AI SECURITY ARCHITECT

TRIPLE POINT SECURITY INCORPORATED•Blacksburg, VA
•$140,000 - $150,000

About The Position

Triple Point Security is looking for an AI Security Architect to help a national research organization explore how artificial intelligence can support its enterprise Zero Trust program. You will identify and prioritize potential AI use cases across the Zero Trust pillars, assess how well AI-based approaches address specific Zero Trust threats compared with existing tools, and help make sure recommended capabilities can be governed and authorized under Federal and HHS AI policy. You will be part of the Risk, Authorization & AI team, reporting to the program's Security Lead and working closely with an ML/Data Engineer and our Lead Zero Trust Architect. The role builds on secure AI adoption work Triple Point already supports for this client. This role includes regular client interaction. You will present findings and recommendations to client security and technology leadership, facilitate use case discovery workshops and working sessions with client stakeholders, and help explain AI concepts to audiences with varying levels of technical background. Your work will have a meaningful impact on the medical and scientific communities our client serves.

Requirements

  • Bachelor's degree in Computer Science, Information Systems, Cybersecurity, Data Science, or a related field from an accredited university
  • 3 to 5 years of experience in cybersecurity architecture, security engineering, or a closely related technical discipline, including hands-on work involving AI/ML systems, security analytics, or detection engineering
  • Working knowledge of Zero Trust principles, including NIST SP 800-207 and the CISA Zero Trust Maturity Model (ZTMM) v2.0 pillars and cross-cutting capabilities
  • Understanding of how AI and machine learning are applied in security, including user and entity behavior analytics (UEBA), anomaly detection, risk scoring, and classification, and of their practical limits: false positives, model drift, data dependencies, and explainability
  • Working knowledge of AI and LLM-specific risks and attack classes, including prompt injection, training and retrieval data poisoning, model extraction, insecure output handling, sensitive data leakage, and excessive agency in agentic systems
  • Familiarity with AI risk frameworks, including the NIST AI Risk Management Framework (AI 100-1) and Generative AI Profile (NIST AI 600-1), the OWASP Top 10 for LLM Applications, and MITRE ATLAS
  • Working knowledge of NIST SP 800-53 Rev. 5 and how established Federal security controls apply to AI-enabled systems
  • Experience evaluating technologies against defined criteria and producing structured assessments, evaluation plans, or analyses of alternatives
  • Hands-on experience in at least one major cloud service provider (AWS, Azure, or GCP), including its AI services (e.g., Amazon Bedrock, Azure OpenAI/AI Foundry, Google Vertex AI)
  • Proficiency in Python or a comparable language sufficient to prototype, test, and review data pipelines and model integrations
  • Strong written communication skills, including the ability to produce data flow diagrams, architecture documentation, and risk assessments for both engineering teams and non-engineering leadership
  • Client-facing experience, including presenting technical findings to leadership, facilitating workshops or working sessions, and explaining technical topics clearly to non-technical audiences
  • Required: at least one active cybersecurity certification, such as CompTIA SecurityX (formerly CASP+), GIAC Security Essentials (GSEC), AWS Certified Security – Specialty, Microsoft Certified: Azure Security Engineer Associate, CCSP, or CISSP
  • Must be a U.S. citizen (client requirement).
  • Must be able to obtain and maintain a client suitability determination (Public Trust) and a client-issued Personal Identity Verification (PIV) credential, and complete required security and privacy training prior to access.

Nice To Haves

  • Master's degree in Cybersecurity, Computer Science, Data Science, or a related field
  • Experience supporting Federal civilian agencies, particularly HHS or other research and health organizations
  • Experience with SIEM, SOAR, and security analytics platforms such as Splunk, Microsoft Sentinel, or the ELK stack, including detection design for identity threats and credential misuse
  • Experience designing evaluation methods for security capabilities without large labeled datasets, such as shadow-mode operation, synthetic adversary injection, purple-team exercises, and drift monitoring with defined revalidation cadences
  • Experience red teaming or adversarially testing LLM, RAG, or agentic AI systems, and securing agent identities, entitlements, and tool use
  • Familiarity with OMB AI policy for Federal agencies (including OMB M-25-21), Federal AI use case inventory reporting, and HHS AI governance requirements
  • Experience with data governance and privacy for security telemetry, including data classification, retention, boundary controls, and handling of PII and PHI
  • Familiarity with ZT enabling technologies such as ICAM, device posture and EDR, micro-segmentation, and policy decision/enforcement points
  • Experience with LLM gateways and orchestration platforms (e.g., LiteLLM, LibreChat) and cloud-native AI guardrail services
  • Experience developing and delivering training, briefings, or workshops on AI or security topics
  • Prior experience in a consulting or professional services environment, including contributing to technical proposals
  • Preferred: IAPP Artificial Intelligence Governance Professional (AIGP), ISACA Advanced in AI Security Management (AAISM), or GIAC AI Platform Security (GAIPS)
  • Preferred: Microsoft Certified: Azure AI Engineer Associate, AWS Certified Machine Learning Engineer – Associate, or equivalent cloud AI/ML certification
  • Preferred: CISSP or CCSP, if not held as the required certification

Responsibilities

  • Lead development of the AI Use Case Inventory across all Zero Trust pillars and cross-cutting capabilities, deriving candidates from a matrix of pillars against AI functions (detection and classification, correlation and enrichment, decision support, workflow automation, and evidence generation)
  • Prioritize use cases by enterprise risk, feasibility, and mission impact, decomposing feasibility into data availability, integration complexity, and governance readiness so the inventory stays tied to what can actually be authorized
  • Author a data statement for every use case documenting what data the capability consumes, where it originates, how it is classified, whether it leaves its collection boundary, how long it is retained, and who is accountable for it
  • Lead the assessment of AI effectiveness against Zero Trust threats, including AI-driven detection of credential misuse, device risk classification, automated enforcement of micro-segmentation policies, and continuous monitoring and anomaly detection
  • Design evaluation approaches that do not assume a large labeled incident corpus, including shadow-mode operation against existing detections, synthetic injection of representative adversary behavior, purple-team scenarios for enforcement use cases, and drift monitoring with defined revalidation cadences
  • Conduct analyses of alternatives comparing classical ML, agentic AI, and conventional automation for each use case, recommending human-in-the-loop designs wherever an AI output drives an enforcement decision
  • Partner with the ML/Data Engineer on technical design artifacts, including data flow diagrams, model requirements, trust-scoring logic, and integration patterns, ensuring scoring is explainable to the person it affects, every enforcement decision has a defined appeal path, and decision logic is kept separate from policy-owned weightings and thresholds
  • Define Zero Trust controls for AI systems themselves, including identity, entitlements, network placement, and action logging for models, agents, and the tools they are permitted to invoke
  • Threat model AI-enabled Zero Trust controls using MITRE ATLAS and the OWASP Top 10 for LLM Applications, and document compensating controls for residual risk
  • Align designs with HHS and client AI policy and record the governing policy version in each design artifact, so policy changes become configuration changes rather than re-architecture
  • Coordinate with the Lead Zero Trust Architect so AI patterns integrate with the enterprise reference architectures, and with the RMF/A&A Specialist so AI-supported controls and their evidence are authorizable
  • Plan and facilitate use case discovery workshops and working sessions with client security, technology, and program stakeholders, including preparing agendas and materials and tracking decisions and action items
  • Present AI use case priorities, assessment results, and recommendations to client leadership and governance bodies
  • Contribute to the coordinated quarterly refresh cycle, ZTA knowledge base content, monthly institute office hours, and enterprise help desk inquiries on AI-related topics
  • Research emerging AI capabilities, attack techniques, and Federal AI policy through Triple Point's Talent and Innovation Hub, and convert findings into reusable patterns and client-ready guidance
  • Mentor junior engineers and interns on AI security and Zero Trust fundamentals
  • Support business development efforts including proposal contributions, technical solutioning, and client presentations

Benefits

  • Immediate vesting for 401(k) company matching contributions
  • 100% of premium cost for basic employee coverage: Health, Dental, and Vision
  • 100% of premium cost: Basic Life AD&D, Short Term Disability, and Long Term Disability
  • Flexible Spending Accounts: Health, Dependent Care, and Mass Transit & Parking
  • Tuition & Training Reimbursement
  • Paid Time Off plus 10 Paid Holidays
  • Performance and referral Bonus
  • Flexible work schedule (with client approval)
  • Employee Assistance Program
  • Call A Doctor Plus Telemedicine Service
  • MetLaw Group Legal Services
  • Technology resources (HW/SW), online training, and virtual labs
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service