Source description
About the role
Required Skills & Qualifications - Bachelors or Masters degree in Computer Science, Cybersecurity, or related field. - 5+ years of experience in Information Security with a focus on application and product security - Ability to evaluate AI security platforms/tools/software. - Solid understanding of: o Cloud and SaaS security models o Identity and access control concepts o Data protection and isolation mechanisms - Familiarity with modern AI system components: o LLM APIs and hosting models o Agent frameworks and tool invocation o RAG pipelines and vector stores - Understanding of GenAI and LLM-specific risks, including: o Prompt injection and indirect prompt injection o Insecure output handling o Model abuse and misuse o Data poisoning and supply-chain risk - Ability to translate AI-specific risks into enterprise security language for decision-makers. - Solid research and evaluation mindset - Ability to produce clear, defensible evaluation reports - Comfortable presenting trade-offs and risk-based recommendations - Ability to say not suitable with evidence, when required - Experience evaluating or approving third-party developer platforms or SaaS tools - Exposure to AI governance or AI risk management frameworks - Experience working with product, platform, or architecture review boards Scope of Responsibility - AI developer tools (e.g., coding assistants, copilots) - AI platforms and services (LLMs, GenAI APIs, agentic platforms, RAG frameworks) - Open-source AI tooling proposed for enterprise use Required Skills & Qualifications - Bachelors or Masters degree in Computer Science, Cybersecurity, or related field. - 5+ years of experience in Information Security with a focus on application and product security - Ability to evaluate AI security platforms/tools/software. - Solid understanding of: o Cloud and SaaS security models o Identity and access control concepts o Data protection and isolation mechanisms - Familiarity with modern AI system components: o LLM APIs and hosting models o Agent frameworks and tool invocation o RAG pipelines and vector stores - Understanding of GenAI and LLM-specific risks, including: o Prompt injection and indirect prompt injection o Insecure output handling o Model abuse and misuse o Data poisoning and supply-chain risk - Ability to translate AI-specific risks into enterprise security language for decision-makers. - Solid research and evaluation mindset - Ability to produce clear, defensible evaluation reports - Comfortable presenting trade-offs and risk-based recommendations - Ability to say not suitable with evidence, when required - Experience evaluating or approving third-party developer platforms or SaaS tools - Exposure to AI governance or AI risk management frameworks - Experience working with product, platform, or architecture review boards Scope of Responsibility - AI developer tools (e.g., coding assistants, copilots) - AI platforms and services (LLMs, GenAI APIs, agentic platforms, RAG frameworks) - Open-source AI tooling proposed for enterprise use