About this role
Responsibilities • Conduct comprehensive cloud security assessments, evaluating designs, configurations, and implementations across major cloud service providers (CSPs) including AWS, Azure, and GCP. • Architect and drive enterprise-wide cloud security strategies, including baselines, guardrails, and secure design patterns for cloud-native and hybrid environments. • Identify and analyze potential security risks, vulnerabilities, and misconfigurations within cloud environments, AI/ML platforms, and applications. • Perform software architecture design reviews for cloud deployments, including AI/ML pipelines, LLM integrations, agentic frameworks, and data platforms. • Develop and enforce security controls for AI/ML systems, covering model security, data governance, prompt injection defenses, supply chain integrity, and inference infrastructure hardening. • Collaborate with AI engineering, platform, and development teams to embed security throughout the SDLC and CI/CD pipelines, including AI-specific development workflows. • Develop, evaluate, and document security measures, controls, and guardrails to protect data, applications, APIs, and infrastructure across cloud and AI environments. • Provide senior technical advisory services on cloud security, AI security, and security engineering to internal stakeholders, ensuring alignment with firm-wide security policies and industry best practices. • Develop and maintain scripts, automated solutions, and security tooling to streamline security processes, vulnerability identification, and compliance checks across cloud and AI environments. • Stay current on emerging threats across cloud, AI/ML, and security engineering domains, including adversarial ML techniques, cloud-native attack vectors, and evolving regulatory requirements. • Lead and mentor technical security teams; influence senior stakeholders and align security posture with business objectives. • Contribute to incident response and remediation efforts related to cloud security and AI security events as required. Qualifications Mandatory Requirements: • 12+ years of hands-on experience in cybersecurity, with depth spanning in the following domains: • Cloud Security: Architecting and assessing security for cloud-native and hybrid environments across major CSPs (AWS, Azure, GCP, OCI). • Security Engineering: Building security tooling, automation, detection capabilities, or secure-by-design systems at scale. • AI Engineering Security: Securing AI/ML systems, LLM-based applications, agentic pipelines, or ML infrastructure. • Cybersecurity Generalist: Broad cross-domain expertise including network security, identity and access management, threat modeling, vulnerability management, incident response, and compliance.
• Strong development and scripting proficiency (Python, PowerShell, Bash, or similar) for automation, security tooling, and data analysis. • Deep, demonstrated knowledge of cloud security architecture across at least one major CSP (AWS strongly preferred), including IAM, network security, encryption/key management, workload/container security, and monitoring/logging. • Technical expertise in application security architecture, including secure-by-design patterns, threat modeling, and enterprise AppSec standards for web, API, and microservices environments. • Proven experience securing AI/ML systems or platforms, including familiarity with threats specific to LLMs, model pipelines, and AI supply chains. • Proven track record driving security initiatives across large, complex enterprise environments with cross-functional impact. Preferred Qualifications: • Experience in financial services or other highly regulated industries, with familiarity with relevant compliance frameworks. • Advanced knowledge of industry security frameworks and standards (e.g., NIST AI RMF, NIST CSF, ISO 27001, CIS Benchmarks, MITRE ATLAS, OWASP LLM Top 10). • Familiarity with AI/ML security frameworks including OWASP LLM Top 10, MITRE ATLAS, and NIST AI Risk Management Framework. • Strong leadership and communication skills to influence at the executive level, mentor technical teams, and represent security in cross-functional forums. • Relevant certifications across security and cloud domains (e.g., CISSP, CCSP, AWS Certified Security – Specialty, Azure Security Engineer Associate, Google Cloud Professional Cloud Security Engineer, GIAC certifications). • Experience with MLOps, model deployment pipelines, and AI platform security (e.g., SageMaker, Vertex AI, Azure ML, Databricks). • Hands-on experience with red teaming, or adversarial testing of AI/ML systems.