Design and implement security controls for AI systems, LLMs, and autonomous agents, protecting them against emerging threats such as prompt injection, jailbreaks, tool abuse, and data exfiltration. The role combines traditional cybersecurity with specialized AI/LLM security practices.
Responsibilities:
- Design AI security architecture and conduct AI-specific threat modeling.
- Implement defenses against prompt injection, jailbreaks, and agent tool abuse.
- Define AI identity, authentication, authorization, and access controls.
- Conduct AI security testing, adversarial testing, and red-team exercises.
- Perform AI privacy reviews covering PII, prompts, outputs, and logs.
- Partner with AI Governance and Platform Engineering to strengthen security posture.
- Communicate AI-specific risks and vulnerabilities to security leadership.
- Identify and remediate vulnerabilities and emerging AI threats.
- Train delivery teams on AI security best practices and threat patterns.
Qualifications:
- 5+ years of cybersecurity/AppSec experience, including 2+ years in AI/LLM/Agent Security.
- Strong knowledge of LLM and agent security threats, including prompt injection, jailbreaking, and data exfiltration.
- Strong foundation in IAM, network security, secure SDLC, and application security.
- Experience with AI/LLM security testing and adversarial testing tools.
- Familiarity with Azure AI Foundry Prompt Shields/content filtering, AWS Bedrock Guardrails, and Google Vertex AI safety controls.
- Knowledge of open-source AI security tools such as NeMo Guardrails and Rebuff is a plus.
- Strong understanding of AI privacy, data protection, and security risk management.
- Experience conducting AI red-team exercises.
- Strong communication and stakeholder-management skills.
- Ability to stay updated on emerging AI security threats and vulnerabilities.