TD SYNNEX (NYSE: SNX) is the world's largest IT distributor, adopting AI at speed across Azure AI Foundry, AWS Bedrock, Copilot Studio, Databricks, and self-hosted agent environments. Our security model is runtime-first: instead of blocking AI adoption with slow approvals, we intercept, analyze, and enforce at the moment of execution - which means high-quality monitoring, triage, analytics, and reporting are what keep the system honest. As our AI and Cloud Security Analyst, you provide day-to-day L2 coverage of the AI security detection fabric - triaging and supporting investigation of AI-specific detections from runtime defense, behavioral/intent monitoring, model-security, and adversarial-testing platforms. You turn that telemetry into insight through data analytics and produce the OCR (operational, compliance, and risk) reporting that gives leadership, control owners, and auditors a continuous picture of AI and cloud risk. You also help monitor the security posture of our Azure, AWS, and GCP environments. You elevate to a dedicated L3 engineer and work alongside two AI & Cloud Security Architects. The analyst will report to AI & Cloud Security leadership and have strong working relationships with other Cybersecurity, IT and application development teams.
Responsibilities
- L2 coverage of the AI Security toolset .
- Monitor AI security detections across the detection fabric - runtime defense/AIDR events, intent and behavioral anomalies, model-level detections, and adversarial-testing signals.
- Validate detections, classify severity and impact, propose and implement policy updates, and elevate complex cases to L3 with complete, reusable context.
- Investigate AI-specific events across all five AI archetypes (embedded SaaS copilots, low-code/no-code agents, homegrown agentic pipelines, device-based coding agents, homegrown models): direct and indirect prompt injection, jailbreaks, sensitive-data leakage, RAG poisoning indicators, unauthorized MCP/tool activity, agent hijacking, and rogue or overprivileged agent behavior - using prompt/response logs, decision traces, identity context, and agent inventory data.
- Support the AI asset-intelligence layer : help maintain agent inventory hygiene, ownership attribution, MCP registry accuracy, and risk-scoring context that feeds runtime enforcement decisions and fast-track approval workflows.
- Data analytics . Query and correlate AI and security telemetry (KQL), identify anomalies and attack patterns, and build/maintain dashboards tracking the program's key metrics - detection volumes, runtime containment rate, mean time to detect/contain/resolve, agent-visibility coverage, approval-SLA performance, and top policy-violation categories - feeding tuning recommendations back to the L3 engineer.
- OCR reporting (operational, compliance, and risk) . Produce recurring dashboards and executive summaries communicating AI-security posture, KPIs, and trends to stakeholders and control owners; support automated NIST AI RMF compliance evidence generation and audit/regulatory reporting, including EU AI Act-related evidence for EU scope.
- Maintain rigorous case documentation and shift/handover notes; contribute observed patterns to detection-rule tuning, runbook refinement, and the closed-loop improvement cycle (red-team findings → policy and detection updates → re-test validation).
- Build working fluency in the OWASP Top 10 for LLM Applications 2025, the OWASP Top 10 for Agentic Applications, and MITRE ATLAS as the shared investigation taxonomy.
- Monitor and triage cloud security alerts across Azure, AWS, and GCP from company CSPM platform - misconfigurations, security risks, exposed resources, excessive permissions, workload threats - and route, remediate, or escalat per playbook.
- Support cloud compliance monitoring and reporting against CIS Benchmarks and NIST 800-53 r5 / CSF 2.0 baselines, tracking remediation to closure and integrating cloud posture into the consolidated OCR reporting.
- Support L3 engineer with policy updates.
- Assist with cloud workload vulnerability triage (VMs, containers, images) and with Microsoft 365 / Google Workspace security-signal review.
- Partner with the L3 engineer, SOC, cloud teams, and incident responders on investigations and enrichment spanning cloud, identity, endpoint, and AI telemetry.
Critical Skills
- Solid security operations fundamentals : alert monitoring, triage, validation, incident classification, escalation, and case management against SLAs, working from runbooks in a follow-the-sun/handover model.
- Strong data analytics and reporting : KQL (and/or SQL) for querying and correlation; dashboard and report development; the ability to turn telemetry into clear, decision-ready operational, compliance, and risk reporting.
- Foundational AI/GenAI security awareness : LLM risks (prompt injection, jailbreaks, data leakage), agentic AI and MCP concepts, AI guardrails, and familiarity with the OWASP LLM Top 10 and MITRE ATLAS.
- Exposure to AI security