VAPT + AI Security ( Pentesting with AI Experience)
KPMG Assurance and Consulting Services LLPJob Description
Role Purpose
The Assistant Manager / Manager AI Security is responsible for leading the design, assessment, and validation of secure AI systems across their lifecycle. The role combines AI security architecture, secure-by-design advisory, AI security tooling, and AI red teaming to help organisations deploy AI safely, securely, and at scale.
Key Responsibilities
1 AI Security Architecture & Secure-by-Design Advisory
Lead and review AI security architecture for:
- AI platforms, pipelines, and MLOps environments
- GenAI applications (LLMs, copilots, agents, RAG pipelines)
Define and embed securebydesign principles across:
- Data ingestion and training pipelines
- Model hosting, inference APIs, and AI agents
- Identity, access control, and isolation for AI systems
Advise clients on defenseindepth approaches aligned to:
- Zero Trust (NHI, IAM) for AI
- Enterprise cloud and application security patterns
- AIspecific threat models
2 AI Security Across the AI Lifecycle
Data & Training Phase
- Assess risks related to:
- Data poisoning, bias manipulation, and training data leakage
- Weak provenance, lineage, and thirdparty data dependencies
- Define controls for secure data handling and integrity validation.
Model Development & FineTuning
- Perform AI threat modeling covering:
- Model inversion and extraction
- Backdoored or trojaned models
- Review secure MLOps pipelines, CI/CD controls, and isolation mechanisms.
Deployment & Inference
- Secure AI runtime environments across cloud, containerized, and hybrid setups.
- Define controls for:
- Prompt injection resistance
- Output filtering, guardrails, and misuse prevention
- Abuse scenarios in GenAI and agentbased systems
Monitoring & Operations
- Support AI Security Posture Management (AISPM) and continuous assurance.
AI Red Teaming & Adversarial Testing
Plan and execute AI Red Team engagements, including:
- Prompt injection and jailbreak testing
- Model misuse, data exfiltration, and policy bypass scenarios
- AIenabled attack simulations
Apply industry frameworks such as:
- MITRE ATLAS
- OWASP Top 10 for LLM Applications
- OWASP Agentic AI
- NIST AI RMF
Design custom adversarial scenarios aligned to client context and risk appetite.
Translate red team findings into actionable remediation roadmaps for engineering and leadership teams.
Engagement Leadership & Practice Contribution
- Manage small to midsized AI security engagements or workstreams.
- Act as a subjectmatter resource for AI security across pursuits and proposals.
- Mentor junior team members on AI security concepts and delivery.
- Contribute to thought leadership, playbooks, and internal enablement on AI security and red teaming.
Required Skills & Experience
Strong understanding of cybersecurity fundamentals (IAM, AppSec, Cloud Security, Threat Modeling).
Practical understanding of AI/ML and GenAI architectures, including:
- Model training vs inference
- LLMs, agents, and RAG patterns
Experience with:
- AI security assessments or testing
- Secure MLOps / DevSecOps pipelines
- Offensive security or adversarial testing (preferred)
Preferred Certifications
- CAI/ML Pen Certificate (Certified AI/ML Penetration Testing)
• CEH, OSCP, or equivalent offensive security certification
• GIAC certifications (GPEN, GWAPT, GCTI)
• Cloud Security certifications (AWS / Azure / GCP)
• AI Governance / Responsible AI certifications or NIST AI RMF training
• CISSP / CCSP (advantageous)
No Referrers Available
There are currently no referrers available for this job. You can still apply, will let you know once there is any referrer available.
