xelys jobs xelys jobs

AI Security Engineer

ISC2

midpermanentsecuritybackend United States 7 days ago via LinkedIn

See how well this job matches your profile

Sign up to get an AI match score and generate a tailored application in seconds.

Get your match score

Tags

AI SecurityLLM SecurityThreat ModelingAdversarial TestingPrompt InjectionAI-SDLCISO/IEC 27001:2022NIST AI RMFOWASP Top 10 for LLMsSupply Chain Risk

About the role

Role Overview

The AI Security Engineer identifies, assesses, and mitigates security risks introduced by AI/ML systems across ISC2’s technology estate. The role focuses on AI/ML pipelines, LLM integrations, and AI-powered products/services, spanning offensive security, application security, and data science.

Responsibilities

  • Perform security assessments of AI/ML systems using threat modeling, adversarial testing, and LLM security evaluations.
  • Assess vulnerabilities such as:
    • Prompt injection and jailbreaking
    • Model inversion
    • Data poisoning
    • Membership inference
    • Adversarial example attacks
  • Define and implement secure AI development lifecycle (AI-SDLC) standards, including:
    • Secure model training
    • Data governance
    • Agent and access controls
    • Deployment guardrails
  • Conduct third-party AI vendor and model supply chain risk assessments.
  • Evaluate API-based AI services (e.g., OpenAI, Anthropic, Claude Code, Azure OpenAI) for data handling, privacy, and security posture.
  • Partner with engineering and product teams on:
    • AI feature design reviews
    • Pre-deployment security reviews
    • Risk acceptance recommendations for AI-related SSDLC exceptions
  • Monitor the AI threat landscape and stay current on:
    • EU AI Act
    • NIST AI RMF
    • OWASP Top 10 for LLMs
    • MITRE ATLAS
  • Support ISC2’s ISO/IEC 27001:2022 ISMS by mapping AI risk controls to Annex A (A.8.25–A.8.29) and contributing AI-specific risk treatment plans to the risk register.
  • Develop and deliver internal training on responsible AI use and AI-specific threats for developers and stakeholders.
  • Contribute to AI security thought leadership via content, certification, and research initiatives.

Requirements

  • Strong security assessment and threat modeling skills for AI/ML and LLM-based systems.
  • Ability to evaluate and mitigate AI-specific vulnerabilities (e.g., prompt injection, jailbreaks, inference attacks, poisoning).
  • Experience defining secure AI/ML development lifecycle and deployment guardrails.
  • Knowledge of AI supply chain risk and third-party AI/API security assessment.
  • Familiarity with governance frameworks and standards (ISO/IEC 27001:2022, EU AI Act, NIST AI RMF) and industry references (OWASP Top 10 for LLMs, MITRE ATLAS).

Notes

  • This position is not available to residents of California.

About ISC2

ISC2 (International Information System Security Certification Consortium) is a nonprofit member organization for cybersecurity professionals. It supports cyber safety through globally recognized certifications and education initiatives, including the Center for Cyber Safety and Education.

Scraped 8/3/2026