Senior Specialist - AI Security
Role details
Job location
Tech stack
Job description
- The Senior AI Security Risk Specialist will work under the responsibility of the Head of IS Services and Risk Management. The responsibilities of the role will be to conduct enhanced risk assessments on new AI solutions being implemented.
- Put Artificial Intelligence risks into simple words to be presented to the leadership team in the Operational Risk and Compliance Committee monthly
- Improve the current Security risk assessment methodology for complex AI systems
- Translating technical jargon and complex IT risks into business language is a must
- Support the business and IT stakeholders in completing risk assessments for their AI use case.
- Conduct in-depth technical assessments of AI solutions to identify security risks.
- Develop threat models for AI systems to anticipate and account for potential impacts due to misuse, abuse, or other adversarial attacks.
- Document all findings and develop mitigation strategies for identified risks, and coordinate with the project team or business partners to deploy countermeasures to reduce risk to systems and applications.
- Communicate progress on enhanced risk assessments performed to the AI Triage Group and AI Governance Working Group.
- Co-ordinate with the Data Privacy and Artificial Intelligence team, Innovation and Data Analytics team, Operational Risk team, Project teams and Business Functions to ensure all relevant input is provided when assessing risks.
- Prioritise enhanced risk assessment based on business value, project timelines and risk exposure.
- Ensure leadership is aware of key risks, potential threats, and if there are anticipated changes to ongoing projects.
- Produce reports and presentations that outline findings, explain risk positions, and recommend changes.
- Leverage research, industry trends, and internal data points to understand how AI systems could be abused and misused.
Requirements
Do you have experience in TensorFlow?, Do you have a Master's degree?, We are seeking a highly skilled expert in Security with good understanding of Artificial Intelligence, Machine Learning and AI red Teaming to join our Security Risk Management team. This role will focus on performing enhanced risk assessments of new projects and proof of concepts where artificial intelligence (AI) is being utilised and deemed to be a material risk to the company. The ideal candidate will have a robust background in Security, Risk management and be familiar with AI red teaming techniques. This position will require the ability to assess risks effectively and propose appropriate compensatory controls., You must have an IT background and a good understanding of Artificial Intelligence (LLM and Deep learning model development and deployment), * Fluent in English.
- Master's Degree in a Computer Science, Information Security, Statistics or related field with years of professional experience in Risk Management and/or Information Security
- Expert in synthesizing and clearly communicating complex information to all audiences up to C-Level leaders (Required)
- Demonstrated ability in artificial intelligence.
- Knowledge of AI red teaming
- Experience in articulating risks in business language and advising on the appropriate risk management action (Required)
- Excellent attention to detail and the ability to create clear, concise and engaging presentations breaking down difficult problems (Required)
- Knowledge of Information Security frameworks (Mitre ATT&CK, FAIR, NIST, ISO 2700X …) (Required)
- Expert analytical and reporting skills (Required)
- Excellent interpersonal and collaborative skills (Required)
- Expert in Microsoft Office (Word, Excel, PowerPoint, SharePoint) (Required)
- Experience in multinational companies (Required)
- Outstanding knowledge of Risk management (Required)
- Experience in information security management reporting and related methodologies (Preferred)
- Information Security and /or Information Technology industry certification (CISSP, CISM, or equivalent) (Preferred)
- Knowledge of Risk management frameworks is a plus (ISO 3100X, NIST 800-30/37/39, ENISA, EBIOS, OCTAVE, FAIR).
Desired Skills and Abilities:
- Experience in information security management reporting and related methodologies (Preferred)
- Effective knowledge of Information Security frameworks (Mitre ATT&CK, NIST, ISO 2700X …) (Preferred)
- Expertise in Python (Preferred)
Demonstrable experience with LLMs with understanding of AI/ML frameworks (PyTorch, TensorFlow, etc.) (Preferred)