Overview
AI Security Analyst responsible for detecting, investigating, and containing risk across AI tools, agents, and models used in AlphaSense’s environment.
What you'll do
- Continuously monitor CASB/SWG, OAuth, and endpoint telemetry to discover unsanctioned AI tools and API-level agents.
- Classify shadow AI findings by risk tier and escalate unauthorized deployments for containment.
- Investigate alerts for autonomous agents and AI-powered workflows, including anomalous tool chains and credential misuse.
- Monitor DLP and AI usage logs for signs of sensitive data exfiltration via AI tools and connectors.
- Govern developer-facing AI tools by checking policy compliance and credential exposure.
- Maintain and validate AI activity logging and data retention controls for auditability.
- Tune AI security detections by analyzing false positive/negative trends and improving thresholds and logic.
What you'll need
- 3–5+ years in security analysis, SOC, or GRC analyst roles.
- Working knowledge of SIEM platforms including Splunk, Microsoft Sentinel, or Google Chronicle.
- Working knowledge of DLP/CASB tooling.
- Understanding of AI/LLM risk concepts including prompt injection, data exfiltration, model/agent misuse, and shadow AI.
- Familiarity with non-human identity concepts (service accounts, API keys, OAuth tokens).
- Comfort reading and interpreting logs and API telemetry for investigations.
- Basic scripting/query proficiency (Python, SQL, or SPL/KQL) for investigation and reporting.
Nice to have
- Exposure to AI governance frameworks such as ISO 42001, NIST AI RMF, or EU AI Act risk tiers.
- Experience supporting audit evidence collection or control testing (e.g., SOC 2, ISO).
- Familiarity with agentic AI frameworks (LangChain, AutoGen, CrewAI) and MCP-based tool-use architectures.