AI Security & Information Protection Analyst – Agentic AI
Focused on securing agentic LLMs and RAG flows; hands-on work with prompt-injection patterns, agent frameworks, and AI security tooling.
About the Role
Responsible for assessing and mitigating security and information protection risks introduced by agentic AI (LLM agents, RAG, tool-calling and orchestration). Implement and tune DLP controls, investigate incidents, produce secure AI guidance, and conduct third-party AI vendor risk assessments to enable safe business use of AI.
Job Description
Role
AI Security & Information Protection Analyst (Agentic AI focus) responsible for assessing agentic AI use cases and implementing controls to prevent prompt injection, data exfiltration, model abuse, unsafe tool invocation, and supply-chain risks.
Key Responsibilities
- Assess agentic AI patterns including LLM agents, tool/function calling, orchestration, and RAG for security and data-leakage risks.
- Support and design AI security guardrails, secure configurations, role/data scoping, allow/deny policies, reference architectures, and usage guidance.
- Administer and tune DLP controls across endpoints, email, collaboration platforms, cloud, and SaaS; monitor, triage, escalated, and remediate alerts with data owners and legal/privacy teams.
- Detect unsanctioned AI applications, risky plugins/extensions, shadow AI, and risky data uploads.
- Support investigations using agent logs, tool-call traces, and prompt/response histories; develop playbooks and AI security KPIs/KRIs.
- Contribute to AI policy, training, third-party due diligence, and vendor/SaaS assessments covering residency, retention, training-data controls, auditability, and transparency.
Requirements
- Foundational knowledge of agentic AI, RAG, prompt injection, leakage pathways, DLP policies/classifiers/incident workflows, IAM, least privilege, network and SaaS security.
- Experience with at least one enterprise DLP/CASB/SSE platform, SIEM/EDR/cloud-security monitoring, or SaaS governance.
- Strong analytical skills, documentation, stakeholder communication, adaptability, and a learning mindset.
- Exposure to LLM ecosystems, agent frameworks, vector stores, model gateways, prompt-injection and exfiltration patterns.
- Familiarity with Python or PowerShell, logs/JSON, and standards/guidance such as NIST AI RMF, ISO/IEC 23894, OWASP LLM guidance, or MITRE ATLAS.
Success in the First Six Months
- Baseline sanctioned and unsanctioned AI usage and improve AI-focused DLP precision.
- Publish secure AI guidance and implement initial detections/playbooks for prompt injection, risky tools, and abnormal data movement.
- Complete at least one AI vendor or solution risk assessment.
- OSP contractor: six months with possible extension.
- Hybrid/remote per terms; limited on-call or incident-support windows may apply.
- Candidates should be comfortable with ambiguity, incremental improvement, and pragmatic, hands-on work to protect sensitive data while enabling business value.
LLM agents LLM ecosystems RAG agent frameworks tool/function calling vector stores model gateways DLP CASB SSE SIEM EDR cloud-security monitoring SaaS governance IAM Python PowerShell JSON EDM/IDM fingerprints NIST AI RMF ISO/IEC 23894 OWASP LLM guidance MITRE ATLAS
Skills
Analytical thinking Documentation Stakeholder communication Adaptability Learning mindset Incident response Investigations Risk assessment Policy development Vendor/SaaS assessments
Experience Level
Mid
Employment Type
Full Time, Permanent
- Hybrid/Remote (per terms)
- Limited on-call / incident-support windows