3Core Systems , Inc

Cyber AI Security & Forensic Engineer – IT & OT

3Core Systems , Inc Denver, Colorado, United States

Software Development · 51-200 employees

Yesterday
Principal (10+ yrs) Contractor United States
Log in to apply, save this posting, or score it against your profile with AI.

About the role

The engineers will identify, assess, and mitigate cybersecurity risks related to AI, LLMs, and autonomous systems within IT and OT environments. They are responsible for performing security testing, conducting threat modeling, and collaborating with cross-functional teams to remediate vulnerabilities.

What they look for

Cybersecurity Artificial Intelligence Large Language Models Generative AI Forensics Vulnerability Assessment Penetration Testing OWASP API Security Threat Modeling Cloud Security Operational Technology Industrial Control Systems SCADA Risk Analysis DevSecOps

Requirements

Candidates must have a bachelor's degree in a relevant field and extensive experience in cybersecurity, application security, or AI/ML security. Strong knowledge of AI vulnerabilities, security frameworks like OWASP, and risk assessment methodologies is required.

Full description

Cyber AI Security & Forensic Engineer – IT & OT

Location: South Denver, CO

Duration: Long Term

Positions: 2 Openings – 1 IT / 1 OT

Work Arrangement: 2days Onsite -Hybrid as required by the client

Job Summary

We are seeking experienced Cyber AI Security & Forensic Engineers to help identify, assess, and mitigate emerging cybersecurity risks associated with Artificial Intelligence, Large Language Models (LLMs), Generative AI, and autonomous/agentic AI systems.

There are two openings for this position:

  • IT

Cyber AI Security & Forensic Engineer: Focused on enterprise applications, cloud environments, LLM/GenAI applications, APIs, AI agents, and application security.

  • OT

Cyber AI Security & Forensic Engineer: Focused on applying AI security and cybersecurity principles within Operational Technology (OT), Industrial Control Systems (ICS), SCADA, and industrial environments.

The ideal candidates will have a strong cybersecurity foundation combined with hands-on experience assessing AI/LLM applications, identifying vulnerabilities and bypass techniques, recommending security controls, and applying security frameworks such as OWASP.

Key Responsibilities

  • Perform

security testing of AI applications, LLMs, Generative AI solutions, and AI-enabled platforms to identify vulnerabilities, weaknesses, misuse cases, and potential bypass techniques.

  • Conduct

AI/LLM security assessments, including testing for prompt injection, jailbreaks, data leakage, insecure outputs, model manipulation, and unauthorized access.

  • Evaluate

AI applications and integrations for security weaknesses across APIs, data sources, tools, plugins, and external services.

  • Assess agentic AI architectures and autonomous software agents to

understand how agents interact with external tools, APIs, data, and enterprise systems.

  • Evaluate

agent permissions, tool access, authentication, authorization, and least-privilege controls.

  • Identify

risks associated with excessive agency, insecure tool use, indirect prompt injection, and unauthorized actions.

  • Recommend

secure AI and data usage practices, including data protection, access controls, secure prompts, guardrails, and responsible AI practices.

  • Apply OWASP

Top 10, OWASP API Security Top 10, OWASP LLM Top 10, and other applicable security standards to identify and communicate security risks.

  • Perform

threat modeling and security assessments for AI-enabled applications and services.

  • Work

with application, cloud, data, infrastructure, and cybersecurity teams to remediate identified vulnerabilities.

  • Support

vulnerability management, incident investigations, digital forensics, and root-cause analysis where required.

  • Review

logs, telemetry, application behavior, and security events to identify suspicious or malicious AI activity.

  • Develop

security recommendations, assessment reports, remediation plans, and technical documentation.

  • Stay

current with emerging AI attack techniques, LLM vulnerabilities, agentic AI risks, and AI security frameworks.

IT Position – Additional Responsibilities

  • Assess

security of enterprise LLM/GenAI applications, APIs, cloud services, RAG solutions, vector databases, and AI integrations.

  • Test

AI applications for prompt injection, jailbreaks, sensitive information disclosure, insecure output handling, and data poisoning.

  • Review

AI integrations with enterprise applications, SaaS platforms, APIs, and external tools.

  • Evaluate

cloud security controls across AWS, Azure, or GCP environments.

  • Support

application security, API security, secure SDLC, SAST/DAST, and DevSecOps initiatives.

  • Analyze

AI application logs and telemetry for security anomalies and potential abuse.

OT Position – Additional Responsibilities

  • Apply

AI and cybersecurity security practices to Operational Technology environments, including ICS, SCADA, PLC, DCS, and industrial control systems.

  • Assess

security risks associated with AI-enabled OT applications and autonomous systems.

  • Understand

OT network architecture, segmentation, remote access, industrial protocols, and OT security controls.

  • Support

OT incident response, threat hunting, forensic investigations, and security assessments.

  • Evaluate

the potential impact of AI-driven attacks or compromised AI systems on industrial environments.

  • Work

closely with OT engineering, controls, infrastructure, and cybersecurity teams to identify and mitigate risks.

Required Qualifications

  • Bachelor's

degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related field, or equivalent experience.

  • Strong

cybersecurity engineering, application security, penetration testing, or security assessment experience.

  • Hands-on

experience with AI/ML security, LLM security, Generative AI security, or AI application testing.

  • Understanding

of common LLM and AI vulnerabilities, attack techniques, and security controls.

  • Experience

with OWASP Top 10 and preferably OWASP LLM Top 10 / OWASP Agentic AI security concepts.

  • Experience

with threat modeling, vulnerability assessment, security testing, and risk analysis.

  • Understanding

of authentication, authorization, API security, data protection, and least-privilege principles.

  • Experience

analyzing security findings and providing practical remediation recommendations.

  • Strong

analytical, troubleshooting, documentation, and communication skills.