11 сен

security engineer for AI adoption

ориентир по рынку
вакансия зп не указана
в среднем 343 365 ₽
Загрузи резюме, чтобы видеть мэтчи с вакансией

подготовьтесь к отклику

ai-инструменты

Чтобы адаптировать резюме под вакансию или составить сопроводительное письмо, загрузите резюме

описание

Brunswick is a global advisory firm that helps companies address high-stakes issues, navigate complex stakeholder relationships, and achieve high-impact outcomes. It provides expertise across financial and investment, regulatory and geopolitical, NGO, and workforce environments.

задачи

  • Review and assess third-party AI tools, enterprise AI platforms, and new AI-enabled features, including ChatGPT, Claude, Microsoft Copilot, and other emerging technologies;
  • Review and assess requests relating to AI-enabled solutions, enterprise AI platforms, new features, integrations, and internally developed applications;
  • Provide security architecture guidance for applications and solutions developed or introduced by the AI team;
  • Support the implementation of security guardrails, governance processes, and secure design patterns for AI adoption across the firm;
  • Conduct STRIDE-based threat modelling for internally developed solutions, AI-enabled workflows, integrations, and automation use cases;
  • Assess risks associated with AI use cases, including data exposure, prompt injection, model misuse, third-party dependency risk, inappropriate access to sensitive information, and insecure integrations;
  • Advise on secure design principles, including identity and access management, data protection, logging, monitoring, encryption, resilience, and secure configuration;
  • Define and document security requirements, architecture decisions, design recommendations, and risk-based remediation actions;
  • Monitor emerging AI security risks, attacker techniques, and industry best practices, ensuring relevant mitigations are considered within Brunswick's environment.

требования

  • 5–7 Years of experience in cyber security, information security, security engineering, or a related technical security role;
  • Proven experience providing security guidance across technology projects, enterprise platforms, AI-related initiatives, third-party tools, cloud-based solutions, or internally developed applications;
  • Strong understanding of security architecture and secure design principles, including identity and access management, data protection, logging, monitoring, encryption, network security, and resilience;
  • Familiarity with AI-related technologies, enterprise AI platforms, large language models, agentic AI, and the security risks associated with AI adoption;
  • Experience conducting STRIDE-based threat modelling, technical risk assessments, or security design reviews;
  • Practical understanding of cloud and enterprise environments, particularly Microsoft 365, Azure, SaaS platforms, and modern workplace technologies;
  • Ability to translate technical security risks into clear, business-focused recommendations;
  • Strong written and verbal communication skills, with confidence engaging technical and non-technical stakeholders;
  • Understanding of security risks associated with third-party AI tools, internally developed AI applications, integrations, automation, and agent-based use cases;
  • Sound judgement, attention to detail, and the ability to balance security requirements with business needs;
  • Nice to have: Experience working in an ISO27001-aligned or regulated environment, ISC2 CISSP/CCSP/SSCP certifications, ISACA CISM/CISA/CRISC certifications, CompTIA Security+/CySA+/CASP+ certifications.

условия

  • Employee benefits supporting financial future, health and wellness, family and community, and continuous professional development.

Если просят выйти из iCloud, прислать код из SMS, запустить или установить что-то, перевести деньги — не соглашайтесь: это мошенничество.

Про зарплаты

Анонимные данные по зарплатам и грейдам.
Можно сверить вилку с рынком.

Посмотреть зарплаты

Если просят выйти из iCloud, прислать код из SMS, запустить или установить что-то, перевести деньги — не соглашайтесь: это мошенничество.