AI Security Engineer

Paconsulting

Melbourn

Hybrid

GBP 90,000 - 120,000

Full time

3 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

PA Consulting is seeking a security engineer to own AI security tool selection and deployment within the Cyber Security and Compliance team. You will evaluate evidence, measure detection efficacy, and integrate with SIEM, SOAR and EDR platforms to deliver value from day one.

You will also address the AI threat landscape, align with governance standards, perform adversarial testing, and develop demonstrators that influence investment decisions while ensuring responsible AI usage across the firm.

Qualifications

  • Security engineer with ML/LLM literacy.
  • Understanding of models, RAG pipelines and agents.
  • Reasonable Python scripting ability and cloud platform experience.
  • Ability to explain AI risk to non-specialists.

Responsibilities

  • Technical ownership of AI security tool selection and deployment.
  • Understand AI threat landscape and align with governance frameworks.
  • Demonstrate AI protection, detection and response measures.
  • Conduct assurance and testing, including adversarial testing and red teaming.
  • Communicate risk and value to stakeholders and drive demonstrators.

Skills

Security engineering
ML & LLM literacy
Python scripting
Cloud security
Security architecture
SOC engineering

Tools

SIEM
SOAR
EDR

Job description

Hybrid working - our approach is to be in the office a minimum of 2 days per week.

PA's IT team, internally known as Group Systems, is comprised of a variety of areas that support the wider firm, consisting of four key pillars: Strategy, Architecture and Infrastructure Services; Enterprise Solutions; Technology and Operations; and Cyber Security and Compliance.

The successful candidate will be covered two primary areas: the security of AI (protecting the organisation's own AI systems and use of AI) and AI for security (using AI to strengthen protection, detection and response). This role will sit within Cyber Security and Compliance.

Technical ownership of AI security tool selection and deployment

Define requirements, run structured evaluations and proofs of concept, and judge vendor claims on evidence rather than marketing.

That means measuring detection efficacy, false positive rates, latency and operational overhead. The tool categories to cover include AI security posture management, LLM guardrails and firewalls, model and supply-chain scanning, GenAI data loss prevention, and AI-enabled SOC tooling.

They should also own the deployment itself: integration with existing SIEM, SOAR, EDR and identity tooling, architecture decisions, and making sure the tools are tuned and producing value after go‑live rather than becoming shelfware.

Input to vendor risk assessments fits here too, particularly on how vendors handle your data in their own models.

Understanding the AI threat landscape

They need a working knowledge of AI‑specific attack techniques and should be fluent in the reference frameworks, mainly the OWASP Top 10 for LLM Applications and MITRE ATLAS. Key threats include:

  • Direct and indirect prompt injection
  • Data and model poisoning
  • Sensitive data leakage through prompts and outputs
  • Model theft and extraction
  • Malicious model files in the supply chain
  • The growing set of risks from agentic AI, such as excessive permissions and tool misuse

They also need to understand how attackers use AI against the organisation (more convincing phishing, deepfake‑enabled fraud, faster reconnaissance and exploit development) and how that changes your threat model. Shadow AI, meaning unsanctioned use of AI tools by staff, is a practical, near‑term issue they should be able to discover and manage.

Demonstrating AI in protection, detection and response

This is where the role earns its keep with stakeholders. In protection, that might mean AI‑assisted vulnerability prioritisation, secure code review, or posture analysis. In detection, it covers behavioural anomaly detection, alert triage and enrichment, and LLM‑assisted threat hunting. In response, it includes AI copilots for investigation and incident summarisation, automated playbooks, and agentic response actions.

A good candidate will be clear‑eyed about limits: where human‑in‑the‑loop controls are needed, how to validate AI outputs, and how to avoid automating mistakes at speed. The ability to build or run demonstrators that show value concretely is a strong differentiator.

Assurance and testing

The role should include adversarial testing and red teaming of the organisation's AI systems, whether done directly or by scoping and overseeing third parties. Examples are testing RAG applications for injection and data exposure, or checking that an agent can't be manipulated into acting outside its intended permissions.

Alignment with governance & standards

This isn't primarily a governance role, but the engineer should translate frameworks into technical controls and evidence. The relevant reference points are:

  • NCSC's Guidelines for Secure AI System Development
  • The UK government's AI Cyber Security Code of Practice
  • NIST AI RMF
  • ISO/IEC 42001
  • The EU AI Act, where relevant to clients or operations
Skills & background

The ideal profile is a security engineer (typically from cloud security, security architecture, or SOC engineering) who has built genuine ML and LLM literacy. That means understanding how models, RAG pipelines and agents work, reasonable Python or scripting ability, and cloud platform experience. Communication matters more than usual: this person will regularly need to explain AI risk and capability to non‑specialist decision‑makers without overselling or scaremongering.

Measures of success

Useful indicators:

  • Tools selected and deployed against defined requirements, with measurable outcomes (reduced triage time, improved detection coverage)
  • An AI asset inventory and threat model in place
  • AI systems tested before deployment
  • Demonstrators that have influenced investment or adoption decisions

Please be aware that some of our UK roles at PA Consulting require a UK security clearance.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

AI Security Engineer
AI Security Engineer

PA Consulting • Melbourn

Hybrid
GBP 85,000 - 120,000
25 days annual leave
Generous pension scheme
Annual performance-based bonus
+1
Ai Security Engineer
Ai Security Engineer

Pa Consulting • Watford

Hybrid
GBP 70,000 - 110,000
Private healthcare
25 days annual leave
Generous pension
+1
AI Security Engineer
AI Security Engineer

SmartRecruiters, Inc. • Royston

Hybrid
GBP 70,000 - 120,000
Private healthcare
25 days annual leave
Pension plan
+1
AI Security Engineer
AI Security Engineer

PA Consulting Group • Melbourn

Hybrid
GBP 75,000 - 110,000
Health and lifestyle perks
25 days annual leave
Generous pension
+3
AI & ML Engineer (Cybersecurity)
AI & ML Engineer (Cybersecurity)

Accenture PLC • Cheltenham

Hybrid
GBP 70,000 - 110,000
AI Security Consultant
AI Security Consultant

PA Consulting • City of Westminster

On-site
GBP 90,000 - 120,000
Health insurance
25 days annual leave
Pension scheme
+2
AI Security Consultant - OWASP / NIS - Cyber Security With Llms
AI Security Consultant - OWASP / NIS - Cyber Security With Llms

Avanti Recruitment Limited • City Of London

On-site
GBP 60,000 - 100,000
Bonus
AI Security Architect
AI Security Architect

Polo • Cheltenham

Hybrid
GBP 75,000 - 85,000
AI Security engineer
AI Security engineer

DCV Technologies • Greater London

Hybrid
GBP 104,000 - 136,000
AI Security Architect
AI Security Architect

Polo • Greater London

On-site
GBP 75,000 - 85,000