Engineering, Cybersecurity, Application Security Engineer, Vice President
TPG
- Location
- Fort Worth, Texas, United States
- Work model
- On-Site
- Level
- Staff
- Posted
- 1h ago
Skills
About this role
About TPG
TPG is a leading global alternative asset management firm, founded in San Francisco in 1992, has investment and operational teams around the world. TPG invests across a broadly diversified set of strategies, including private equity, impact, credit, real estate, and market solutions, and our unique strategy is driven by collaboration, innovation, and inclusion. Our teams combine deep product and sector experience with broad capabilities and expertise to develop differentiated insights and add value for our fund investors, portfolio companies, management teams, and communities.
TPG’s success depends on our people, and we build and sustain our world-class team by creating an inclusive, supportive culture within the firm that seeks excellence and encourages humility and transparency. The quality of our investments and our ability to build great companies depend on the originality of our insights. Reaching our firm’s full potential means supporting every team member to bring the fullness of their unique perspective to their work and to our community. We are committed to a diverse, equitable, and inclusive workplace to foster diversity of thought and reflect the breadth of our limited partners and portfolio companies.
Description of Position
TPG has an exciting opportunity for a senior application security professional to help secure the firm’s software and AI systems. The number one focus of this role is the secure development and operation of agentic AI. TPG’s Cybersecurity team protects the firm’s applications, data, and clients across a fast-moving technology landscape. As the firm expands its use of generative and agentic AI, we are building application security expertise to ensure these systems are designed, deployed, and operated securely. This is a hands-on, high-impact role for a senior practitioner who enjoys partnering directly with software engineers and embedding security into how products are built.
Principal Responsibilities
• Serve as the firm’s subject-matter expert on agentic AI development — partnering with engineering teams to securely design, build, and operate AI agents, autonomous workflows, and tool-using LLM applications
• Identify and help remediate AI-specific risks such as prompt injection (direct and indirect), jailbreaking, insecure tool and function calling, excessive agency, memory and context poisoning, model and data leakage, and emergent privilege escalation across multi-step agentic workflows
• Establish security controls and guardrails for generative and agentic AI workloads, including the Model Context Protocol (MCP), agent frameworks, retrieval-augmented generation (RAG) pipelines, and the data sources and tools agents can access
• Partner with developers to secure authentication and authorization processes, including the design and review of identity flows, session management, secrets handling, and least-privilege access across applications and AI systems
• Review code scan analysis exception requests — evaluating SAST, DAST, SCA, and related findings, validating risk acceptance rationale, and making well-documented decisions that balance security with business needs
• Define and document SDLC, identity, and authentication best practices for developers, and create clear, practical guidance that makes secure development easier to adopt
• Review existing application stacks against security best practices, identify gaps, and work with development teams to define, prioritize, and track remediation plans
• Perform threat modeling and secure design reviews early in the development lifecycle to identify weaknesses before code is written
• Embed security controls into CI/CD pipelines and agentic delivery workflows, integrating automated testing and policy enforcement
• Apply recognized AI and application security