AI Security Analyst

JobgetherIndiaOn-siteFull-timeMid level, 2–5 yearsListed 49 minutes ago

Apply now

About this role

Accountabilities:

- Monitor enterprise AI usage across CASB, SWG, OAuth, endpoint, DLP, and other security telemetry to identify unauthorised AI applications, browser extensions, and API-based agents.

- Classify AI security findings according to risk and escalate unauthorised or potentially harmful deployments for investigation and containment.

- Investigate alerts involving autonomous agents and AI-powered workflows, including anomalous tool chains, unexpected data access, credential misuse, and emerging agent-based attack patterns.

- Document investigation findings and coordinate remediation with automation, identity, security operations, and engineering teams.

- Monitor AI usage and DLP logs for potential sensitive-data exfiltration through prompts, uploads, plugins, connectors, and other AI interfaces.

- Tune and validate AI-specific DLP and detection controls to ensure they operate effectively and identify relevant security risks.

- Monitor developer-facing AI tools for policy compliance, credential exposure, non-human identity risks, and other security concerns.

- Partner with engineering teams to establish and maintain appropriate security guardrails for code-assistance and agentic development tools.

- Maintain and validate AI activity logging, retention, and audit controls to ensure sufficient visibility and traceability.

- Collect, organise, and maintain evidence supporting AI security audits, ISO 42001 certification activities, AI impact assessments, and regulatory readiness initiatives.

- Analyse false-positive and false-negative trends and recommend improvements to detection thresholds, rules, and investigation logic.

- Identify recurring security patterns and contribute them to automation and security-response playbooks.

- Collaborate with Security Operations, Identity, Legal, AI/ML Engineering, and governance stakeholders to align findings with incident response and risk-management processes.

- Translate technical security findings into clear, risk-based narratives for governance forums, leadership, and executive reporting.

Requirements:

- 3–5+ years of experience in security analysis, SOC, GRC, or a closely related cybersecurity role.

- Working knowledge of SIEM platforms such as Splunk, Microsoft Sentinel, or Google Chronicle, as well as DLP and CASB technologies.

- Understanding of AI and LLM security risks, including prompt injection, AI-enabled data exfiltration, model or agent misuse, and shadow AI.

- Familiarity with non-human identity concepts, including service accounts, API keys, OAuth tokens, and their associated security risks.

- Understanding of threat detection methodologies and frameworks such as MITRE ATT&CK; exposure to MITRE ATLAS or the OWASP LLM Top 10 is strongly preferred.

- Ability to interpret security logs, API telemetry, and structured or unstructured investigation data.

- Basic scripting or query skills in Python, SQL, SPL, KQL, or comparable technologies for security investigations and reporting.

- Strong written documentation skills and the ability to communicate complex technical findings through clear, risk-based narratives.

- Familiarity with cloud environments such as AWS, Azure, or GCP.

- Demonstrated, hands-on AI security experience in at least one relevant area, such as AI/LLM risk testing, prompt-injection investigation, AI-specific data-exfiltration analysis, shadow AI discovery, CASB/SWG-based application discovery, non-human identity investigations, or agentic AI/MCP security.

- Practical experience should include a specific example of identifying a security issue, investigating its underlying cause, and contributing to an outcome or remediation.

- Exposure to agentic AI or MCP-based architectures from either a security or engineering perspective is valuable, including experience with technologies such as LangChain, AutoGen, CrewAI, or MCP servers.

- Hands-on exposure to AI governance frameworks such as ISO 42001, NIST AI RMF, or EU AI Act risk classifications is advantageous, particularly through audit evidence collection or control testing.

- Experience with security platforms such as Netskope, Zscaler, Wiz, Orca Security, Microsoft Purview, Abnormal Security, Bolster AI, or comparable technologies is a plus.

- Exposure to ML-based anomaly detection or NLP-driven log analysis is beneficial.

- Security certifications such as Security+, CISSP Associate, or relevant AI/ML security credentials are advantageous.

- Strong analytical, investigative, problem-solving, and cross-functional collaboration skills.

Benefits:

- Remote working opportunity from India.

- Opportunity to work at the intersection of cybersecurity, AI, governance, and emerging technology.

- Exposure to enterprise-scale AI security, threat detection, data protection, and identity-security challenges.

- Collaboration with multidisciplinary teams spanning security operations, engineering, identity, legal, automation, and governance.

- Opportunities to contribute to AI governance and compliance initiatives, including ISO 42001 and emerging AI regulatory requirements.

- Professional growth through hands-on work with evolving AI security technologies, frameworks, and attack patterns.

- Inclusive and collaborative working environment.

- Equal opportunity employment and reasonable accommodation for qualified individuals, in accordance with applicable requirements.

How Jobgether works:
We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.
We appreciate your interest and wish you the best!
 Why Apply Through Jobgether? 
 
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
 
 
#LI-CL1