AI Security Specialist

Consultec-TI•Colorado Springs, CO

About The Position

We are seeking an AI Security Specialist responsible for evaluating, designing, and implementing security controls for solutions based on Artificial Intelligence, Machine Learning, Generative AI, Large Language Models (LLMs), and AI agents. Your role will be to ensure that AI solutions are designed, developed, and implemented under Security by Design principles, identifying vulnerabilities, threats, and risks associated with models, data, prompts, APIs, agents, integrations, and infrastructure components. You will work closely with Cybersecurity, Development, Architecture, DevSecOps, Cloud, Data, and Artificial Intelligence teams to incorporate security controls throughout the solutions' lifecycle, from design to operation in production environments. You will be responsible for technically evaluating the specific risks of AI applications, defining protection mechanisms, and conducting tests to detect vulnerabilities before they can compromise critical business information, systems, or processes.

Requirements

  • Professional experience in Cybersecurity, Application Security, DevSecOps, Cloud Security, Ethical Hacking, or related areas.
  • Experience evaluating the security of applications, APIs, microservices, and modern architectures.
  • Knowledge of Artificial Intelligence, Machine Learning, Generative AI, and Large Language Models (LLMs).
  • Knowledge of specific risks and vulnerabilities of Artificial Intelligence and LLM applications.
  • Experience performing Threat Modeling, vulnerability analysis, and risk assessments.
  • Knowledge of OWASP Top 10 and security frameworks associated with Generative AI applications.
  • Experience or knowledge in AI Red Teaming, Adversarial Testing, or Ethical Hacking.
  • Knowledge of authentication and authorization mechanisms such as OAuth 2.0, OpenID Connect, RBAC, and IAM.
  • Experience with REST API security and web services.
  • Knowledge of data protection, encryption, secrets management, and access controls.
  • Experience working with at least one Cloud platform: Microsoft Azure, AWS, or Google Cloud Platform.
  • Experience with DevSecOps practices, CI/CD, and Secure Software Development Lifecycle.
  • Knowledge of scripting or programming languages, preferably Python.
  • Familiarity with RAG architectures, vector databases, embeddings, and AI agents.
  • Knowledge of AI platforms and services such as Azure OpenAI, Microsoft Copilot, AWS Bedrock, Google Vertex AI, Gemini, or OpenAI APIs.
  • Familiarity with frameworks like LangChain, Semantic Kernel, LlamaIndex, or equivalents.
  • Knowledge of standards and frameworks such as NIST AI Risk Management Framework, OWASP GenAI Security Project, and MITRE ATLAS.

Nice To Haves

  • Ability to identify security risks specific to Artificial Intelligence-based solutions.
  • Analytical thinking and ability to anticipate possible attack vectors.
  • Technical judgment to evaluate controls and determine the level of risk associated with detected vulnerabilities.
  • Ability to understand complex architectures integrating applications, models, data, APIs, and Cloud services.
  • Ability to design controls that balance security, functionality, and user experience.
  • Skill in documenting vulnerabilities, risks, recommendations, and remediation plans.
  • Ability to communicate technical risks to both technical and non-technical audiences.
  • Autonomy to research new threats and attack techniques related to Artificial Intelligence.
  • Effective collaboration with Cybersecurity, Development, Architecture, DevSecOps, Cloud, Data, and AI teams.
  • Permanent interest in researching new vulnerabilities, technologies, and trends related to AI Security.
  • Critical thinking and problem-solving.
  • High analytical capacity.
  • Effective communication.
  • Attention to detail.
  • Proactivity and autonomy.
  • Research and continuous learning ability.
  • Collaborative work with multidisciplinary teams.
  • Ability to explain technical risks clearly and structurally.
  • Orientation towards prevention and risk management.
  • Adaptability to emerging technologies and threats.

Responsibilities

  • Evaluate architectures, applications, and services based on Generative AI, LLMs, and Machine Learning, identifying vulnerabilities and establishing adequate security controls before their release to production.
  • Perform threat analyses on Artificial Intelligence solutions, identifying attack surfaces, risk vectors, critical assets, and possible exploitation scenarios.
  • Identify and mitigate risks associated with Prompt Injection, Jailbreaking, Sensitive Information Disclosure, Improper Output Handling, Data and Model Poisoning, Model Theft, and Supply Chain Vulnerabilities.
  • Evaluate autonomous or semi-autonomous agents that interact with tools, APIs, databases, and other systems, implementing permission, authentication, authorization, and least privilege controls to limit unwanted actions.
  • Design and execute adversarial tests on AI models and applications to identify vulnerabilities, unexpected behaviors, control bypasses, prompt manipulation, and possible information extraction or exposure mechanisms.
  • Evaluate Retrieval-Augmented Generation implementations, including knowledge sources, embeddings, vector databases, retrieval mechanisms, and information access controls.
  • Implement controls to prevent the exposure of confidential information, personal data, intellectual property, credentials, secrets, and other sensitive information processed by Artificial Intelligence solutions.
  • Design and implement input and output validation mechanisms, content filtering, usage policies, operational restrictions, and controls to reduce unwanted model behaviors.
  • Evaluate integrations between AI models, enterprise applications, APIs, microservices, and external platforms, ensuring appropriate authentication, authorization, encryption, and data protection mechanisms.
  • Assess risks associated with third-party models, frameworks, libraries, datasets, APIs, repositories, plugins, and vendors used within the Artificial Intelligence ecosystem.
  • Incorporate specific AI security controls within Secure SDLC and DevSecOps practices, participating in technical reviews during the design, development, testing, and deployment phases.
  • Evaluate security configurations and controls in Artificial Intelligence services deployed on Microsoft Azure, AWS, or Google Cloud, ensuring adequate management of identities, permissions, secrets, networks, and data.
  • Define logging, traceability, monitoring, and anomaly detection mechanisms for AI models, agents, and applications.
  • Identify, document, and prioritize vulnerabilities related to Artificial Intelligence solutions, establishing technical recommendations and remediation plans.
  • Participate in the definition of policies, standards, and security controls associated with the use of Artificial Intelligence within the organization.
  • Support the analysis and response to incidents related to AI solutions, identifying causes, impact, attack vectors, and corrective actions.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service