Job Description
AI Security Specialist / AI Security Lead (CyberProof) Key responsibilities: Support the delivery of the Compass AI Security & Governance Programme, ensuring roadmap activities are progressed and tracked across all workstreams. Develop and operationalise AI security controls, standards and procedures aligned AI Framework Define template AI asset inventories, AI registers, ownership models and market onboarding activities. Support the development of the templates for AI risk taxonomy, exception framework and associated governance processes. Develop plans and processes for technical assessments of AI platforms, AI-enabled applications, AI agents, MCP integrations and embedded vendor AI capabilities. Establish AI security monitoring requirements and work with the Cyber Defence Centre (CDC) to develop detections, use cases, dashboards and reporting. Support shadow AI discovery activities through analysis of Microsoft, AWS, SAP and other available telemetry sources, helping identify unsanctioned AI usage and associated risks. Define security requirements for AI agents, including identity, privilege management, logging, monitoring, recertification and approval processes. Create security guidance for AI development, secure prompt engineering, model consumption and AI-assisted development ("vibe coding") practices. Develop AI incident response processes, playbooks, threat scenarios and tabletop exercises in conjunction with the CDC. Produce management reporting, implementation metrics, control effectiveness measures and quarterly assurance outputs for leadership review.