IT Security Specialist - Threat Modeling AI
We require a senior security specialist with practical experience in AI-related threats and a strong understanding AI related threats. The specialist will independently conduct application-level assessments, map relevant AI threat scenarios, evaluate security exposures, and define appropriate risk mitigation strategies.
Responsibilities
- Lead threat modelling workshops with application and platform teams.
- Identify and assess assets, trust boundaries, attack surfaces, threats, and security risks related to AI threats.
- Develop and maintain threat models using the approved threat modelling tooling and methodology.
- Review solution designs and architecture documentation to identify security gaps and validate threat coverage.
- Map applicable AI threat scenarios to application components, data flows, and security controls.
- Collaborate with development, architecture, and security teams to define practical risk mitigation actions.
- Provide guidance to less experienced team members during threat modelling activities.
- Track and report identified threats, security risks, mitigation actions, and remediation status.
Must-have knowledge and experience
- Strong knowledge of IT Security Architecture.
- Practical experience in threat modelling AI agents, machine learning systems, and large language models.
- Strong working knowledge of threat modelling methodologies, including STRIDE, attack trees, and kill chains.
- Ability to independently identify assets, trust boundaries, attack surfaces, threat actors, and abuse cases.
- Experience developing and adapting reusable threat models and threat libraries.
- Ability to map identified threats to relevant security controls, risks, and remediation actions.
Nice-to-have knowledge and experience
- Ability to independently translate technical threats and security findings into clear business risks and potential business impacts.
- Strong working knowledge of the OWASP Top 10 for LLM Applications and MITRE ATLAS, with the ability to apply these frameworks during threat assessments.