Cybersecurity - AI Cybersecurity Architect & Engineer - Consulting - Location OPEN
Location: Anywhere in Country
About the role
The AI Cybersecurity Architect & Engineer is a hybrid technical leadership role responsible for designing, building, and defending AI systems as first-class assets — while simultaneously leveraging AI to deliver next-generation cyber defense capabilities. This individual sits at the intersection of cybersecurity engineering, machine learning, and agentic AI, protecting models, data pipelines, prompts, agents, integrations, and the infrastructure that hosts them, while also using AI offensively (from a defensive standpoint) to match the speed and sophistication of Frontier AI-enabled attacks.
This role is critical as organizations face a fundamental shift in the threat landscape: Frontier AI models can now autonomously discover and weaponize zero-day vulnerabilities in hours, AI-generated polymorphic malware evades signature-based detection, and autonomous AI worms spread laterally adapting tactics per-target. Defenders need an equally capable AI-augmented security posture — built and operated by professionals who understand both domains deeply.
Responsibilities
- AI Security Architecture & Design
- Design end-to-end secure architectures for AI/ML systems, including LLM applications, agentic AI workflows, RAG pipelines, vector databases, and model serving infrastructure.
- Establish threat models for AI systems using MITRE ATLAS, OWASP Top 10 for LLM Applications, OWASP Agentic Security Initiative (ASI) Top 10, and CSA MAESTRO 7-layer framework.
- Define secure-by-design patterns for AI agent permissions, tool invocation, memory/context isolation, and inter-agent communication (Model Context Protocol, Agent2Agent).
- Architect zero-trust controls for AI training pipelines, model registries, embedding stores, and prompt template repositories.
- Develop reference architectures for integrating GenAI capabilities into enterprise security platforms (CrowdStrike NGSIEM, Microsoft Sentinel, ServiceNow SIR / Now Assist, Splunk).
- AI-Driven Cyber Defense Engineering
- Build and operationalize AI-augmented detection, triage, and response capabilities — including LLM-assisted alert enrichment, autonomous incident summarization, and AI-driven threat hunting.
- Engineer agentic SOC workflows that integrate ServiceNow AI Agents, NVIDIA NIM, OpenAI / Anthropic models, and custom ML models with SIEM / SOAR / XDR platforms.
- Develop detections for AI-specific TTPs: prompt injection, jailbreak, model extraction, training data poisoning, agent hijacking, MCP server tampering, and rogue agent behavior.
- Build behavioral baselines and anomaly detection for AI agent activity, API call patterns, and inter-agent communications.
- Design and deploy AI-specific deception (decoy MCP servers, poisoned data traps, decoy LLM-accessible resources).
- Threat Defense Against Frontier AI Attacks
- Lead red-team and adversarial testing of AI systems — prompt injection, jailbreaks, model extraction, membership inference, training data extraction, and adversarial examples.
- Defend against AI-generated polymorphic malware, deepfake vishing / social engineering, AI-orchestrated multi-stage attacks, and autonomous AI worms.
- Build defenses against AI-driven vulnerability discovery — including reachability / exploitability validation, compensating controls frameworks, and AI-speed patching workflows.
- Develop containment playbooks for rogue AI agents, compromised LLM integrations, and AI-driven cascading failures.
- Operate within the MLSecOps lifecycle: threat modeling, supply chain defense, model assurance, runtime defense, observability / IR, and governance.
- Governance, Risk & Compliance for AI
- Implement AI governance frameworks (NIST AI RMF, ISO/IEC 42001, EU AI Act readiness) for enterprise AI deployments.
- Build AI risk assessment methodologies — data provenance, model lineage, prompt template management, third-party AI vendor risk.
- Establish AI usage policies, Shadow AI detection capabilities, and DLP controls for GenAI tool usage.
- Partner with privacy, legal, and compliance teams on AI-specific regulatory requirements.
- Define and track AI security KPIs: prompt injection block rate, AI-generated phishing detection rate, agent permission drift, model integrity validation.
- Client Advisory & Practice Leadership
- Lead Frontier AI readiness assessments for client organizations across SOC, incident response, vulnerability management, identity, and data protection.
- Develop client-facing deliverables: solution architectures, executive summaries, technical roadmaps, and one-pagers.
- Contribute to thought leadership: whitepapers, client workshops, industry conference presentations.
- Mentor junior engineers and consultants on AI security topics; build internal AI security competency.
- Partner with alliance teams (ServiceNow, CrowdStrike, Microsoft, NVIDIA, OpenAI / Anthropic) on joint solutions and go-to-market motions.
Requirements
- Experience
- 8+ years of progressive experience in cybersecurity engineering or architecture.
- 3+ years of hands-on experience with AI / ML systems — either building, securing, or red-teaming.
- Demonstrated experience designing secure architectures for production AI workloads (LLM applications, agentic systems, ML pipelines).
- Proven track record leading complex security projects in regulated industries (financial services, healthcare, energy, government).
- Technical Skills — Cybersecurity Core
- Deep expertise in security architecture: zero trust, defense in depth, least privilege, secure SDLC.
- Strong working knowledge of SIEM / SOAR / XDR platforms (CrowdStrike Falcon / NGSIEM, Microsoft Sentinel, Splunk, ServiceNow SecOps).
- Hands-on experience with cloud security (AWS, Azure, GCP) — IAM, network controls, container / Kubernetes security, secrets management.
- Familiarity with detection engineering (Detection-as-Code, Sigma, KQL, EQL, YARA).
- Incident response and forensics fundamentals; comfort with MITRE ATT&CK and MITRE ATLAS frameworks.
- Technical Skills — AI / ML
- Working knowledge of neural network architectures (transformers, CNNs, RNNs), training / optimization, inference / deployment.
- Hands-on experience with LLM application development (prompt engineering, RAG, fine-tuning, function calling).
- Experience with AI orchestration frameworks (LangChain, LlamaIndex, Semantic Kernel, AutoGen) and agentic patterns.
- Understanding of vector databases (Pinecone, Chroma, Weaviate), embedding models, and inference infrastructure.
- Familiarity with model serving platforms (NVIDIA NIM, Triton, TorchServe, vLLM).
- Proficiency in Python; familiarity with PyTorch and/or TensorFlow.
- Technical Skills — AI Security Specific
- Strong understanding of OWASP Top 10 for LLM Applications and OWASP Agentic Security Initiative threats.
- Hands-on experience with MITRE ATLAS adversarial techniques.
- Knowledge of prompt injection (direct, indirect, triggered), jailbreaks, model extraction, training data poisoning, and adversarial examples.
- Experience with AI red-teaming tools (e.g., Garak, PyRIT, promptfoo) and LLM security testing methodologies.
- Understanding of differential privacy, federated learning, and secure multi-party computation (preferred).
Qualifications
- Master's degree in Computer Science, Cybersecurity, AI / ML, or a related field (preferred).
- Experience implementing or auditing AI governance (NIST AI RMF, ISO/IEC 42001, EU AI Act).
- Contributions to OWASP GenAI Security Project, MITRE ATLAS, MLSecOps Community, or similar.
- Published research, conference talks (RSA, Black Hat, DEF CON AI Village, BSides), or thought leadership in AI security.
- Experience with consulting / client advisory engagements.
- Familiarity with EY's Cyber Practice methodologies, ServiceNow alliance solutions, and CrowdStrike / Microsoft Security alliance offerings.
Skills
- Translates complex AI security concepts into business-impact language for CISOs and boards.
- Comfortable working in ambiguity at the leading edge of an emerging discipline.
- Strong written communication for client deliverables (slide decks, executive summaries, architecture diagrams).
- Collaborative orientation across security, data science, ML engineering, and business stakeholder teams.
- Continuous learner — actively tracks emerging Frontier AI threats and defensive research.
Certifications
One or more of the following preferred:
- CISSP, CISSP-ISSAP, or CCSP.
- AWS Certified Security – Specialty, Azure Security Engineer (AZ-500), or Google Professional Cloud Security Engineer.
- AI / ML-specific: Certified AI Security Professional (CAISP), AI Cybersecurity Specialist certification.
- MLOps / MLSecOps certifications.
- Vendor: CrowdStrike Certified Falcon Administrator / Responder, Microsoft Security Operations Analyst (SC-200), ServiceNow Certified Implementation Specialist – Security Operations.
What Success Looks Like (first 12 Months)
- Designed and delivered 2–3 production-grade AI security architectures for enterprise clients.
- Established baseline AI security controls (prompt injection defense, agent permission framework, AI inventory) for internal practice or major client.
- Built or extended a Frontier AI readiness assessment methodology used across the practice.
- Published or presented at least one piece of external thought leadership on AI cybersecurity.
- Mentored 3–5 junior team members on AI security capabilities.
Pay
Salary range (US, role-dependent): $185,000 –