---:|
| Identity, authentication, or authorization | 81 of 113 |
| Prompt-injection attack or defense | 80 of 113 |
| Cloud, container, or platform security | 77 of 113 |
| Secure coding or programming | 77 of 113 |
| LLM, agent, or retrieval architecture | 71 of 113 |
| Security telemetry, detection, or response | 70 of 113 |
| Threat modeling | 66 of 113 |
| Adversarial testing or evaluation | 65 of 113 |
| Application or API security | 62 of 113 |

| Explicitly classified applicant criterion | Required | Preferred |
|---|---:|---:|
| LLM, agent, or retrieval architecture | 24 of 62 | 22 of 84 |
| Identity, authentication, or authorization | 21 of 62 | 18 of 84 |
| Secure coding or programming | 31 of 62 | 7 of 84 |
| Prompt-injection attack or defense | 17 of 62 | 15 of 84 |
| Cloud, container, or platform security | 26 of 62 | 27 of 84 |
| Adversarial testing or evaluation | 19 of 62 | 20 of 84 |
| Security telemetry, detection, or response | 13 of 62 | 18 of 84 |
| Threat modeling | 19 of 62 | 6 of 84 |
| Application or API security | 24 of 62 | 14 of 84 |

An assigned duty is not automatically an applicant prerequisite: a hiring team may expect the person to perform a review after joining while listing a different formal screen. A preferred criterion is a stated advantage, not a compulsory gate. For example, 20 of the 84 postings with stated preferred criteria classify adversarial testing or evaluation as preferred, while 19 of the 62 with stated required criteria classify it as required. The other postings did not explicitly waive the skill.

The foundation is substantial. Software and API security help define the attack surface around the model: input handling, service authentication, API scopes, logging, data flows, and the security properties of application code. Identity and authorization become especially important when an agent acts through tools, where the relevant question is not simply whether a user is signed in but what authority the agent inherits or receives at each step. Cloud and platform security matter because AI workflows run in deployed environments with secrets, networks, storage, build pipelines, and operational controls. Programming enables instrumentation, test harnesses, guardrail implementation, and reproducible evidence. [Cisco&#039;s AI security engineer posting](https://cisco.wd5.myworkdayjobs.com/en-US/Cisco_Careers/job/AI-Security-Engineer_2024998) names Kubernetes, APIs, and Python or Go in its technical environment; [the University of Washington posting](https://uw.wd5.myworkdayjobs.com/en-US/UWHires/job/Seattle-WA/AI-Security-Engineer_REQ-0000135281) names Azure AI Foundry, Entra ID, role-based access control, infrastructure-as-code tools, and code-security tooling. Named products show the environments of particular employers, not a universal stack.

The specialist layer adds knowledge of LLM behavior, agent orchestration, retrieval context, prompt injection, adversarial evaluation, model or data-pipeline security, and the limits of a guardrail. In any coded context, 21 of 113 postings explicitly mention model or ML pipeline security, 62 data privacy or protection, and 24 security-framework application. Some roles lean toward model evaluation, others toward enterprise integration or platform control. [Anthropic&#039;s safeguards red-team engineer](https://job-boards.greenhouse.io/anthropic/jobs/5320469008), [Appian&#039;s AI security engineer](https://job-boards.greenhouse.io/appian/jobs/8201099), and [AllianceBernstein&#039;s AI security engineer](https://abglobal.wd1.myworkdayjobs.com/en-US/alliancebernsteincareers/job/Nashville-Tennessee/AI-Security-Engineer_R0019675-3) illustrate that range across different employers.

### Tools are evidence of context, not a standard kit

The underlying postings mention tools and technologies, but the aggregate matrix does not normalize counts for individual products or languages. It would be unsound to rank products or declare a mandatory toolchain from it. The source records show Python, Go, Rust, TypeScript, Java, cloud platforms, SIEM systems, Kubernetes, APIs, and infrastructure-as-code in different roles. Some refer to model or agent frameworks and model-context tooling. The concrete tool matters less than the task it supports: construct a test harness, inspect a tool call, enforce a permission boundary, collect telemetry, or give a development team an implementable finding. A candidate should read the current employer posting for its exact stack rather than infer it from the overall occupational label.

## Behavioral skills, interfaces, and work rhythm

The work frequently spans engineering groups. In any coded context, cross-functional engineering collaboration is explicitly mentioned in 72 of 113 requisitions, developer guidance or enablement in 55, independent ownership with documented handoff in 36, translation of technical findings into business risk in 33, clear written findings in 29, and prioritization or explanation of tradeoffs in 29. Incident coordination or escalation appears in 20. As with technical skills, these are coded mentions, not measured job performance or a ranking of what employers value most.

In the authors&#039; practical reading, a reviewer explains the failed boundary, attacker control, resulting action, repeatability, and remediation owner. A finding that only names a risk category leaves engineers to reconstruct the path. A useful handoff gives evidence, severity reasoning, constraints on a fix, and a repeatable check. Risk communication distinguishes demonstrated exposure from a hypothetical path and a narrow fix from a broader control.

The source records show several interfaces without establishing a common organization chart. [OpenAI&#039;s agent-security posting](https://jobs.ashbyhq.com/openai/e9bea775-7eb6-438a-ab96-27d5f941e69d) describes daily collaboration across agent infrastructure, product, research, safety, and security. [Cisco&#039;s posting](https://cisco.wd5.myworkdayjobs.com/en-US/Cisco_Careers/job/AI-Security-Engineer_2024998) identifies AI platform, infrastructure, security, compliance, and product counterparts. [Cloudflare&#039;s red-team role](https://job-boards.greenhouse.io/cloudflare/jobs/8097321) connects offensive testing with detection and response and with governance evidence. An enterprise role may also interface with central technology teams, while a product-security role may be embedded with developers. Those observations are grounded in named postings; aggregate interface disclosure is shown below.

Work rhythm similarly depends on the role. Anthropic&#039;s cyber-evaluations role places safeguard robustness testing before major model launches. Cloudflare&#039;s red-team posting describes exercises that probe incident-response readiness and feed defensive improvement. OpenAI&#039;s agent-security role describes daily cross-functional work. Other advertisements simply state ongoing design, testing, monitoring, or consultation without specifying a daily, weekly, or release cadence. The evidence therefore supports a range: pre-release evaluation, iterative engineering review, operational monitoring, and incident-triggered response. It does not support a single standard schedule for AI-security practitioners.

Decision authority is another boundary to read carefully. A role may propose a control, provide evidence to an owner, or influence a launch decision; the posting may not say who has final sign-off. [Notion&#039;s AI product-security role](https://jobs.ashbyhq.com/notion/def3f337-5593-491c-b34d-e0b53f2a5cac) addresses customer-workspace AI functions involving tool execution and permission checks. Cloudflare&#039;s red-team findings are intended to drive defensive changes. Neither example licenses a general claim that an AI-security engineer independently approves or blocks every release. Where a posting is silent on formal authority or escalation, that field remains unresolved. In practice, an effective security deliverable should make the recommendation, evidence, decision owner, exception path, and follow-up explicit, while respecting the actual employer&#039;s governance.

## Qualifications and role levels

The corpus combines several role families and levels. Some postings are explicitly staff, principal, senior, lead, or distinguished roles; others are engineer or research roles, and some titles leave level ambiguous. [Databricks&#039; staff agentic-security engineer](https://job-boards.greenhouse.io/databricks/jobs/7882009002), [Cloudflare&#039;s research and red-team engineer](https://job-boards.greenhouse.io/cloudflare/jobs/8097321), [EVERSANA&#039;s AI security engineer I](https://jobs.smartrecruiters.com/EVERSANA1/744000151855805), and [Anthropic&#039;s cyber-evaluations engineer](https://job-boards.greenhouse.io/anthropic/jobs/5406367008) should not be collapsed into one experience threshold. Level or seniority is stated in 71 of 113 postings and unstated in 42 of 113; this disclosure count does not establish a distribution across levels.

Qualification language should be read at the posting level. A required item belongs to that employer&#039;s application screen; a preferred item may distinguish a candidate but is not stated as mandatory. Some employers ask for experience with security architecture, software engineering, cloud platforms, adversarial evaluation, or AI systems; others emphasize evidence of building and operating controls. The source records disclose education in 35 of 113 postings and experience in 85 of 113, but the aggregate matrix does not establish a cross-employer distribution of degrees, years, certifications, or equivalent routes. This report therefore makes no claim that a specific credential or number of years is universally required. Readers considering a role should inspect its own required and preferred headings and check whether the role is operational, research-focused, application-security-focused, or architecture-led.

| Posting field | Stated | Unstated |
|---|---:|---:|
| Education | 35 of 113 | 78 of 113 |
| Experience | 85 of 113 | 28 of 113 |
| Work cadence | 34 of 113 | 79 of 113 |
| Team or stakeholder interfaces | 72 of 113 | 41 of 113 |
| Decision authority | 45 of 113 | 68 of 113 |
| Escalation | 9 of 113 | 104 of 113 |

“Stated” means the reviewed posting gives an explicit indication for that field; “unstated” means it does not. Neither category measures whether a task occurs after hiring.

A practical preparation sequence, inferred from the tasks and outputs in the sample, starts with application, API, identity, cloud, and programming foundations. Model an AI workflow&#039;s trust and permission boundaries; run a reproducible adversarial test; evaluate a control and its residual risk; and write an actionable handoff. This is guidance for demonstrating work, not an employment promise.

## Method, rights, and limits

The unit of analysis was one distinct, current employer-owned requisition with a live U.S. workplace or explicitly U.S.-remote application path on 5 October 2026. Researchers used live Greenhouse and Ashby employer boards, official Workday, Lever, SmartRecruiters, iCIMS, Workable and employer career pages, and focused search queries for AI security, LLM and agent security, prompt injection, application or product security with an explicit AI remit, and adversarial evaluation. Search snippets were discovery leads, not evidence; an employer posting and live application path supplied the inclusion evidence. At least 237 distinct candidate URLs were logged: 113 entered the strict sample and 124 other distinct URLs were excluded or remained unresolved after reconciling three URLs recorded in both screening paths. This is a lower bound because unlogged discovery snippets are not counted. Inclusion required an explicit technical duty securing an AI, LLM, retrieval, or agent-enabled system. A general cybersecurity role that merely used AI as a work aid did not qualify. Closed, duplicate, non-U.S., nontechnical, product-only, marketing, sales, and otherwise unsuitable leads were excluded. Duplicate URLs and employer requisition IDs were removed; distinct geographic or seniority requisitions with separate IDs were retained.

The 113 accepted requisitions came from 90 employers: 54 Greenhouse, 33 Ashby, 11 Workday, five official employer career-site, four Lever, four SmartRecruiters, one iCIMS, and one Workable records. The source mix reflects accessible postings found by this purposive search, not where all U.S. vacancies are advertised. Multiple openings from an employer can increase its weight in requisition counts. As a sensitivity check, the matrix also counts an employer once per category: security architecture or control implementation appears in postings from 65 of 90 employers, AI-system threat modeling or security review from 50 of 90, agent tool or action authorization from 36 of 90, and prompt-injection attack or defense is mentioned in postings from 69 of 90 employers. These employer counts are descriptive checks, not employer-market prevalence estimates.

The analysis records explicit evidence for assigned duties, outputs, hard and behavioral skills, and whether a criterion is clearly required or preferred. A requisition contributes at most once to a category even when the posting repeats it. A capability may appear as a duty and a preferred or required criterion in the same posting; column totals should never be summed. Ambiguous criterion wording remains unclassified. Whole-sample counts use the exact **113-requisition denominator**. Required-criterion counts use the 62 requisitions that disclose that field; preferred-criterion counts use the 84 that disclose that field. Those groups may overlap. The 90-employer counts use a separate denominator. An unstated field is not treated as evidence that the work never occurs.

The report paraphrases employer postings and links to selected primary sources without reproducing job-description text. The employer pages may change or close after the retrieval date. The independent [MTF Institute article on AI security, prompt injection, and agent controls](https://mtfinstitute.com/insights/ai-security-prompt-injection-agent-controls-2026/) offers recent technical context; it is not part of the 113-posting count. Broad occupational or professional-association material can inform interpretation but cannot establish specialist vacancy frequency here.

This is a structured, purposive snapshot, not a probability sample. It cannot estimate national prevalence, hiring growth, salary, employer adoption, or career outcomes. Job advertisements are selective descriptions of intended work, not observations of actual day-to-day practice. The categories overlap and depend on the available wording; unstated does not mean absent in the workplace. The sample includes varied role families and seniority, and it gives limited normalized evidence on individual products, formal qualification types, and final decision rights. The defensible conclusion is narrower and useful: in these reviewed current requisitions, employers explicitly describe AI-system security work that joins trust-boundary analysis, adversarial testing, agent and data controls, monitoring, implementable outputs, and established application-security engineering.



## Citation

When citing or summarizing this material, link to the canonical HTML page: https://mtfinstitute.com/insights/ai-security-us-vacancy-requirements-2026/
