What are the responsibilities and job description for the Cyber AI Security & Forensic Engineer - IT & OT position at 3coresystems?
Cyber AI Security & Forensic Engineer - IT & OT<\/b>
<\/p>
<\/p>\n
\n <\/div>\n
\n <\/div>\n
\n <\/div>
<\/p>
<\/p>\n
\n <\/div>\n
\n <\/div>
<\/p>
Job Summary<\/b>
<\/p>
We are seeking experienced Cyber AI Security & Forensic Engineers<\/b> to help identify, assess, and mitigate emerging cybersecurity risks associated with Artificial Intelligence, Large Language Models (LLMs), Generative AI, and autonomous\/agentic AI systems<\/b>.
<\/p>
There are two openings for this position:
<\/p>\n
- \n
- IT Cyber AI Security & Forensic Engineer:<\/b> Focused on enterprise applications, cloud environments, LLM\/GenAI applications, APIs, AI agents, and application security.
<\/li>\n- OT Cyber AI Security & Forensic Engineer:<\/b> Focused on applying AI security and cybersecurity principles within Operational Technology (OT), Industrial Control Systems (ICS), SCADA, and industrial environments<\/b>.
<\/li>\n <\/ul>The ideal candidates will have a strong cybersecurity foundation combined with hands\-on experience assessing AI\/LLM applications, identifying vulnerabilities and bypass techniques, recommending security controls, and applying security frameworks such as OWASP<\/b>.
<\/p>Key Responsibilities<\/b>
<\/p>\n- \n
- Perform security testing of AI applications, LLMs, Generative AI solutions, and AI\-enabled platforms<\/b> to identify vulnerabilities, weaknesses, misuse cases, and potential bypass techniques.
<\/li>\n- Conduct AI\/LLM security assessments, including testing for prompt injection, jailbreaks, data leakage, insecure outputs, model manipulation, and unauthorized access<\/b>.
<\/li>\n- Evaluate AI applications and integrations for security weaknesses across APIs, data sources, tools, plugins, and external services.
<\/li>\n- Assess agentic AI architectures<\/b> and autonomous software agents to understand how agents interact with external tools, APIs, data, and enterprise systems.
<\/li>\n- Evaluate agent permissions, tool access, authentication, authorization, and least\-privilege controls.
<\/li>\n- Identify risks associated with excessive agency, insecure tool use, indirect prompt injection, and unauthorized actions.
<\/li>\n- Recommend secure AI and data usage practices<\/b>, including data protection, access controls, secure prompts, guardrails, and responsible AI practices.
<\/li>\n- Apply OWASP Top 10, OWASP API Security Top 10, OWASP LLM Top 10<\/b>, and other applicable security standards to identify and communicate security risks.
<\/li>\n- Perform threat modeling and security assessments for AI\-enabled applications and services.
<\/li>\n- Work with application, cloud, data, infrastructure, and cybersecurity teams to remediate identified vulnerabilities.
<\/li>\n- Support vulnerability management, incident investigations, digital forensics, and root\-cause analysis where required.
<\/li>\n- Review logs, telemetry, application behavior, and security events to identify suspicious or malicious AI activity.
<\/li>\n- Develop security recommendations, assessment reports, remediation plans, and technical documentation.
<\/li>\n- Stay current with emerging AI attack techniques, LLM vulnerabilities, agentic AI risks, and AI security frameworks.
<\/li>\n <\/ul>IT Position - Additional Responsibilities<\/b>
<\/p>\n- \n
- Assess security of enterprise LLM\/GenAI applications, APIs, cloud services, RAG solutions, vector databases, and AI integrations<\/b>.
<\/li>\n- Test AI applications for prompt injection, jailbreaks, sensitive information disclosure, insecure output handling, and data poisoning.
<\/li>\n- Review AI integrations with enterprise applications, SaaS platforms, APIs, and external tools.
<\/li>\n- Evaluate cloud security controls across AWS, Azure, or GCP<\/b> environments.
<\/li>\n- Support application security, API security, secure SDLC, SAST\/DAST, and DevSecOps initiatives.
<\/li>\n- Analyze AI application logs and telemetry for security anomalies and potential abuse.
<\/li>\n <\/ul>OT Position - Additional Responsibilities<\/b>
<\/p>\n- \n
- Apply AI and cybersecurity security practices to Operational Technology environments<\/b>, including ICS, SCADA, PLC, DCS, and industrial control systems.
<\/li>\n- Assess security risks associated with AI\-enabled OT applications and autonomous systems.
<\/li>\n- Understand OT network architecture, segmentation, remote access, industrial protocols, and OT security controls.
<\/li>\n- Support OT incident response, threat hunting, forensic investigations, and security assessments.
<\/li>\n- Evaluate the potential impact of AI\-driven attacks or compromised AI systems on industrial environments.
<\/li>\n- Work closely with OT engineering, controls, infrastructure, and cybersecurity teams to identify and mitigate risks.
<\/li>\n <\/ul>Required Qualifications<\/b>
<\/p>\n- \n
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related field, or equivalent experience.
<\/li>\n - Strong cybersecurity engineering, application security, penetration testing, or security assessment experience.
<\/li>\n - Hands\-on experience with AI\/ML security, LLM security, Generative AI security, or AI application testing<\/b>.
<\/li>\n- Understanding of common LLM and AI vulnerabilities, attack techniques, and security controls.
<\/li>\n- Experience with OWASP Top 10<\/b> and preferably OWASP LLM Top 10 \/ OWASP Agentic AI security concepts<\/b>.
<\/li>\n- Experience with threat modeling, vulnerability assessment, security testing, and risk analysis.
<\/li>\n- Understanding of authentication, authorization, API security, data protection, and least\-privilege principles.
<\/li>\n- Experience analyzing security findings and providing practical remediation recommendations.
<\/li>\n- Strong analytical, troubleshooting, documentation, and communication skills.
<\/li>\n <\/ul>
<\/p><\/span>
<\/p>\n\n
\n <\/div><\/span>
\n <\/body>\n<\/html> - Understanding of common LLM and AI vulnerabilities, attack techniques, and security controls.
- Assess security risks associated with AI\-enabled OT applications and autonomous systems.
- Test AI applications for prompt injection, jailbreaks, sensitive information disclosure, insecure output handling, and data poisoning.
- Conduct AI\/LLM security assessments, including testing for prompt injection, jailbreaks, data leakage, insecure outputs, model manipulation, and unauthorized access<\/b>.
- OT Cyber AI Security & Forensic Engineer:<\/b> Focused on applying AI security and cybersecurity principles within Operational Technology (OT), Industrial Control Systems (ICS), SCADA, and industrial environments<\/b>.