- Experience
- 8+ yrs
- Salary
- —
- Openings
- 1
- Posted
- 4 hours ago
- Work mode
- In office
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
About the Role
Kerry Consulting is looking for a seasoned AI Security Risk Manager to oversee and challenge the organization's use of AI, Generative AI, and other emerging technologies. This position centers on identifying and mitigating cybersecurity, technology, and data risks connected to AI solutions while collaborating with Technology, Cybersecurity, Data, and Business teams to ensure secure and responsible AI adoption.
Key Responsibilities
- Oversee risk management efforts related to AI, Machine Learning, and Generative AI projects.
- Perform comprehensive security risk assessments across the entire AI lifecycle from design through development, deployment, and continuous operation.
- Analyze AI-specific vulnerabilities such as prompt injection, data leaks, model tampering, insecure integrations, and excessive autonomous behaviors.
- Evaluate security controls related to AI applications, models, APIs, data pipelines, and associated cloud infrastructure.
- Assess data protection measures including access controls, encryption, data loss prevention (DLP), and identity management within AI environments.
- Review security testing methodologies such as vulnerability assessments, adversarial testing, and AI red-teaming activities.
- Assess risks from third-party AI platforms, models, and service providers.
- Develop and continually improve AI security risk frameworks, policies, standards, and baseline control requirements.
- Conduct thematic reviews, track control deficiencies, risk acceptances, and remediation efforts.
- Advise on risks related to emerging technologies like large language models (LLMs), AI agents, and AI-powered applications.
- Stay updated on evolving AI threats, regulations, and industry standards, evaluating their impact on the organization.
- Communicate significant AI security risks and suggestions to senior leaders and governance groups.
Qualifications and Experience
- Over eight years of professional experience in cybersecurity, technology risk, information security, security architecture, or technology assurance.
- Solid grasp of cybersecurity, technology risk, and control frameworks.
- Sound knowledge of AI, Machine Learning, Generative AI, and LLM technologies alongside their inherent security risks.
- Familiarity with application security, cloud security, APIs, identity and access management (IAM), data protection, vulnerability management, and DevSecOps practices.
- Experience performing technology and security risk assessments and evaluating control effectiveness.
- Preferably acquainted with NIST AI Risk Management Framework (RMF), ISO 27001, ISO 42001, MITRE ATLAS, and OWASP AI/LLM guidelines.
- Strong ability to manage stakeholders and translate complex technical risks into understandable business implications.
- Holding certifications such as CISSP, CISM, CRISC, or CCSP is advantageous.
Additional Information
Interested candidates should submit their resumes or contact Chen Yi directly at the provided email for a discussion. Due to a high volume of applications, only shortlisted candidates will be contacted. Registration: R1876389 License: 16S8060
Industry
IT Services & Consulting