Back to Jobs

AI Product Owner — Security Principal Architect

Ulta Beauty

Job Description & Details

This is a high-impact architecture role at Ulta Beauty where you'll essentially write the rulebook for how the company adopts AI safely and securely. If you enjoy bridging the gap between cutting-edge generative AI and enterprise-grade security without slowing down engineering momentum, this is worth a look.

What You'll Actually Be Doing

Your day-to-day will revolve around defining reference architectures, reviewing new AI initiatives for risk, and designing enterprise-grade patterns for AI guardrails and LLM output validation. You won't be writing the application code yourself, but you'll be the technical authority guiding the AI engineering and data platform teams. Expect to spend a lot of time collaborating with enterprise architecture and infrastructure folks to bake least-privilege access, zero-trust principles, and data governance directly into their cloud and SaaS AI deployments.

The Core Tech Stack

You need a rock-solid foundation in cloud security architecture—specifically across AWS, Azure, or GCP—alongside a deep technical understanding of MLOps, data pipelines, and model training/serving mechanics. Because this role tackles modern generative AI challenges, you'll need working knowledge of the OWASP LLM Top 10, NIST AI RMF, and ISO/IEC 42001 frameworks. It's not just about knowing these standards on paper, but actually knowing how to map them to real-world architectures involving LLMs and agentic AI systems.

Interview Expectations

You will likely be asked to walk through a scenario where a business unit wants to deploy a third-party generative AI agent with direct access to customer data, and the hiring manager will want to hear how you design the guardrails, output validation, and identity boundaries for it. They're secretly testing whether you can say 'yes' securely rather than just acting as a roadblock. Another common line of questioning will focus on your experience mitigating prompt injection or data exfiltration risks in production MLOps pipelines, so be ready to pull from real-world battle scars.

Application Advice

To get past the automated screens, make sure your resume explicitly highlights keywords like 'AI security', 'OWASP LLM Top 10', 'zero-trust', and specific cloud platforms like Azure or AWS. Don't just list traditional security architectures; explicitly frame your past experience around securing data platforms, ML lifecycles, or generative AI deployments. If you have retail or large enterprise consumer-brand experience, put that front and center to show you understand scale.