Cyber AI Security & Forensic Engineer – IT & OT
3Core Systems , Inc Denver, Colorado, United States
Software Development · 51-200 employees
About the role
The engineers will identify, assess, and mitigate cybersecurity risks related to AI, LLMs, and autonomous systems within IT and OT environments. They are responsible for performing security testing, conducting threat modeling, and collaborating with cross-functional teams to remediate vulnerabilities.
What they look for
Requirements
Candidates must have a bachelor's degree in a relevant field and extensive experience in cybersecurity, application security, or AI/ML security. Strong knowledge of AI vulnerabilities, security frameworks like OWASP, and risk assessment methodologies is required.
Full description
Cyber AI Security & Forensic Engineer – IT & OT
Location: South Denver, CO
Duration: Long Term
Positions: 2 Openings – 1 IT / 1 OT
Work Arrangement: 2days Onsite -Hybrid as required by the client
Job Summary
We are seeking experienced Cyber AI Security & Forensic Engineers to help identify, assess, and mitigate emerging cybersecurity risks associated with Artificial Intelligence, Large Language Models (LLMs), Generative AI, and autonomous/agentic AI systems.
There are two openings for this position:
- IT
Cyber AI Security & Forensic Engineer: Focused on enterprise applications, cloud environments, LLM/GenAI applications, APIs, AI agents, and application security.
- OT
Cyber AI Security & Forensic Engineer: Focused on applying AI security and cybersecurity principles within Operational Technology (OT), Industrial Control Systems (ICS), SCADA, and industrial environments.
The ideal candidates will have a strong cybersecurity foundation combined with hands-on experience assessing AI/LLM applications, identifying vulnerabilities and bypass techniques, recommending security controls, and applying security frameworks such as OWASP.
Key Responsibilities
- Perform
security testing of AI applications, LLMs, Generative AI solutions, and AI-enabled platforms to identify vulnerabilities, weaknesses, misuse cases, and potential bypass techniques.
- Conduct
AI/LLM security assessments, including testing for prompt injection, jailbreaks, data leakage, insecure outputs, model manipulation, and unauthorized access.
- Evaluate
AI applications and integrations for security weaknesses across APIs, data sources, tools, plugins, and external services.
- Assess agentic AI architectures and autonomous software agents to
understand how agents interact with external tools, APIs, data, and enterprise systems.
- Evaluate
agent permissions, tool access, authentication, authorization, and least-privilege controls.
- Identify
risks associated with excessive agency, insecure tool use, indirect prompt injection, and unauthorized actions.
- Recommend
secure AI and data usage practices, including data protection, access controls, secure prompts, guardrails, and responsible AI practices.
- Apply OWASP
Top 10, OWASP API Security Top 10, OWASP LLM Top 10, and other applicable security standards to identify and communicate security risks.
- Perform
threat modeling and security assessments for AI-enabled applications and services.
- Work
with application, cloud, data, infrastructure, and cybersecurity teams to remediate identified vulnerabilities.
- Support
vulnerability management, incident investigations, digital forensics, and root-cause analysis where required.
- Review
logs, telemetry, application behavior, and security events to identify suspicious or malicious AI activity.
- Develop
security recommendations, assessment reports, remediation plans, and technical documentation.
- Stay
current with emerging AI attack techniques, LLM vulnerabilities, agentic AI risks, and AI security frameworks.
IT Position – Additional Responsibilities
- Assess
security of enterprise LLM/GenAI applications, APIs, cloud services, RAG solutions, vector databases, and AI integrations.
- Test
AI applications for prompt injection, jailbreaks, sensitive information disclosure, insecure output handling, and data poisoning.
- Review
AI integrations with enterprise applications, SaaS platforms, APIs, and external tools.
- Evaluate
cloud security controls across AWS, Azure, or GCP environments.
- Support
application security, API security, secure SDLC, SAST/DAST, and DevSecOps initiatives.
- Analyze
AI application logs and telemetry for security anomalies and potential abuse.
OT Position – Additional Responsibilities
- Apply
AI and cybersecurity security practices to Operational Technology environments, including ICS, SCADA, PLC, DCS, and industrial control systems.
- Assess
security risks associated with AI-enabled OT applications and autonomous systems.
- Understand
OT network architecture, segmentation, remote access, industrial protocols, and OT security controls.
- Support
OT incident response, threat hunting, forensic investigations, and security assessments.
- Evaluate
the potential impact of AI-driven attacks or compromised AI systems on industrial environments.
- Work
closely with OT engineering, controls, infrastructure, and cybersecurity teams to identify and mitigate risks.
Required Qualifications
- Bachelor's
degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related field, or equivalent experience.
- Strong
cybersecurity engineering, application security, penetration testing, or security assessment experience.
- Hands-on
experience with AI/ML security, LLM security, Generative AI security, or AI application testing.
- Understanding
of common LLM and AI vulnerabilities, attack techniques, and security controls.
- Experience
with OWASP Top 10 and preferably OWASP LLM Top 10 / OWASP Agentic AI security concepts.
- Experience
with threat modeling, vulnerability assessment, security testing, and risk analysis.
- Understanding
of authentication, authorization, API security, data protection, and least-privilege principles.
- Experience
analyzing security findings and providing practical remediation recommendations.
- Strong
analytical, troubleshooting, documentation, and communication skills.