Principal AI Security Analyst

ActiveVerified 3h ago

Job description

Overview

As a Principal AI Security Analyst, you will be the organization's deepest subject-matter expert at the intersection of artificial intelligence and cybersecurity. You will lead the security review of AI/ML systems, manage our AI security toolchain, identify emerging threats unique to large-scale models, and build the frameworks that keep our AI infrastructure resilient against adversarial attacks. This is a high-visibility, high-autonomy role that shapes how the company thinks about AI risk.As a Principal AI Security Analyst, you will be the organization's deepest subject-matter expert at the intersection of artificial intelligence and cybersecurity. You will lead the security review of AI/ML systems, manage our AI security toolchain, identify emerging threats unique to large-scale models, and build the frameworks that keep our AI infrastructure resilient against adversarial attacks. This is a high-visibility, high-autonomy role that shapes how the company thinks about AI risk.As a Principal AI Security Analyst, you will be the organization's deepest subject-matter expert at the intersection of artificial intelligence and cybersecurity. You will lead the security review of AI/ML systems, manage our AI security toolchain, identify emerging threats unique to large-scale models, and build the frameworks that keep our AI infrastructure resilient against adversarial attacks. This is a high-visibility, high-autonomy role that shapes how the company thinks about AI risk.

As a Principal AI Security Analyst, you will be the organization's deepest subject-matter expert at the intersection of artificial intelligence and cybersecurity. You will lead the security review of AI/ML systems, manage our AI security toolchain, identify emerging threats unique to large-scale models, and build the frameworks that keep our AI infrastructure resilient against adversarial attacks. This is a high-visibility, high-autonomy role that shapes how the company thinks about AI risk.

As a Principal AI Security Analyst, you will be the organization's deepest subject-matter expert at the intersection of artificial intelligence and cybersecurity. You will lead the security review of AI/ML systems, manage our AI security toolchain, identify emerging threats unique to large-scale models, and build the frameworks that keep our AI infrastructure resilient against adversarial attacks. This is a high-visibility, high-autonomy role that shapes how the company thinks about AI risk.

Responsibilities

Own end-to-end threat modeling for AI and ML systems, including LLMs, training pipelines, and inference infrastructureAdminister and tune Palo Alto Networks AI Runtime Security (AIRS) to detect and block adversarial inputs, prompt injection, and model abuse in real timeManage AI Access Security policies to govern employee use of third-party AI applications — enforcing DLP, acceptable-use rules, and shadow-AI visibilityIntegrate an AI gateway layer to apply rate limiting, access controls, and observability across LLM API trafficResearch and operationalize defenses against adversarial attacks — model extraction, data poisoning, jailbreaking, and membership inferenceLead red-team exercises targeting AI systems and synthesize findings into actionable security roadmapsDefine and maintain security standards, policies, and controls specific to AI model development and deploymentPartner with ML engineering, platform, and product teams to embed security requirements from design through productionEvaluate third-party AI tools, APIs, and vendors for supply-chain and data-handling riskWork with other security team members in AI governance discussions, including compliance with EU AI Act and NIST AI RMFMentor other team members; set technical direction for the AI security practiceOwn end-to-end threat modeling for AI and ML systems, including LLMs, training pipelines, and inference infrastructureAdminister and tune Palo Alto Networks AI Runtime Security (AIRS) to detect and block adversarial inputs, prompt injection, and model abuse in real timeManage AI Access Security policies to govern employee use of third-party AI applications — enforcing DLP, acceptable-use rules, and shadow-AI visibilityIntegrate an AI gateway layer to apply rate limiting, access controls, and observability across LLM API trafficResearch and operationalize defenses against adversarial attacks — model extraction, data poisoning, jailbreaking, and membership inferenceLead red-team exercises targeting AI systems and synthesize findings into actionable security roadmapsDefine and maintain security standards, policies, and controls specific to AI model development and deploymentPartner with ML engineering, platform, and product teams to embed security requirements from design through productionEvaluate third-party AI tools, APIs, and vendors for supply-chain and data-handling riskWork with other security team members in AI governance discussions, including compliance with EU AI Act and NIST AI RMFMentor other team members; set technical direction for the AI security practiceOwn end-to-end threat modeling for AI and ML systems, including LLMs, training pipelines, and inference infrastructureAdminister and tune Palo Alto Networks AI Runtime Security (AIRS) to detect and block adversarial inputs, prompt injection, and model abuse in real timeManage AI Access Security policies to govern employee use of third-party AI applications — enforcing DLP, acceptable-use rules, and shadow-AI visibilityIntegrate an AI gateway layer to apply rate limiting, access controls, and observability across LLM API trafficResearch and operationalize defenses against adversarial attacks — model extraction, data poisoning, jailbreaking, and membership inferenceLead red-team exercises targeting AI systems and synthesize findings into actionable security roadmapsDefine and maintain security standards, policies, and controls specific to AI model development and deploymentPartner with ML engineering, platform, and product teams to embed security requirements from design through productionEvaluate third-party AI tools, APIs, and vendors for supply-chain and data-handling riskWork with other security team members in AI governance discussions, including compliance with EU AI Act and NIST AI RMFMentor other team members; set technical direction for the AI security practice
  • Own end-to-end threat modeling for AI and ML systems, including LLMs, training pipelines, and inference infrastructure
Own end-to-end threat modeling for AI and ML systems, including LLMs, training pipelines, and inference infrastructure
  • Administer and tune Palo Alto Networks AI Runtime Security (AIRS) to detect and block adversarial inputs, prompt injection, and model abuse in real time
Administer and tune Palo Alto Networks AI Runtime Security (AIRS) to detect and block adversarial inputs, prompt injection, and model abuse in real time
  • Manage AI Access Security policies to govern employee use of third-party AI applications — enforcing DLP, acceptable-use rules, and shadow-AI visibility
Manage AI Access Security policies to govern employee use of third-party AI applications — enforcing DLP, acceptable-use rules, and shadow-AI visibility
  • Integrate an AI gateway layer to apply rate limiting, access controls, and observability across LLM API traffic
Integrate an AI gateway layer to apply rate limiting, access controls, and observability across LLM API traffic
  • Research and operationalize defenses against adversarial attacks — model extraction, data poisoning, jailbreaking, and membership inference
Research and operationalize defenses against adversarial attacks — model extraction, data poisoning, jailbreaking, and membership inference
  • Lead red-team exercises targeting AI systems and synthesize findings into actionable security roadmaps
Lead red-team exercises targeting AI systems and synthesize findings into actionable security roadmaps
  • Define and maintain security standards, policies, and controls specific to AI model development and deployment
Define and maintain security standards, policies, and controls specific to AI model development and deployment
  • Partner with ML engineering, platform, and product teams to embed security requirements from design through production
Partner with ML engineering, platform, and product teams to embed security requirements from design through production
  • Evaluate third-party AI tools, APIs, and vendors for supply-chain and data-handling risk
Evaluate third-party AI tools, APIs, and vendors for supply-chain and data-handling risk
  • Work with other security team members in AI governance discussions, including compliance with EU AI Act and NIST AI RMF
Work with other security team members in AI governance discussions, including compliance with EU AI Act and NIST AI RMF
  • Mentor other team members; set technical direction for the AI security practice
Mentor other team members; set technical direction for the AI security practice

Qualifications

REQUIRED8+ years in cybersecurity with 3+ years focused on AI/ML securityHands-on experience with Palo Alto Networks AIRS or AI Access SecurityDeep understanding of LLM architectures and common vulnerability classesProficiency in Python; ability to review model code and ML pipelinesExperience with threat modeling frameworks (STRIDE, PASTA, or similar)Track record driving cross-functional security programs at scaleCloud-native environment experience (AWS, GCP, or Azure)PREFERREDPalo Alto Networks certifications (PCNSE, PCCSE, or equivalent)Experience deploying AI gateways (Portkey, Kong AI, or similar)Published research or CVEs related to AI/ML securityFamiliarity with differential privacy or model watermarkingCISSP, OSCP, or equivalent certificationsREQUIRED8+ years in cybersecurity with 3+ years focused on AI/ML securityHands-on experience with Palo Alto Networks AIRS or AI Access SecurityDeep understanding of LLM architectures and common vulnerability classesProficiency in Python; ability to review model code and ML pipelinesExperience with threat modeling frameworks (STRIDE, PASTA, or similar)Track record driving cross-functional security programs at scaleCloud-native environment experience (AWS, GCP, or Azure)PREFERREDPalo Alto Networks certifications (PCNSE, PCCSE, or equivalent)Experience deploying AI gateways (Portkey, Kong AI, or similar)Published research or CVEs related to AI/ML securityFamiliarity with differential privacy or model watermarkingCISSP, OSCP, or equivalent certificationsREQUIRED8+ years in cybersecurity with 3+ years focused on AI/ML securityHands-on experience with Palo Alto Networks AIRS or AI Access SecurityDeep understanding of LLM architectures and common vulnerability classesProficiency in Python; ability to review model code and ML pipelinesExperience with threat modeling frameworks (STRIDE, PASTA, or similar)Track record driving cross-functional security programs at scaleCloud-native environment experience (AWS, GCP, or Azure)PREFERREDPalo Alto Networks certifications (PCNSE, PCCSE, or equivalent)Experience deploying AI gateways (Portkey, Kong AI, or similar)Published research or CVEs related to AI/ML securityFamiliarity with differential privacy or model watermarkingCISSP, OSCP, or equivalent certifications

REQUIRED

REQUIREDREQUIRED
  • 8+ years in cybersecurity with 3+ years focused on AI/ML security
8+ years in cybersecurity with 3+ years focused on AI/ML security
  • Hands-on experience with Palo Alto Networks AIRS or AI Access Security
Hands-on experience with Palo Alto Networks AIRS or AI Access Security
  • Deep understanding of LLM architectures and common vulnerability classes
Deep understanding of LLM architectures and common vulnerability classes
  • Proficiency in Python; ability to review model code and ML pipelines
Proficiency in Python; ability to review model code and ML pipelines
  • Experience with threat modeling frameworks (STRIDE, PASTA, or similar)
Experience with threat modeling frameworks (STRIDE, PASTA, or similar)
  • Track record driving cross-functional security programs at scale
Track record driving cross-functional security programs at scale
  • Cloud-native environment experience (AWS, GCP, or Azure)
Cloud-native environment experience (AWS, GCP, or Azure)

PREFERRED

PREFERREDPREFERRED
  • Palo Alto Networks certifications (PCNSE, PCCSE, or equivalent)
Palo Alto Networks certifications (PCNSE, PCCSE, or equivalent)
  • Experience deploying AI gateways (Portkey, Kong AI, or similar)
Experience deploying AI gateways (Portkey, Kong AI, or similar)
  • Published research or CVEs related to AI/ML security
Published research or CVEs related to AI/ML security
  • Familiarity with differential privacy or model watermarking
Familiarity with differential privacy or model watermarking
  • CISSP, OSCP, or equivalent certifications
CISSP, OSCP, or equivalent certifications