AI Security Analyst
Skills
About the Role
You will monitor enterprise AI use, investigate unauthorized tools and rogue agents, and identify data-exfiltration risks. You will review telemetry and logs, tune detection rules, validate logging and retention controls, document findings, support audits, and communicate risk findings to relevant stakeholders.
Requirements
- 3–5+ years of experience in security analysis, SOC, or GRC analyst roles.
- Working knowledge of SIEM platforms and DLP/CASB tooling.
- Understanding of AI and LLM risks, including prompt injection, AI data exfiltration, model or agent misuse, and shadow AI.
- Familiarity with non-human identities, including service accounts, API keys, and OAuth tokens.
- Understanding of threat-detection logic and MITRE ATT&CK.
- Ability to read and interpret logs, API telemetry, and investigation data.
- Basic Python, SQL, SPL, or KQL proficiency.
- Strong written documentation and risk-based communication skills.
- Familiarity with AWS, Azure, or GCP.
Responsibilities
- Monitor telemetry to discover unsanctioned AI tools, browser extensions, and API-level agents.
- Classify AI tool findings by risk tier and escalate unauthorized deployments for containment.
- Investigate rogue-agent alerts, anomalous tool chains, unexpected data access, and credential misuse.
- Monitor DLP and AI usage logs for sensitive-data exfiltration through AI tools.
- Tune detection rules and validate AI-specific DLP controls.
- Monitor developer-facing AI tools for policy compliance, credential exposure, and non-human identity risk.
- Maintain and validate AI activity logging and data-retention controls.
- Assemble audit evidence for ISO 42001 audits, EU AI Act readiness, and internal AI impact assessments.
- Analyze detection false-positive and false-negative trends and recommend improvements.
- Partner with Security Operations, Identity, Legal, and AI/ML Engineering on incident response and risk reporting.
