AI Security Consulting Director

CNA

Chicago, Illinois

JOB DETAILS
SKILLS
Amazon Web Services (AWS), Analysis Skills, Applications Security, Artificial Intelligence (AI), Benchmarking, Best Practices, CCSP - Cisco Certified Security Professional, CISSP - Certified Information Systems Security Professional, Cloud Applications, Cloud Computing, Communication Skills, Computer Security, Consulting, Continuous Deployment/Delivery, Continuous Integration, Data Management, Data Modeling, Documentation, Documentation Review, Financial Services, GIAC - Global Information Assurance Certification, Industry Standards, Information/Data Security (InfoSec), Injections, Insurance, Leadership, Legal, Machine Learning, Machine Tool, Modeling Languages, Problem Solving Skills, Proof of Concept, Public Cloud, Regulatory Compliance, Request for Proposals (RFP), Risk, Risk Analysis, Risk Management, Security Analysis, Security Architecture, Security Consulting, Security Design, Security Monitoring, Software Development, Software Development Lifecycle (SDLC), Software Engineering, Systems Analysis, Technical Analysis, Technology Analysis, Testing, Threat Modeling, Threat and risk analysis (TRA), U.S. National Institute of Standards and Technology (NIST), Writing Skills
LOCATION
Chicago, Illinois
POSTED
8 days ago

You have a clear vision of where your career can go. And we have the leadership to help you get there. At CNA, we strive to create a culture in which people know they matter and are part of something important, ensuring the abilities of all employees are used to their fullest potential. 

The Consulting Director, AI Security is a hands-on technical contributor responsible for reviewing, evaluating, and validating AI initiatives across CNA’s enterprise. This role performs architecture and design reviews of AI, Machine Learning (ML), Generative AI (GenAI), Large Language Model (LLM), and agentic solutions; develops technology evaluation criteria for RFIs/RFPs; and tests and validates candidate solutions against security requirements. As part of the AI Governance review process, this role is a representative of the AI Security team and provides the technical security perspective on AI threats — focusing on the technical security assessment rather than governance, risk, or compliance functions, which are owned by dedicated teams. The specialist applies deep technical expertise to identify risks in AI systems and data pipelines and recommends practical controls and remediations, partnering closely with the AI Security team, Engineering, Cloud Security, Application Security, IAM, Data Security, and AI Governance.

JOB DESCRIPTION:

Essential Duties & Responsibilities 

  • Serve as the AI Security team’s technical reviewer within the AI Governance review process, providing the security perspective on AI threats and risks. 
  • Conduct architecture and design reviews of AI/ML, GenAI, LLM, and agentic initiatives, documenting findings, risks, and recommended controls. 
  • Write and maintain technology evaluation criteria for RFIs and RFPs covering AI security tooling and solutions. 
  • Test, validate, and benchmark candidate AI security solutions through proofs of concept and hands-on assessments. 
  • Perform threat modeling and security risk assessments of AI systems, models, and data pipelines. 
  • Evaluate AI workload security across cloud environments (AWS, Google Cloud) and recommend secure configurations. 
  • Apply industry standards and frameworks (e.g., NIST AI RMF, OWASP Top 10 for LLMs, MITRE ATLAS) to reviews and assessments. 
  • Contribute to AI security standards, reference architectures, and best-practice guidance. 
  • Support integration of AI security controls into SDLC, CI/CD, and DevSecOps workflows. 
  • Assist with vulnerability management, security monitoring, and incident readiness for AI systems. 
  • Provide technical security input to Risk, Legal, and AI Governance teams to support their compliance and regulatory work. 
  • Track emerging AI threats, attack techniques (e.g., prompt injection, data poisoning, model extraction), and defensive practices

Reporting Relationship 

Typically reports to Director or above. 

Skills, Knowledge & Abilities 

  • Strong working knowledge of AI/ML, GenAI, and LLM security concepts and common attack/defense techniques. 
  • Hands-on experience with security architecture and design reviews. 
  • Solid understanding of cloud security (AWS, Google Cloud) and secure cloud configurations. 
  • Familiarity with DevSecOps practices and secure software development. 
  • Ability to design and execute solution testing, proofs of concept, and technical validations. 
  • Ability to write clear evaluation criteria, technical assessments, and review documentation. 
  • Ability to translate technical risk into actionable recommendations. 
  • Strong analytical, problem-solving, and communication skills. 
  • Ability to work independently and manage multiple concurrent reviews. 

Education & Experience 

  • Bachelor’s Degree required; relevant technical disciplines preferred. 
  • 5+ years of information security experience, including exposure to cloud and AI/ML environments. 
  • Hands-on experience with public cloud security (AWS, Google Cloud). 
  • Relevant certifications preferred (CISSP, CCSP, GIAC, or AI/cloud security credentials). 
  • Insurance or financial services experience preferred. 

#LI-Hybrid

#LI-DM1

In certain jurisdictions, CNA is legally required to include a reasonable estimate of the compensation for this role. In District of Columbia,California, Colorado, Connecticut, Illinois,Maryland, Massachusetts, New York and Washington,the national base pay range for this job level is $97,000 to $189,000 annually. Salary determinations are based on various factors, including but not limited to, relevant work experience, skills, certifications and location. CNA offers a comprehensive and competitive benefits package to help our employees – and their family members – achieve their physical, financial, emotional and social wellbeing goals.  For a detailed look at CNA’s benefits, please visit cnabenefits.com.


CNA utilizes AI-enabled technology during the recruiting process. For more information, please visit our careers page.


CNA is committed to providing reasonable accommodations to qualified individuals with disabilities in the recruitment process. To request an accommodation, please contact 

leaveadministration@cna.com

About the Company

C

CNA

CNA's approach to research is a modern iteration of the Newtonian principle that complex, dynamic processes are best understood through direct observation of events and people. That was the methodology CNA analysts first applied in the 1940s when they pioneered the field of operations research by helping the Navy address the German U-boat threat. Not content to study the problem from afar, this small group of MIT scientists insisted on deploying with Navy forces in order to observe operations and collect the data needed for meaningful analyses. Their groundbreaking work, and the anti-submarine warfare equations it produced, set a standard for operations research methods that CNA has maintained for 75 years. Today, with more than 500 professionals at our headquarters and 50 researchers in the field, CNA still takes a multi-disciplinary, real-world approach to our work. On-site analysts carefully observe all aspects of a process—people, decisions, actions, consequences—and then collaborate with a headquarters-based research team to assess data and arrive at findings. CNA's objective, empirical research and analysis helps decision makers develop sound policies, make better-informed decisions, and manage programs more effectively. Our work, which in its early decades focused solely on defense-related matters, has grown to include investigation and analysis of a broad range of national security, defense, and public interest issues including education, homeland security and air traffic management. Through our Center for Naval Analyses and Institute for Public Research, we provide public-sector organizations with the tools they need to tackle the complex challenges of making government more efficient and keeping our country safe and strong.
COMPANY SIZE
100 to 499 employees
INDUSTRY
Other/Not Classified
FOUNDED
1940
WEBSITE
https://www.cna.org/