Source description
About the role
Required Skills & Qualifications 5+ years of experience in Information Security with a focus on application and product security Ability to evaluate AI security platforms/tools/software. Solid understanding of: o Cloud and SaaS security models o Identity and access control concepts o Data protection and isolation mechanisms Familiarity with modern AI system components: o LLM APIs and hosting models o Agent frameworks and tool invocation o RAG pipelines and vector stores Understanding of GenAI and LLM-specific risks, including: o Prompt injection and indirect prompt injection o Insecure output handling o Model abuse and misuse o Data poisoning and supply-chain risk Ability to translate AI-specific risks into enterprise security language for decision-makers. Strong research and evaluation mindset Ability to produce clear, defensible evaluation reports Comfortable presenting trade-offs and risk-based recommendations Ability to say “not suitable” with evidence, when required Experience evaluating or approving third-party developer platforms or SaaS tools Exposure to AI governance or AI risk management frameworks Experience working with product, platform, or architecture review boards Key Outputs (What This Team Delivers) AI Security Evaluation Reports (per tool/platform) Approved / Restricted / Disallowed AI Technology List Business/IT-Facing Guidance on AI Tool Usage
More at H&R Block