AI cybersecurity
Job Summary:
Establish and operationalize Threat Response capabilities to identify, detect, investigate, hunt, validate, and respond to threats targeting or leveraging AI systems, including enterprise GenAI, agentic AI, AI applications, models, data sources, identities, tools, and integrations.
The resource will leverage AI cybersecurity standards, baselines and best practices from NIST, OWASP and technology authorities to integrate AI cybersecurity into existing Threat Response capabilities rather than establish a separate AI security function. Must be capable of moving from threat research and architecture to doing hands-on implementation, testing, detection engineering, hunting, and operationalization.
WORK ACTIVITIES/CONTEXT:
- Define requirements for AI cybersecurity threat response leveraging OWASP and MITRE and develop an AI Threat Modeling capability.
- Pilot the AI cybersecurity threat modeling capability, monitoring emerging vulnerabilities, techniques, adversary behavior and known exploits to translate external threat intelligence into actionable tasks for SWA Technology teams.
- Develop a library of AI attack scenarios mapped to MITRE ATLAS for evaluation of the Adversary Emulation team and the Purple team.
- Define what telemetry and logging is needed to detect AI-specific cybersecurity threats and prioritize what information would be most helpful during event analysis and incident analysis.
- Develop an AI cybersecurity threat hunting capability, building AI-focused hunt playbooks and conducting the first initial hunts.
- Assess what information SWA has available to provide visibility across the attack scenarios and conduct a gap analysis.
- Partner with others to develop a plan for providing the additional telemetry and logging information needed to detect and analyze AI-specific cybersecurity threats.
- Prioritize AI threat detection use-cases leveraging an initial evaluation of cybersecurity risks for the company.
- Partner with the Operations team to engineer and operationalize detections using existing platforms, then tuning and validating the monitoring, detections and alerts.
- Establish reporting to measure AI cybersecurity threat detection coverage.
- Consult with the Threat Informed Defense team on Adversary Emulation aspects of detecting and validating AI attack scenarios.
- Participate in initial Purple Team exercises to confirm which detections are effective and which additional detections are needed for proper controls coverage and to improve the Purple Team methodology to be used for AI systems.
- Consult with the Incident Response team to ensure AI-specific runbooks and incident response procedures are in place and routinely improved, including special considerations for evidence gathering and forensics requirements.
- Provide content to the Threat Intelligence team that will be useful in the development of future Tabletop exercises.
- Facilitate requirement validation, prioritization, solution evaluation, and approval discussions with subject matter experts and leadership.
- Conduct an initial capability assessment to measure our organization s readiness against the new requirements and prioritize the improvements to invest in first to improve our capabilities / processes / tooling.
- Provide leadership with professional development education requirements to consider while planning what training their team members should complete to be able to properly understand and manage AI cybersecurity threat response.
- Provide a recommendation to leadership regarding work intake and process improvement aspects of incorporating AI cybersecurity threat response as part of our existing capabilities and processes.
- Contributes to the development and ongoing maintenance of roadmaps and durable operating capabilities, including ownership, maintenance, tuning, metrics, testing, and continuous improvement.
- Track changes in the AI threat landscape and recommend updates to monitoring standards, use cases, tools, and response playbooks
LICENSING/CERTIFICATION:
- Cybersecurity, cloud security, SIEM, incident response, detection engineering, or security architecture certification preferred, such as CISSP, CCSP, GIAC, AWS Certified Security Specialty, or relevant vendor certification.
- AWS AI Practitioner and AWS Cloud Practitioner certifications are preferred.
- AI cybersecurity certifications such as Advanced in AI Risk (AAIR), Advanced in AI Security Management (AAISM), CompTIA Sec AI+ or other completed AI training is preferred.