Responsibilities
- Conduct threat modeling and security evaluations for AI platforms, including large language models, generative AI, agent-based systems, and retrieval-augmented generation frameworks.
- Detect, analyze, and address security risks specific to AI, such as prompt manipulation, data contamination, model exposure, and newly emerging threats.
- Analyze security vulnerabilities in the supply chain related to AI models, software agents, plugins, and third-party AI services.
- Develop and enforce security controls for AI systems, including input and output validation, usage policies, request throttling, surveillance, and system segregation.
- Create and uphold security benchmarks and recommended practices for AI deployments in live environments.
- Advocate for built-in security and privacy protections during the design and development of AI systems.
- Lead security evaluations and sign-off procedures prior to releasing AI applications into production.
- Organize and carry out red team exercises and adversarial testing tailored to AI use cases.
- Examine agent-driven workflows and automated execution features for potential misuse or unauthorized access escalation.
- Design logging, monitoring, alerting, and response protocols specific to AI-powered systems.
- Assist in probing security incidents and performing digital forensics related to AI components.
- Work with diverse teams to align AI implementations with security, regulatory, privacy, and governance standards.
- Guide development and product units in securely building and managing AI capabilities.
- Support organization-wide efforts to increase awareness and understanding of AI security practices.