Job Summary: Skillset Needed: Experience
- Minimum 7 years of professional cybersecurity experience (engineering, security architecture, or security analyst).
- Demonstrated experience building security controls into software or AI/ML systems (secure SDLC, secure-by-design principles).
- Hands-on experience securing or assessing LLM / generative AI and agentic AI systems, including MCP (Model Context Protocol) servers, tool-calling, and agent-to-tool authorization.
- Experience assessing both in-house-developed AI which leverage COTS\open-source software for weaknesses.
- Python — proficiency for building security tooling, automation, and testing harnesses.
- Cloud platforms — hands-on security experience with at cloud providers (Azure, AWS, or Google Cloud Platform); ability to secure cloud-hosted AI workloads, identities, and data pipelines.
- Working knowledge of AI security frameworks and standards, specifically:
- OWASP Top 10 for LLM Applications
- MITRE ATLAS
- NIST AI Risk Management Framework (AI RMF)
- Understanding of core AI/ML attack surfaces: prompt injection, jailbreaks, data/model poisoning, model extraction, insecure output handling, excessive agency, and supply-chain risks.
- Strong foundational security domains: identity & access management, authentication/authorization (OAuth, fine-grained authZ), API security, encryption, and network