AI/ML Application Security Analyst
Lead II - Data Science
Who We Are:
Born digital, UST transforms lives through the power of technology. We walk alongside our clients and partners, embedding innovation and agility into everything they do. We help them create transformative experiences and human-centered solutions for a better world.
UST is a mission-driven group of 29,000+ practical problem solvers and creative thinkers in more than 30 countries. Our entrepreneurial teams are empowered to innovate, act nimbly, and create a lasting and sustainable impact for our clients, their customers, and the communities in which we live.
With us, you’ll create a boundless impact that transforms your career—and the lives of people across the world.
Visit us at UST.com.
You Are:
We are seeking a highly skilled and motivated Application Security Analyst to join our dynamic team. In this role, you will be at the forefront of securing our cutting-edge applications and AI/ML systems. You will lead efforts to protect our applications from a wide range of threats, ensuring the integrity, confidentiality, and availability of our data and systems. This position requires understanding of application security, including SSPM using CASB, Zero Trust Security, and advanced application protection techniques.
The opportunity:
· Security Assessment and Implementation:
o Conduct comprehensive security assessments of applications and AI/ML systems to identify vulnerabilities and implement robust security measures.
o Develop and enforce security policies, standards, and procedures to protect against threats such as data breaches, DDoS attacks, and unauthorized data egress.
· SSPM using CASB, and Zero Trust Security:
o Implement and manage SaaS Security Posture Management (SSPM) solutions using existing CASB to ensure continuous security compliance.
o Design and enforce Zero Trust Security frameworks to ensure secure access to applications and data, minimizing the risk of unauthorized access.
· Application Protection:
o Utilize and manage advanced security technologies including web application firewalls (WAF), API security, DDoS protection, bot mitigation, and data loss prevention (DLP) to safeguard applications.
o Continuously monitor and respond to security incidents, performing root cause analysis and implementing corrective actions.
o Leverage AI technologies to enhance the protection of applications, utilizing AI-driven threat detection and response mechanisms.
· Data Egress Responsibility:
o Secure and monitor data movements to prevent unauthorized data egress, ensuring the protection of sensitive information.
o Collaborate with developers, DevOps, and data scientists to implement secure data handling practices and monitor data flows.
· AI/ML Application Security:
o Support the security of AI/ML applications, including integrating security practices into the MLOps pipeline and ensuring the secure deployment of large language models (LLMs).
o Conduct risk assessments, vulnerability scans and implement mitigation strategies for AI/ML-related vulnerabilities. Staying updated on the latest advancements and threats in AI/ML security is critical.
o Stay updated on latest AI/ML security guidelines/governance, not to exclude, OWASP, NIST and ISO/IEC JTC 1/SC 42. Implementing these recommendations with existing AI/ML security infrastructure.
· Collaboration and Communication:
o Work closely with cross-functional teams to integrate security practices into the application development lifecycle, fostering a culture of security awareness.
o Provide security training and awareness programs for developers, DevOps, and other stakeholders to enhance the overall security posture of the organization.
This position description identifies the responsibilities and tasks typically associated with the performance of the position. Other relevant essential functions may be required.
What you need:
· Bachelor’s or Master’s degree in Computer Science, Cybersecurity, Data Science, or a related field.
· Experience:
· 7+ years of experience in application security, cybersecurity, or a related field.
· Proven experience with SSPM, ASPM, CSPM, and Zero Trust Security frameworks.
· Familiarity with AI/ML security, including MLSecOps, GenAI and LLMs.
· Skills:
· Strong knowledge of web application firewall (WAF), API security, DDoS protection, bot mitigation, runtime application self-protection (RASP), and data loss prevention (DLP) technologies.
· Proficiency in programming languages such as Python, Java, or C++.
· Preferred Qualifications:
· Certifications:
· CISSP, CISM, CompTIA Security+, CAITI, or equivalent.
· Certifications in cloud security (e.g., AWS Certified Security Specialty, Azure Security Engineer Associate).
· Additional Skills:
· Experience with cloud platforms (AWS, Azure, Google Cloud).
· Experience/knowledge of GenAI security monitoring tools
· Knowledge of regulatory compliance standards (e.g., GDPR, CCPA)
Compensation can differ depending on factors including but not limited to the specific office location, role, skill set, education, and level of experience. UST provides a reasonable range of compensation for roles that may be hired in various U.S. markets as set forth below.
Role Location: Ontario
Compensation Range: $98,000-$120,000
Benefits
Full-time, regular employees accrue a minimum of 10 days of paid vacation per year, receive 6 days of paid sick leave each year (pro-rated for new hires throughout the year), paid holidays, and are eligible for paid bereavement leave and jury duty. They and their dependents residing in Canada are eligible for Supplemental Healthcare coverage, as well as Company-paid Employee Only basic life insurance and accidental death and dismemberment coverage.
Full-time temporary employees receive 6 days of paid sick leave each year (pro-rated for new hires throughout the year). They and their dependents residing in Canada are eligible for Supplemental Healthcare coverage, as well as Company-paid Employee Only basic life insurance and accidental death and dismemberment coverage.
Part-time regular and temporary employees receive 6 days of paid sick leave each year (pro-rated for new hires throughout the year).
All Canadian employees who work in a province, territory or locality with more generous paid sick leave benefits than specified here will receive the benefit of those sick leave laws.
What we believe:
We proudly embrace the values that have shaped UST since day one. We build our culture of Humility, Humanity, and Integrity. These values inspire us to nurture a people-first, human centric culture that fosters diversity, prioritizes sustainable solutions, and keeps our people and clients at the forefront of all decisions.
Humility:
We will listen, learn, be empathetic and help selflessly in our interactions with everyone.
Humanity:
Through business, we will better the lives of those less fortunate than ourselves.
Integrity:
We honor our commitments and act with responsibility in all our relationships.
An Equal Opportunity Workplace, Free of Discrimination and Harassment
At UST, we strive to provide a work environment free of discrimination and harassment. We are an equal opportunity employer and employment decisions are based on merit and business needs. Our Human Rights Policy further illustrates our stand on this. We are committed to following fair employment practices that provide equal opportunities to all employees. We do not discriminate or allow harassment on the basis of race, color, religion, disability, gender, national origin, sexual orientation, gender identity, gender expression, age, genetic information, military status, or any other legally protected status. At UST, we value diversity and believe that a diverse workplace builds a competitive advantage.
Un lieu de travail à égalité des chances, sans Discrimination et harcèlement
Chez UST, nous nous efforçons de fournir un environnement de travail exempt de discrimination et harcèlement. Nous sommes un employeur garantissant l'égalité des chances et des décisions en matière d'emploi sont basés sur le mérite et les besoins de l'entreprise. Notre politique en matière de droits de l'homme illustre notre position à ce sujet. Nous nous engageons à respecter un emploi équitable des pratiques qui offrent des chances égales à tous les employés. Nous ne faisons pas discriminer ou permettre le harcèlement sur la base de la race, de la couleur, de la religion, du handicap, genre, origine nationale, orientation sexuelle, identité de genre, expression de genre, âge, informations génétiques, statut militaire ou tout autre statut légalement protégé. Chez UST, nous valorisons la diversité et pensons qu'un lieu de travail diversifié crée un avantage compétitif.
UST reserves the right to periodically redefine your roles and responsibilities based on the requirements of the organization and/or your performance.
#UST
#LI-MK2