You will own the firm's entire AI strategy in both directions: building the internal automation that makes our delivery team faster and better and building the client-facing AI security service lines (AI governance assessments and AI red-teaming) that don't exist in our portfolio today. You'll be the internal specialist whose full-time job is AI - not a mandate handed to already-stretched analysts.
KeyResponsibilities
- Internal tooling: Design and deploy AI-assisted workflows for reconnaissance, vulnerability prioritization, SOC alert triage/correlation, and draft report generation, with human validation built into every step.
- New service line - AI Governance & Risk Assessment: Build and deliver assessments against ISO/IEC 42001, the NIST AI Risk Management Framework, and EU AI Act risk-classification requirements for clients deploying AI systems.
- New service line - AI Red-Teaming: Design and run adversarial testing of client-deployed LLM systems and AI agents - prompt injection, data leakage, jailbreak resistance, and agentic-workflow abuse cases.
- Act as the internal champion and trainer for AI adoption across the delivery team - running hands-on enablement, not just issuing directives.
- Stay current on the fast-moving AI security threat and regulatory landscape and translate it into practical firm capability and client-facing offers.
- Partner with the Head of Security Operations & Delivery to ensure automation actually reduces delivery time and error rate, not just adds tooling overhead.
RequiredQualifications
- 3-6 years in cybersecurity (pentesting, security engineering, or SOC), with substantial hands-on experience applying AI/ML or LLM tooling to security workflows.
- Working understanding of at least one AI governance framework (ISO/IEC 42001, NIST AI RMF, or EU AI Act) - or demonstrated ability to get there fast.
- Practical experience with LLM application security concepts (prompt injection, jailbreaks, RAG/data-leakage risks, agent security).
- Comfortable building and shipping automation/scripts/tooling, not just using off-the-shelf products.
- Strong communicator - this role trains colleagues and pitches new services to clients.
Preferred
- Prior experience standing up a new service line or product inside a consulting/services business.
- A certification or credential relevant to AI governance (e.g., ISO 42001 Lead Implementer) or a track record of self-directed learning in the space.
- Familiarity with SOAR platforms or security automation frameworks.