Haystack
← Back to Jobs
Remote
Technology
OO

Security Analyst III

Opusing One, LLCUnited States🇺🇸United StatesPosted Oct 7, 2026

Quick Overview

Seniority
Mid Senior
Work mode
Remote
Location
United States
Posted
21 hours ago
AWSAzureGoogle CloudDatabricksLLMGenerative AIMLflowOWASP

Job Description

Job Title:                  Security Analyst III

Job Location:           Remote

Job Duration:          6+ months contract  

 

Job Description :
Position Location: remote Position Summary: This is a cybersecurity individual responsible for reducing security risk across enterprise software development, applications, artificial intelligence systems, cloud environments, and emerging technologies.

This role combines DevSecOps and Application Security with specialized expertise in AI Security and AI governance enablement. The Application and AI Security Senior Engineer develops and matures scalable security capabilities across the software development lifecycle, including SAST, DAST, software composition analysis, Software and AI-BOM, package and dependency management, container scanning, vulnerability management, and AI red teaming.

The position also supports the secure adoption of traditional AI/ML, Generative AI, AI[1]enabled applications, AI agents, agentic systems, coding assistants, models, APIs, Retrieval-Augmented Generation, and AI development platforms.

The Application and AI Security Senior Engineer partners with development, DevOps, cloud, architecture, Data & AI, Product Security, and governance teams to embed automated security controls into technology lifecycles and translate emerging threats into practical, risk-based requirements.

Business Use

Job Responsibilities

DevSecOps & Application Security

• Develop, implement, and mature DevSecOps capabilities that integrate automated security testing and vulnerability detection into software development and CI/CD processes.

• Support and optimize Static Application Security Testing and Dynamic Application Security Testing, including pipeline integration, finding validation, prioritization, and remediation workflows.

• Advance Software Bill of Materials and AI Bill of Materials capabilities to improve visibility into applications, packages, libraries, models, AI components, and software and AI supply-chain dependencies.

• Support Software Composition Analysis, package and dependency management, and open-source software governance, including identification of vulnerable, obsolete, malicious, or unapproved components.

• Develop and mature container and container-image scanning to identify vulnerable packages, embedded secrets, configuration weaknesses, malware, and other risks before deployment.

• Embed security controls into source-code repositories, CI/CD pipelines, artifact repositories, container registries, and software release processes.

• Establish risk-based vulnerability management practices and partner with development teams to validate findings, prioritize material risk, and drive remediation.

• Develop and mature AI security testing and red-teaming capabilities for AI-enabled applications, models, and agents.

• Conduct or coordinate adversarial testing for prompt injection, jailbreaks, sensitive[1]data disclosure, system prompt extraction, insecure RAG, unauthorized tool invocation, excessive agency, and misuse of agent permissions.

• Evaluate automated AI testing capabilities, including model scanning, prompt and agent testing, runtime validation, and continuous security assessment. Translate findings into remediation requirements and reusable preventive controls.

Business Use

• Assess the security implications of AI-assisted development and agentic coding tools, including access to source code, repositories, packages, credentials, development environments, and CI/CD processes.

• Perform Product Security reviews of new or materially changed applications and technologies to identify significant cybersecurity risks and establish appropriate security requirements.

AI Security

• Perform technical security assessments of AI-enabled applications, models, platforms, GenAI services, AI agents, agentic workflows, machine-learning systems, and AI-enabled SaaS products.

• Evaluate threats including prompt and indirect prompt injections, data disclosure, excessive agency, insecure tool access, model and data poisoning, insecure output handling, untrusted RAG content, AI supply-chain compromise, excessive privilege, shadow AI, and unauthorized agent actions.

• Review AI architectures and components, including models, APIs, identities, data flows, data sources, RAG implementations, tools, actions, integrations, hosting environments, and external model or service providers.

• Evaluate controls for authentication and authorization, model and API access, data protection, AI guardrails, input/output security, DLP, RAG security, logging and observability, human oversight, and runtime protection.

• Develop and maintain AI security controls, technical standards, guardrails, assessment methodologies, architecture patterns, and implementation guidance.

AI Agent & Emerging Technology Security

• Assess AI agents and agentic systems for risks associated with autonomy, identity, delegated authority, data access, memory, orchestration, tools, integrations, and actions.

• Evaluate agent identities, service principals, authorization models, APIs, connectors, plugins, MCP-based integrations, least privilege, and human-in-the[1]loop controls.

• Determine whether agent permissions and actions operate within appropriate authority boundaries and whether consequential actions have sufficient human oversight, logging, and auditability.

Business Use

• Evaluate emerging AI models, agent frameworks, coding assistants, open-source and open-weight technologies, protocols, and security products.

• Analyze unfamiliar technologies to determine how AI is used, which models and providers are involved, what data is processed, what permissions and external connections exist, and which security controls are required.

AI Governance, Inventory & Security Posture • Provide technical cybersecurity expertise supporting AI governance, AI use-case assessments, technology intake, risk management, and security review processes.

• Support discovery and inventory of AI applications, models, agents, services, APIs, integrations, development tools, MCP servers, and supporting components, including approved, embedded, unmanaged, and shadow AI.

• Advance AI SBOM and component inventory practices to provide traceability across models, software libraries, services, APIs, data sources, tools, and dependencies.

• Support continuous AI security posture management through telemetry, monitoring, control validation, metrics, remediation tracking, and governance evidence.

• Evaluate third-party AI and SaaS providers for model usage, data processing, retention, tenant isolation, identity integration, access controls, logging, external providers, and software or AI supply-chain dependencies.

Required Experience

• Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, Engineering, or related discipline, or equivalent professional experience.

• Five or more years of experience in cybersecurity, DevSecOps, Application Security, Product Security, software engineering security, cloud security, AI security, or a comparable technical security discipline.

• Demonstrated experience with several Application Security and DevSecOps capabilities, including SAST and DAST, software composition analysis (SCA), SBOM generation and management, Package and dependency management, Container and image scanning, CI/CD and repository security, Open-source software security, Vulnerability management and remediation • Experience with AI security testing, AI red teaming, Generative AI security, or adversarial testing strongly preferred.

Business Use

• Working knowledge of LLM and GenAI architectures, RAG, agentic systems, model APIs, and associated security considerations - including prompt-injection risks, AI supply-chain security, guardrails, observability, and agent identities and permissions.

• Experience with enterprise cloud, development, container, and AI ecosystems such as Microsoft Azure, Azure DevOps, GitHub Enterprise, GitHub Copilot, Microsoft AI services, Copilot Studio, Azure Databricks, MLflow, AWS, or Google Cloud.

• Experience assessing third-party SaaS, AI services, models, open-source software, development tools, and technology supply-chain components.

• Familiarity with NIST CSF, NIST AI RMF, NIST SSDF, OWASP application and API security, OWASP AI and LLM security guidance, secure development, and threat modeling.

• Relevant certifications such as CISSP, CSSLP, CCSP, GIAC, or cloud security certifications are preferred but not required.

• Strong technical curiosity and the ability to rapidly evaluate unfamiliar technologies, architectures, vulnerabilities, and emerging threats.

• Strong communication skills and ability to interface with technical and non[1]technical resources to include senior leaders.

• Ability to distinguish material risks from theoretical concerns and translate technical findings into practical remediation requirements, preventive controls, automation opportunities, and risk-based recommendations.

Similar jobs