1,134,601open jobs
65,337companies
199,586added this week
Browse all
Salary
≈ $116k – $246k per year (Estimated)
Location
In office (Charlotte)
Seniority
Staff · 5+ years exp
Employment
Full-Time

Confirmed on the employer's own hiring board on Oct 2, 2026. First seen by Alion on Sep 29, 2026. CRC Group scores B on the Alion truth index.

Overview
Company
Impact
Profile match
Headquartered in Charlotte, North Carolina, CRC Group is a wholesale specialty insurance distributor and underwriting manager. Founded in 1982, the firm operates as one of North America's largest pure-play wholesale brokerages, serving retail insurance agencies and carrier partners. The organization functions through two primary divisions: Specialty + Benefits and Underwriting.

The position is described below. If you want to apply, click the Apply button at the top or bottom of this page. You'll be required to create an account or sign in to an existing one.

If you have a disability and need assistance with the application, you can request a reasonable accommodation. Send an email to Accessibility (accommodation requests only; other inquiries won't receive a response).

Regular or Temporary:

Regular

Language Fluency: English (Required)

Work Shift:

1st Shift (United States of America)

Please review the following job description:

CRC is putting AI agents to work across the business, and we need a hands-on leader to make sure they are built and run securely from day one. The AI Security Engineer Lead owns the engineering of security controls for agentic AI: the agent harnesses that house and orchestrate agents, tools, the MCP servers and APIs that agents call, agent-to-agent (A2A) interactions, and the AI and API gateways that sit in the path. This role designs reusable security patterns, builds and operates the controls that enforce them, and proves those controls actually work.

This is a builder’s role with real influence. The ideal candidate partners closely with AI Innovation, Data Management and Analytics, Enterprise Architecture, and Application and AI Agent Developers to make the secure path the easy path, and communicates risk and progress clearly to both technical and executive stakeholders. Note: CRC is almost-exclusively a Microsoft Azure shop, so the ideal candidate will be able to demonstrate their competence and successes securing AI workloads in Microsoft Foundry and Azure API Management (APIM). Anthropic control experience is also highly-desirable.

Key Responsibilities

AI Security Leadership

  • Lead the AI Security function, including development and delivery of AI Security Service Offerings, reference architectures, operational runbooks, and a roadmap for continual improvement.
  • Partner with Cybersecurity Architects and Engineers, IT Infrastructure Engineers, and Application and AI Agent Developers to embed security into AI solutions from design through production.
  • Partner with Project and Program Management to ensure that we’re executing the right work with the right priorities.
  • Partner with GRC to keep AI use compliant with CRC policy and regulatory obligations (including NYDFS, among others), and to remediate any findings or observations.
  • Maintain the ability to quickly report on current state, risk posture, and progress maturing this space.

Agent Harness Security Patterns

  • Develop, publish, and maintain secure design patterns for AI agent harnesses, covering tool permissioning, sandboxing, human-in-the-loop approvals, memory and context handling, and safe failure modes.
  • Define guardrails against prompt injection (direct and indirect), tool misuse, excessive agency, data leakage, and model or supply-chain compromise, aligned to OWASP Top 10 for LLM Applications, OWASP Agentic AI guidance, and MITRE ATLAS.
  • Secure agents built on Microsoft Foundry (including Foundry Agent Service), and establish equivalent patterns for third-party harnesses such as Anthropic’s Claude Agent SDK.

AI Gateway & API Security

  • Engineer and operate Azure APIM and AI Gateway capabilities as the policy enforcement point for model, agent, MCP, and API traffic, including authentication, authorization, rate and token limits, content safety, logging, and routing.
  • Protect APIs consumed and exposed by agents with strong identity, schema validation, threat protection, and least-privilege access.
  • Integrate gateway telemetry with Microsoft Sentinel and Defender for Cloud for monitoring, detection, and response.

MCP & Agent-to-Agent (A2A) Security

  • Define and enforce standards for building, registering, and consuming MCP servers, including OAuth-based authorization, server allow-listing, tool and scope minimization, and supply-chain vetting.
  • Establish trust, authentication, and authorization models for A2A interactions, including agent identity, delegation boundaries, and auditability of multi-agent workflows.
  • Maintain an inventory of agents, MCP servers, and their connections so that exposure and blast radius are always known.

Identity & Secure Access

  • Design secure access to agents, MCP servers, APIs, and data using Microsoft Entra ID, managed identities, workload and agent identities, Conditional Access, and on-behalf-of flows.
  • Partner with the Data Security team to ensure agents only reach data they are entitled to, leveraging Microsoft Purview classification, DLP, and DSPM for AI.

Control Effectiveness & Assurance

  • Define measurable control objectives and KPIs, and continuously validate that AI security controls are working as intended.
  • Lead AI red teaming, adversarial testing, and threat modeling of agentic systems before and after production release.
  • Build detections and automated response for AI-specific threats, and continuously improve controls based on findings, incidents, and emerging threats.

Qualifications

Required:

  • 5+ years in Cybersecurity, with hands-on keyboard engineering and operational responsibilities.
  • Demonstrated experience developing security patterns for AI agent harnesses and their supporting components, including API and AI gateways.
  • Hands-on experience securing AI workloads in Microsoft Azure, including Microsoft Foundry.
  • Hands-on experience engineering and operating Azure API Management (APIM), including policy authoring.
  • Practical experience designing and validating security controls for AI agents, MCP servers, and A2A interactions.
  • Strong understanding of identity and access patterns for workloads and agents (OAuth 2.x, OIDC, Microsoft Entra ID, managed identities).
  • Working knowledge of AI-specific threats and frameworks such as OWASP Top 10 for LLM Applications, MITRE ATLAS, and NIST AI RMF.
  • Ability to communicate clearly with technical and executive stakeholders, adapting messaging to the audience.

Preferred:

  • Experience with Anthropic’s agent harness and related patterns (e.g., Claude Agent SDK, Claude Code, hooks, permissioning, and sub-agents).
  • Experience with Azure AI Content Safety / Prompt Shields, Defender for Cloud AI threat protection, and Microsoft Purview DSPM for AI.
  • Scripting or development proficiency in Powershell, Python, or other scripting, plus infrastructure-as-code (Terraform or Bicep) and KQL.
  • Familiarity or experience with AI red teaming tools such as PyRIT, Garak, or similar.
  • Microsoft certifications such as AZ-500, SC-100, or AI-102, or equivalent; AI security credentials (e.g., GIAC GOAA) a plus.
  • Familiarity with regulatory and governance frameworks such as NYDFS 23 NYCRR 500, ISO/IEC 42001, and NIST 800-53.
  • Experience in insurance or financial services.

Work Environment

  • Hybrid or on-site depending on organizational needs.
  • On-call rotation may be required for critical incident response.
  • Required flexibility to work nights, weekends and/or holiday shifts in the event of an incident response emergency.

Location: Charlotte, NC is the preferred location. However, we may be open to candidates in other locations based in the Eastern time zone.

General Description of Available Benefits for Eligible Employees of CRC Group: At CRC Group, we're committed to supporting every aspect of teammates' well-being - physical, emotional, financial, social, and professional. Our best-in-class benefits program is designed to care for the whole you, offering a wide range of coverage and support. Eligible full-time teammates enjoy access to medical, dental, vision, life, disability, and AD&D insurance; tax-advantaged savings accounts; and a 401(k) plan with company match. CRC Group also offers generous paid time off programs, including company holidays, vacation and sick days, new parent leave, and more. Eligible positions may also qualify for restricted stock units and/or a deferred compensation plan.

CRC Group supports a diverse workforce and is an Equal Opportunity Employer that does not discriminate against individuals on the basis of race, gender, color, religion, citizenship or national origin, age, sexual orientation, gender identity, disability, veteran status or other classification protected by law. CRC Group is a Drug Free Workplace.

EEO is the Law Pay Transparency Nondiscrimination Provision E-Verify

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
1,134,601 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

AI/ML
Similar stack
Same company
Charlotte
$180k – $210k per year • Hybrid • 8+ years exp • Bachelor's Degree • Chicago
Python
JavaScript
AI/ML
AI Agents
LLM
RAG
Hallucination
LLM Guardrails
DevOps
CI/CD
Windows
Apply
$118k – $176k per year • Equity • In office • Full-Time • 10+ years exp • High School Diploma • Fridley
Python
SQL
Databases
Snowflake
Databricks
AI/ML
Prompt Engineering
AI Agents
RAG
Streamlit
Machine Learning
DevOps
Prometheus
Cortex
Analytics
Power BI
Apply
$217k – $325k per year • Equity • In office • 8+ years exp • Bachelor's Degree • San Diego
AI/ML
Diffusion Models
Edge AI
QA
Rest-Assured
Apply
≈ $145k – $308k per year (Estimated) • In office • 8+ years exp • Milford
AI/ML
AI Agents
LLM
RAG
Machine Learning
DevOps
GCP
Azure
CI/CD
AWS
Platform Engineering
Apply
AI Architect 3 hours ago
≈ $154k – $318k per year (Estimated) • In office • 10+ years exp • Bachelor's Degree • Milford
Python
AI/ML
AI Agents
RAG
Semantic Search
Semantic Search
LLM Guardrails
Machine Learning
DevOps
GCP
Azure
AWS
Management
Agile
Apply
$85k – $107k per year • Hybrid • 4+ years exp • United States
Java
SQL
Java
Apache Tomcat
Databases
Oracle
DevOps
Azure
Windows
Cybersecurity
Microsoft Entra ID
Apply
Data Engineer 1 day ago
≈ $73k – $172k per year (Estimated) • In office • London
Python
SQL
Python
pySpark
Databases
Databricks
Delta Lake
AI/ML
Copilot
Spark
Claude Code
DevOps
Azure DevOps
Azure
CI/CD
Management
Agile
Apply
$120k – $203k per year • Hybrid • Full-Time • 8+ years exp • Toronto
Python
Go
JavaScript
Ruby
Databases
Databricks
DevOps
Splunk
Terraform
Puppet
Ansible
GCP
AWS CDK
Chef
CloudFormation
Datadog
Prometheus
Pulumi
Azure
CI/CD
ArgoCD
Jenkins
AWS
Kubernetes
Grafana
Spinnaker
Platform Engineering
Linux
Apply
$90k – $158k per year • In office • Full-Time • 10+ years exp • Burlington
Python
JavaScript
TypeScript
SQL
C#
Frontend
Angular
React.js
DevOps
GCP
Azure
AWS
Management
Agile
Scrum
Apply
≈ $92k – $180k per year (Estimated) • In office • Full-Time • Bachelor's Degree • London
Python
PowerShell
C#
C#
.NET
DevOps
Azure
CI/CD
Windows Server
Docker
Kubernetes
Platform Engineering
Windows
Cybersecurity
SonarQube
Apply
≈ $105k – $199k per year (Estimated) • Equity • In office • Full-Time • 6+ years exp • Bachelor's Degree • Charlotte • Morrisville • Dallas • Alpharetta
Python
Databases
Databricks
AI/ML
MLFlow
Machine Learning
DevOps
Azure DevOps
Azure
CI/CD
Management
Agile
Apply
Claims Supervisor 3 days ago
≈ $72k – $139k per year (Estimated) • Equity • In office • Full-Time • 5+ years exp • Bachelor's Degree • Flower Mound
Management
Microsoft Office
Apply
≈ $42k – $89k per year (Estimated) • Equity • In office • Full-Time • 1+ year exp • High School Diploma • Flower Mound
Management
Microsoft Office
Apply
≈ $34k – $58k per year (Estimated) • Equity • Remote (United States) • Full-Time • 2+ years exp • High School Diploma • Georgia • United States
Management
Outlook
Microsoft Office
Apply
≈ $36k – $82k per year (Estimated) • Equity • Remote (United States) • Full-Time • United States • Georgia
Apply
Trainer - CLT 1 day ago
≈ $61k – $164k per year (Estimated) • In office • High School Diploma • Charlotte
Apply
≈ $36k – $87k per year (Estimated) • In office • Full-Time • Charlotte
Apply
$70k – $154k per year • Remote (United States) • Full-Time • 5+ years exp • Bachelor's Degree • Chicago • Waterloo • Houston • Birmingham • Milwaukee
Management
Microsoft Office
Apply
$143k – $274k per year • Hybrid • Full-Time • 6+ years exp • Bachelor's Degree • San Antonio • Tampa • Charlotte • Colorado Springs • Plano
Python
SQL
AI/ML
Machine Learning
DevOps
AWS
Robotics
Path Planning
Apply
≈ $36k – $62k per year (Estimated) • Hybrid • Internship • 1+ year exp • High School Diploma • Charlotte
Management
Microsoft Office
Apply
See all jobs
This is one of many
1,134,601 more open roles from verified company boards, updated every day.