Senior Associate, National Security-Cyber Security Governance
Occupations:
Information Security AnalystsInformation Security EngineersSecurity Management SpecialistsCompliance ManagersSecurity ManagersIndustries:
Junior CollegesComputer Systems Design and Related ServicesAdministration of Human Resource ProgramsNational Security and International AffairsManagement of Companies and EnterprisesDescriptionAbout Alvarez & MarsalAlvarez & Marsal (A&M) is a global consulting firm with over 10,000 entrepreneurial, action and results-oriented professionals in over 40 countries. We take a hands-on approach to solving our clients' problems and assisting them in reaching their potential. Our culture celebrates independent thinkers and doers who positively impact our clients and shape our industry. The collaborative environment and engaging work-guided by A&M's core values of Integrity, Quality, Objectivity, Fun, Personal Reward, and Inclusive Diversity-are why our people love working at A&M.The teamAt A&M you will have the opportunity to work with a diverse team of supportive and motivated professionals that love to share their knowledge and depth of industry experience with others. A&M's Disputes and Investigations practice comprises professionals from a wide range of backgrounds, who bring and share their deep expertise in conducting investigations and delivering expert witness reports. We have an inclusive developmental environment where everyone has the opportunity to learn and grow. Our culture is characterized by openness and entrepreneurial thinking, with a foundation of mutual respect and high-quality standards for our work. We strive to remove bureaucracy in favor of recognizing effort and results through advancement opportunities and a motivating performance-based reward structure.How you will contributeWith the rapid adoption of AI technologies and evolving regulatory landscape, demand for AI-focused security analysis and compliance expertise is growing exponentially. Our team supports organizations, investors and counsel in identifying, assessing, and mitigating risks associated with AI system deployment, algorithmic bias, data privacy, and model security. We focus on implementing secure AI/ML pipelines, establishing AI governance frameworks, conducting model risk assessments, and ensuring compliance with emerging AI regulations. Our approach integrates traditional cybersecurity with AI-specific security controls, leveraging automated testing, model monitoring, and adversarial robustness techniques. The team serves as trusted advisors to organizations navigating AI regulatory requirements, security certifications, and responsible AI implementation.Responsibilities:Lead technical teams in executing AI security assessments, model audits, and compliance reviews related to AI Act (EU), NIST AI Risk Management Framework, ISO/IEC 23053/23894, and emerging AI governance standards. Develop AI risk assessment methodologies and implement continuous monitoring solutions for production ML systems.Design and implement secure AI/ML architectures incorporating MLOps security practices, including model versioning, data lineage tracking, feature store security, and secure model deployment pipelines. Integrate security controls for Large Language Models (LLMs), including prompt injection prevention, output filtering, and embedding security.Conduct technical assessments of AI/ML systems using tools such as:AI Security Tools: Adversarial Robustness Toolbox (ART), Foolbox, CleverHans for adversarial testingMLOps Platforms: MLflow, Kubeflow, Amazon SageMaker, Azure ML, Google Vertex AIModel Monitoring: Evidently AI, Fiddler AI, WhyLabs, Neptune.ai for drift detection and explainabilityLLM Security: Guardrails AI, NeMo Guardrails, LangChain security modules, OWASP LLM Top 10 toolsPrivacy-Preserving ML: PySyft, TensorFlow Privacy, Opacus for differential privacy implementationImplement AI compliance and governance solutions addressing:Regulatory Frameworks: EU AI Act, Canada's AIDA, US AI Executive Orders, Singapore's Model AI Governance FrameworkIndustry Standards: ISO/IEC 23053, ISO/IEC 23894, IEEE 7000 series, NIST AI RMFSector-Specific Requirements: FDA AI/ML medical device regulations, GDPR Article 22 (automated decision-making), SR 11-7 model risk managementDevelop and execute penetration testing specifically for AI systems, including:Model extraction attacks and defensesData poisoning vulnerability assessmentsMembership inference and model inversion testingPrompt injection and jailbreaking assessments for LLMsBackdoor detection in neural networksProgram and deploy custom security solutions using:Languages: Python (PyTorch, TensorFlow, scikit-learn), R, JuliaAI Frameworks: Hugging Face Transformers, LangChain, LlamaIndex, AutoML toolsSecurity Libraries: SHAP, LIME for explainability; Fairlearn, AIF360 for bias detectionInfrastructure: Docker, Kubernetes, Terraform for secure AI deploymentIntegrate AI security with traditional security frameworks including Zero Trust architecture, IAM solutions, and SIEM platforms. Implement automated compliance monitoring using AI-powered security orchestration tools (SOAR platforms like Splunk Phantom, Palo Alto Cortex XSOAR).Assess and mitigate risks in:Foundation models and transfer learning implementationsFederated learning systemsEdge AI deploymentsMulti-modal AI systemsGenerative AI applications (GPT, DALL-E, Stable Diffusion implementations)Create technical documentation including AI system security architecture reviews, threat models specific to ML pipelines, compliance mappings, and remediation roadmaps aligned with both traditional security standards (NIST 800-53, ISO 27001) and AI-specific frameworks.Availability for up to 15% travel required to client sites and assessment locations.Qualifications:3+ years of experience in AI/ML development, deployment, or security assessment2+ years of experience in information security, with focus on application security or cloud securityHands-on experience with AI/ML frameworks (TensorFlow, PyTorch, scikit-learn, Hugging Face)Proficiency in Python programming with experience in AI/ML libraries and security testing toolsExperience with cloud AI platforms (AWS SageMaker, Azure ML, Google Vertex AI, Databricks)Knowledge of AI compliance frameworks: NIST AI RMF, EU AI Act requirements, ISO/IEC 23053/23894Experience with MLOps tools and secure model deployment practicesUnderstanding of adversarial machine learning and AI security threats (OWASP ML Top 10, ATLAS framework)Familiarity with privacy-preserving ML techniques (differential privacy, federated learning, homomorphic encryption basics)Experience with containerization (Docker, Kubernetes) and infrastructure as codeKnowledge of traditional security frameworks (NIST CSF, NIST 800-53, ISO 27001)Ability to obtain a USG security clearancePreferred Certifications:One or more AI/ML certifications: AWS Certified Machine Learning, Google Cloud Professional ML Engineer, Azure AI EngineerSecurity certifications: CISSP, CCSP, CompTIA Security+, CEHSpecialized: GIAC AI Security Essentials (GAISE), Certified AI Auditor (when available)Your journey at A&MWe recognize that our people are the driving force behind our success, which is why we prioritize an employee experience that fosters each person's unique professional and personal development. Our robust performance development process promotes continuous learning, rewards your contributions, and fosters a culture of meritocracy. With top-notch training and on-the-job learning opportunities, you can acquire new skills and advance your career.We prioritize your well-being, providing benefits and resources to support you on your personal journey. Our people consistently highlight the growth opportunities, our unique, entrepreneurial culture, and the fun we have together as their favorite aspects of working at A&M. The possibilities are endless for high-performing and passionate professionals.Regular employees working 30 or more hours per week are also entitled to participate in Alvarez & Marsal Holdings' fringe benefits consisting of healthcare plans, flexible spending and savings accounts, life, AD&D, and disability coverages at rates determined periodically as well as a 401(k) retirement savings plan. Provided the eligibility requirements are met, employees will also receive an annual discretionary contribution to their 401(k) retirement savings plan from Alvarez & Marsal. Additionally, employees are eligible for paid time off including vacation, personal days, seventy-two (72) hours of sick time (prorated for part time employees), ten federal holidays, one floating holiday, and parental leave. The amount of vacation and personal days available varies based on tenure and role type. Click here for more information regarding A&M's benefits programsThe salary range is $80,000 - $110,000 annually, dependent on several variables including but not limited to education, experience, skills, and geography. In addition, A&M offers a discretionary bonus program which is based on a number of factors, including individual and firm performance. Please ask your recruiter for details.Alvarez & Marsal recruits on an ongoing basis. Candidates are considered as they apply, until the opportunity is filled. Candidates are encouraged to apply expeditiously to any role(s) that they are qualified for and that are of interest to them.A&M does not require or administer lie detector tests as a condition of employment or continued employment. It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.#LI-NM1Inclusive DiversityA&M's entrepreneurial culture celebrates independent thinkers and doers who can positively impact our clients and shape our industry. The collaborative environment and engaging work-guided by A&M's core values of Integrity, Quality, Objectivity, Fun, Personal Reward, and Inclusive Diversity-are the main reasons our people love working at A&M. Inclusive Diversity means we embrace diversity, and we foster inclusiveness, encouraging everyone to bring their whole self to work each day. It runs through how we recruit, develop employees, conduct business, support clients, and partner with vendors. It is the A&M way.Equal Opportunity EmployerIt is Alvarez & Marsal's practice to provide and promote equal opportunity in employment, compensation, and other terms and conditions of employment without discrimination because of race, color, creed, religion, national origin, ancestry, citizenship status, sex or gender, gender identity or gender expression (including transgender status), sexual orientation, marital status, military service and veteran status, physical or mental disability, family medical history, genetic information or other protected medical condition, political affiliation, or any other characteristic protected by and in accordance with applicable laws. Employees and Applicants can find A&M policy statements and additional information by region here.Unsolicited Resumes from Third-Party RecruitersPlease note that as per A&M policy, we do not accept unsolicited resumes from third-party recruiters unless such recruiters are engaged to provide candidates for a specified opening. Any employment agency, person or entity that submits an unsolicited resume does so with the understanding that A&M will have the right to hire that applicant at its discretion without any fee owed to the submitting employment agency, person or entity.