Jobgether
AI Security Analyst
engineeringfull-timeIndia
SALARY
Not listed
WORK TYPE
remote
JOB TYPE
full-time
INDUSTRY
general
✦ AutoApply Sick of applying? We apply to roles like this for you, up to 20 a month.
Learn more
About the role
Accountabilities:
- Monitor enterprise AI usage across CASB, SWG, OAuth, endpoint, DLP, and other security telemetry to identify unauthorised AI applications, browser extensions, and API-based agents.
- Classify AI security findings according to risk and escalate unauthorised or potentially harmful deployments for investigation and containment.
- Investigate alerts involving autonomous agents and AI-powered workflows, including anomalous tool chains, unexpected data access, credential misuse, and emerging agent-based attack patterns.
- Document investigation findings and coordinate remediation with automation, identity, security operations, and engineering teams.
- Monitor AI usage and DLP logs for potential sensitive-data exfiltration through prompts, uploads, plugins, connectors, and other AI interfaces.
- Tune and validate AI-specific DLP and detection controls to ensure they operate effectively and identify relevant security risks.
- Monitor developer-facing AI tools for policy compliance, credential exposure, non-human identity risks, and other security concerns.
- Partner with engineering teams to establish and maintain appropriate security guardrails for code-assistance and agentic development tools.
- Maintain and validate AI activity logging, retention, and audit controls to ensure sufficient visibility and traceability.
- Collect, organise, and maintain evidence supporting AI security audits, ISO 42001 certification activities, AI impact assessments, and regulatory readiness initiatives.
- Analyse false-positive and false-negative trends and recommend improvements to detection thresholds, rules, and investigation logic.
- Identify recurring security patterns and contribute them to automation and security-response playbooks.
- Collaborate with Security Operations, Identity, Legal, AI/ML Engineering, and governance stakeholders to align findings with incident response and risk-management processes.
- Translate technical security findings into clear, risk-based narratives for governance forums, leadership, and executive reporting.
- 3–5+ years of experience in security analysis, SOC, GRC, or a closely related cybersecurity role.
- Working knowledge of SIEM platforms such as Splunk, Microsoft Sentinel, or Google Chronicle, as well as DLP and CASB technologies.
- Understanding of AI and LLM security risks, including prompt injection, AI-enabled data exfiltration, model or agent misuse, and shadow AI.
- Familiarity with non-human identity concepts, including service accounts, API keys, OAuth tokens, and their associated security risks.
- Understanding of threat detection methodologies and frameworks such as MITRE ATT&CK; exposure to MITRE ATLAS or the OWASP LLM Top 10 is strongly preferred.
- Ability to interpret security logs, API telemetry, and structured or unstructured investigation data.
- Basic scripting or query skills in Python, SQL, SPL, KQL, or comparable technologies for security investigations and reporting.
- Strong written documentation skills and the ability to communicate complex technical findings through clear, risk-based narratives.
- Familiarity with cloud environments such as AWS, Azure, or GCP.
- Demonstrated, hands-on AI security experience in at least one relevant area, such as AI/LLM risk testing, prompt-injection investigation, AI-specific data-exfiltration analysis, shadow AI discovery, CASB/SWG-based application discovery, non-human identity investigations, or agentic AI/MCP security.
- Practical experience should include a specific example of identifying a security issue, investigating its underlying cause, and contributing to an outcome or remediation.
- Exposure to agentic AI or MCP-based architectures from either a security or engineering perspective is valuable, including experience with technologies such as LangChain, AutoGen, CrewAI, or MCP servers.
- Hands-on exposure to AI governance frameworks such as ISO 42001, NIST AI RMF, or EU AI Act risk classifications is advantageous, particularly through audit evidence collection or control testing.
- Experience with security platforms such as Netskope, Zscaler, Wiz, Orca Security, Microsoft Purview, Abnormal Security, Bolster AI, or comparable technologies is a plus.
- Exposure to ML-based anomaly detection or NLP-driven log analysis is beneficial.
- Security certifications such as Security+, CISSP Associate, or relevant AI/ML security credentials are advantageous.
- Strong analytical, investigative, problem-solving, and cross-functional collaboration skills.
- Remote working opportunity from India.
- Opportunity to work at the intersection of cybersecurity, AI, governance, and emerging technology.
- Exposure to enterprise-scale AI security, threat detection, data protection, and identity-security challenges.
- Collaboration with multidisciplinary teams spanning security operations, engineering, identity, legal, automation, and governance.
- Opportunities to contribute to AI governance and compliance initiatives, including ISO 42001 and emerging AI regulatory requirements.
- Professional growth through hands-on work with evolving AI security technologies, frameworks, and attack patterns.
- Inclusive and collaborative working environment.
- Equal opportunity employment and reasonable accommodation for qualified individuals, in accordance with applicable requirements.
Requirements:
Benefits:
✦ Sick of applying to 40 jobs a month?
I rewrite your resume for ATS by hand first. Once you sign off on it, AutoApply applies to up to 20 roles like this a month, cover letter in your own voice each time. From $14.99/mo, cancel anytime.
Get AutoApply