- 4 months initial contract with possible extensions
- Hybrid role based in Central Sydney
Data#3 is seeking an experienced AI Security Risk Analyst to support a Cyber Security and AI function with the security assessment of AI capabilities being considered for enterprise use, with an initial focus on an enterprise generative AI platform.
You'll assess plugins and connectors, Model Context Protocol (MCP) capabilities, new AI models, integrations and other AI platform features, applying a practical, risk-based approach to identify material security risks, recommend proportionate controls and inform enablement decisions. You'll also help build a more consistent, scalable approach to these reviews as request volumes grow.
Duties of the role:
- Perform security reviews of AI plugins, connectors, MCP servers and tools, AI models, integrations and platform feature enablement
- Assess authentication, authorisation, OAuth scopes, delegated access, MCP and API permissions and other access models
- Review data flows to determine what organisational information an AI capability can access, process, transmit or expose
- Assess the security implications of read, write, delete, share, tool-use and administrative capabilities
- Assess current LLM, VLM and agentic models and variants, including capabilities, limitations and security implications
- Assess MCP servers, clients and tools, including permissions, trust boundaries, external interactions and access to internal systems and data
- Consider AI-specific risks including prompt injection, unintended data disclosure, excessive agency or permissions,
insecure tool use and interaction with untrusted content
- Identify control gaps and recommend practical controls, restrictions or configuration changes
- Undertake deeper assessment of higher-risk or complex capabilities, engaging vendors and specialists where needed
- Develop and maintain repeatable assessment criteria, checklists and guidance
- Work closely with Cyber Security, AI, application owners and other stakeholders to gather information and validate controls
Skills and experience
- Experience in cyber security risk assessment, security analysis, technology risk or a related discipline
- Demonstrated experience assessing security risks in AI, generative AI, LLMs or AI-enabled applications
- Strong understanding of generative AI technologies (LLMs, VLMs, agentic models) and how they interact with enterprise data and external systems
- Understanding of AI plugins and connectors and the security considerations of connecting AI platforms to enterprise applications
- Understanding of MCP, including servers, clients, tools, permission and trust models, and associated risks
- Understanding of AI-specific risks including prompt injection, data disclosure, excessive agency and insecure tool use
- Solid grasp of identity and access concepts: SSO, OAuth, delegated access, permission scopes and RBAC
- Understanding of APIs, SaaS, cloud services and common enterprise integration patterns
- Ability to interpret data flows, access models, trust boundaries and technical documentation
Interested candidates that meet the required skillset of the role are encouraged to apply via the link with an updated resume. Reference BIHI 114580
📌 Cyber Security Risk Analyst (Sydney)
🏢 Data#3
📍 Sydney