Чтобы адаптировать резюме под вакансию или составить сопроводительное письмо, загрузите резюме
описание
Brunswick is a global advisory firm that helps companies address high-stakes issues, navigate complex stakeholder relationships, and achieve high-impact outcomes. It provides expertise across financial and investment, regulatory and geopolitical, NGO, and workforce environments.
задачи
Review and assess third-party AI tools, enterprise AI platforms, and new AI-enabled features, including ChatGPT, Claude, Microsoft Copilot, and other emerging technologies;
Review and assess requests relating to AI-enabled solutions, enterprise AI platforms, new features, integrations, and internally developed applications;
Provide security architecture guidance for applications and solutions developed or introduced by the AI team;
Support the implementation of security guardrails, governance processes, and secure design patterns for AI adoption across the firm;
Conduct STRIDE-based threat modelling for internally developed solutions, AI-enabled workflows, integrations, and automation use cases;
Assess risks associated with AI use cases, including data exposure, prompt injection, model misuse, third-party dependency risk, inappropriate access to sensitive information, and insecure integrations;
Advise on secure design principles, including identity and access management, data protection, logging, monitoring, encryption, resilience, and secure configuration;
Define and document security requirements, architecture decisions, design recommendations, and risk-based remediation actions;
Monitor emerging AI security risks, attacker techniques, and industry best practices, ensuring relevant mitigations are considered within Brunswick's environment.
требования
5–7 Years of experience in cyber security, information security, security engineering, or a related technical security role;
Proven experience providing security guidance across technology projects, enterprise platforms, AI-related initiatives, third-party tools, cloud-based solutions, or internally developed applications;
Strong understanding of security architecture and secure design principles, including identity and access management, data protection, logging, monitoring, encryption, network security, and resilience;
Familiarity with AI-related technologies, enterprise AI platforms, large language models, agentic AI, and the security risks associated with AI adoption;
Practical understanding of cloud and enterprise environments, particularly Microsoft 365, Azure, SaaS platforms, and modern workplace technologies;
Ability to translate technical security risks into clear, business-focused recommendations;
Strong written and verbal communication skills, with confidence engaging technical and non-technical stakeholders;
Understanding of security risks associated with third-party AI tools, internally developed AI applications, integrations, automation, and agent-based use cases;
Sound judgement, attention to detail, and the ability to balance security requirements with business needs;
Nice to have: Experience working in an ISO27001-aligned or regulated environment, ISC2 CISSP/CCSP/SSCP certifications, ISACA CISM/CISA/CRISC certifications, CompTIA Security+/CySA+/CASP+ certifications.
условия
Employee benefits supporting financial future, health and wellness, family and community, and continuous professional development.