AI Threat Modelling Specialist
Brak informacji o wynagrodzeniu
MidFull-time
#425130·Dodano 24 dni temu·5
Źródło: nofluffjobs.comTech Stack / Keywords
Machine learning
Firma i stanowisko
We are looking for an experienced AI Threat Modelling Specialist / Subject Matter Expert to support the identification and assessment of security risks related to AI-enabled applications, platforms and services.
Wymagania
- Strong knowledge of IT Security Architecture
- Practical experience in threat modelling for AI agents, Machine Learning, and Large Language Models
- Strong knowledge of threat modelling methodologies, including STRIDE, attack trees, and kill chains
- Ability to identify assets, trust boundaries, attack surfaces, threat actors, and abuse cases
- Experience creating and maintaining reusable threat models and threat libraries
- Ability to translate identified threats into appropriate security controls and remediation actions
- Strong analytical and problem-solving skills
- Ability to work effectively with application, development, architecture, and security teams
- Fluency in English (both written and spoken)
Obowiązki
- Conduct threat modelling workshops with application, platform, and security teams
- Perform application-level security assessments focusing on AI, ML, LLMs, and AI agents
- Identify critical assets, trust boundaries, attack surfaces, threat actors, abuse cases, and security risks
- Map relevant threats and attack scenarios using the Mythos adversary framework
- Develop and maintain threat models using approved threat modelling methodologies and tools
- Review solution designs, system architecture, and technical documentation to ensure appropriate threat coverage
- Apply threat modelling methodologies such as STRIDE, attack trees, and kill chains
- Map identified threats to appropriate security controls and remediation actions
- Collaborate with development, architecture, and security teams to define and implement risk mitigation measures
- Develop reusable threat models, threat patterns, and threat libraries
- Track identified threats, security risks, and remediation activities, and provide clear reporting on their status
Diverse CG
23 aktywne oferty