Cyber AI Security & Forensic Engineer – IT & OT
3Core Systems , Inc
- Location
- Hybrid (Denver, Colorado)
- Employment
- Contract
- Level
- Senior Level
About the Role
3Core Systems is seeking Cyber AI Security & Forensic Engineers to identify and mitigate cybersecurity risks associated with AI, LLMs, and autonomous systems within IT and OT environments. The role involves performing security testing, threat modeling, and collaborating with teams to remediate vulnerabilities in enterprise and industrial control systems.
Skills
Full job details
Cyber AI Security & Forensic Engineer – IT & OT
Job Summary
We are seeking experienced Cyber AI Security &
Forensic Engineers to help identify, assess, and mitigate emerging
cybersecurity risks associated with Artificial Intelligence, Large Language
Models (LLMs), Generative AI, and autonomous/agentic AI systems.
There are two openings for this position:
- IT
Cyber AI Security & Forensic Engineer: Focused on enterprise
applications, cloud environments, LLM/GenAI applications, APIs, AI agents,
and application security.
- OT
Cyber AI Security & Forensic Engineer: Focused on applying AI
security and cybersecurity principles within Operational Technology
(OT), Industrial Control Systems (ICS), SCADA, and industrial environments.
The ideal candidates will have a strong cybersecurity
foundation combined with hands-on experience assessing AI/LLM applications,
identifying vulnerabilities and bypass techniques, recommending security
controls, and applying security frameworks such as OWASP.
Key Responsibilities
- Perform
security testing of AI applications, LLMs, Generative AI solutions, and
AI-enabled platforms to identify vulnerabilities, weaknesses, misuse
cases, and potential bypass techniques.
- Conduct
AI/LLM security assessments, including testing for prompt injection,
jailbreaks, data leakage, insecure outputs, model manipulation, and
unauthorized access.
- Evaluate
AI applications and integrations for security weaknesses across APIs, data
sources, tools, plugins, and external services.
- Assess agentic AI architectures and autonomous software agents to
understand how agents interact with external tools, APIs, data, and
enterprise systems.
- Evaluate
agent permissions, tool access, authentication, authorization, and
least-privilege controls.
- Identify
risks associated with excessive agency, insecure tool use, indirect prompt
injection, and unauthorized actions.
- Recommend
secure AI and data usage practices, including data protection,
access controls, secure prompts, guardrails, and responsible AI practices.
- Apply OWASP
Top 10, OWASP API Security Top 10, OWASP LLM Top 10, and other
applicable security standards to identify and communicate security risks.
- Perform
threat modeling and security assessments for AI-enabled applications and
services.
- Work
with application, cloud, data, infrastructure, and cybersecurity teams to
remediate identified vulnerabilities.
- Support
vulnerability management, incident investigations, digital forensics, and
root-cause analysis where required.
- Review
logs, telemetry, application behavior, and security events to identify
suspicious or malicious AI activity.
- Develop
security recommendations, assessment reports, remediation plans, and
technical documentation.
- Stay
current with emerging AI attack techniques, LLM vulnerabilities, agentic
AI risks, and AI security frameworks.
IT Position – Additional Responsibilities
- Assess
security of enterprise LLM/GenAI applications, APIs, cloud services,
RAG solutions, vector databases, and AI integrations.
- Test
AI applications for prompt injection, jailbreaks, sensitive information
disclosure, insecure output handling, and data poisoning.
- Review
AI integrations with enterprise applications, SaaS platforms, APIs, and
external tools.
- Evaluate
cloud security controls across AWS, Azure, or GCP environments.
- Support
application security, API security, secure SDLC, SAST/DAST, and DevSecOps
initiatives.
- Analyze
AI application logs and telemetry for security anomalies and potential
abuse.
OT Position – Additional Responsibilities
- Apply
AI and cybersecurity security practices to Operational Technology
environments, including ICS, SCADA, PLC, DCS, and industrial control
systems.
- Assess
security risks associated with AI-enabled OT applications and autonomous
systems.
- Understand
OT network architecture, segmentation, remote access, industrial
protocols, and OT security controls.
- Support
OT incident response, threat hunting, forensic investigations, and
security assessments.
- Evaluate
the potential impact of AI-driven attacks or compromised AI systems on
industrial environments.
- Work
closely with OT engineering, controls, infrastructure, and cybersecurity
teams to identify and mitigate risks.
Required Qualifications
- Bachelor's
degree in Cybersecurity, Computer Science, Information Technology,
Engineering, or a related field, or equivalent experience.
- Strong
cybersecurity engineering, application security, penetration testing, or
security assessment experience.
- Hands-on
experience with AI/ML security, LLM security, Generative AI security,
or AI application testing.
- Understanding
of common LLM and AI vulnerabilities, attack techniques, and security
controls.
- Experience
with OWASP Top 10 and preferably OWASP LLM Top 10 / OWASP
Agentic AI security concepts.
- Experience
with threat modeling, vulnerability assessment, security testing, and risk
analysis.
- Understanding
of authentication, authorization, API security, data protection, and
least-privilege principles.
- Experience
analyzing security findings and providing practical remediation
recommendations.
- Strong
analytical, troubleshooting, documentation, and communication skills.