Our Client, a Research, Recruiting, Licensing, Education, Entrepreneurship company, is looking for an AI Security Analyst for their Remote location.
Responsibilities:
AI Security Analyst
Client IT provides AI services to 110K students, faculty, and staff for teaching, research, and university operations.
These services include Cloudforce's nebulaONE multi-model AI platform hosted in Microsoft Foundry, commercial LLM offerings such as Microsoft Copilot, ChatGPT EDU, Claude EDU, and Google Gemini Enterprise, connectors and plugins, an AI gateway (in procurement), and other associated components (e.g. MCP servers).
This position will be responsible for evaluating the security of the AI services to identify risks, recommending compensating controls and new security products, advising the teams on AI-specific security topics, and helping build
knowledge in secure AI practices.
Platform & integration risk evaluation
Evaluate new releases and capabilities across AI platforms and tools for security risks - including nebulaONE, the
ChatGPT/Claude/Gemini/Copilot EDU instances, and agentic AI platforms
Evaluate integrations, connectors, and plug-ins linking AI tools to university data sources such as Microsoft 365, enterprise systems, and enterprise databases
Assess agentic-specific risks - standing credentials, autonomous tool access, and data exfiltration by agents - as capabilities that warrant distinct scrutiny
Risk assessment & decision authority
Supply AI-specific threat expertise within the university's tiered AI risk assessment process
Recommend go/no-go decisions and escalate to Information Security's Director or Consulting and Architecture and CISO based on the scope, scale, and data sensitivity of the system
Advisory
Advise the AI team on security questions
Advise on AI architecture to ensure security is considered and integrated
Advise on security tooling to strengthen the AI ecosystem
Advise on vendor and third-party risk, including data processing agreements, SOC 2 reports, data residency, and sub-processors
Building leverage (scaling expertise beyond individual assessments)
Enhance AI security knowledge and advisory capabilities within the existing team.
Define reusable secure baselines and reference configurations for each AI platform so guidance can be applied without per-case involvement
Ground recommendations in recognized frameworks - NIST AI RMF, the OWASP Top 10 for LLMs, and MITRE ATLAS
Staying current
Track the evolving AI threat landscape - new attack techniques, platform changes, and emerging standards - and fold changes into assessments and baselines
Requirements:
Bachelor's degree in Cybersecurity, Computer Science, Engineering, or a related field, or equivalent experience.
3+ years of experience in cybersecurity, application security, cloud security, or related technical security roles.
Hands-on experience with AI/ML systems, LLM applications, or data pipelines.
Strong understanding of secure coding, authentication, authorization, API security, and cloud security.
Familiarity with adversarial ML concepts, model security, and AI risk management.
Preferred Qualifications
Experience securing generative AI applications, RAG systems, or model serving platforms.
Familiarity with frameworks and guidance such as OWASP Top 10 for LLM Applications, OWASP Top 10 for Agentic
Applications, NIST AI RMF, or MITRE ATLAS.
Working knowledge of at least two compliance frameworks: FERPA, HIPAA, NIST 800-53/800-171, or SOC 2.
Understanding of privacy, data governance, and regulatory considerations for AI.
Relevant certifications such as CISSP, GSEC, CSSLP, AWS Security Specialty, or similar.
Why Should You Apply?
Health Benefits
Referral Program
Excellent growth and advancement opportunities
Numbers & Facts
Location
CA
Skills
Access Authorizationunmatched
Amazon Web Services (AWS)unmatched
Application Programming Interface (API)unmatched
Applications Securityunmatched
Artificial Intelligence (AI)unmatched
Authenticationunmatched
CISSP - Certified Information Systems Security Professionalunmatched
Cloud Applicationsunmatched
Cloud Computingunmatched
Computer Scienceunmatched
Consultingunmatched
Data Processingunmatched
Ecosystemsunmatched
Entrepreneurshipunmatched
Family Educational Rights and Privacy Act (FERPA)unmatched