adpLeesburg, VA
AI SECURITY ARCHITECT
$140,000 per year
Apply →AI SECURITY ARCHITECT
AI SECURITY ARCHITECT
adpLeesburg, VA
yesterday
$140,000 per year
Computer Systems Design ServicesOther Scientific and Technical Consulting ServicesAll Other Professional, Scientific, and Technical Services
Apply for this role →Salary Range: $140,000.00 To $150,000.00 Annually
About the Role:
Triple Point Security is looking for an AI Security Architect to help a national research organization explore how artificial intelligence can support its enterprise Zero Trust program. You will identify and prioritize potential AI use cases across the Zero Trust pillars, assess how well AI-based approaches address specific Zero Trust threats compared with existing tools, and help make sure recommended capabilities can be governed and authorized under Federal and HHS AI policy.
You will be part of the Risk, Authorization & AI team, reporting to the program's Security Lead and working closely with an ML/Data Engineer and our Lead Zero Trust Architect. The role builds on secure AI adoption work Triple Point already supports for this client.
This role includes regular client interaction. You will present findings and recommendations to client security and technology leadership, facilitate use case discovery workshops and working sessions with client stakeholders, and help explain AI concepts to audiences with varying levels of technical background. Your work will have a meaningful impact on the medical and scientific communities our client serves.
Required Qualifications:
Bachelor's degree in Computer Science, Information Systems, Cybersecurity, Data Science, or a related field from an accredited university
3 to 5 years of experience in cybersecurity architecture, security engineering, or a closely related technical discipline, including hands-on work involving AI/ML systems, security analytics, or detection engineering
Working knowledge of Zero Trust principles, including NIST SP 800-207 and the CISA Zero Trust Maturity Model (ZTMM) v2.0 pillars and cross-cutting capabilities
Understanding of how AI and machine learning are applied in security, including user and entity behavior analytics (UEBA), anomaly detection, risk scoring, and classification, and of their practical limits: false positives, model drift, data dependencies, and explainability
Working knowledge of AI and LLM-specific risks and attack classes, including prompt injection, training and retrieval data poisoning, model extraction, insecure output handling, sensitive data leakage, and excessive agency in agentic systems
Familiarity with AI risk frameworks, including the NIST AI Risk Management Framework (AI 100-1) and Generative AI Profile (NIST AI 600-1), the OWASP Top 10 for LLM Applications, and MITRE ATLAS
Working knowledge of NIST SP 800-53 Rev. 5 and how established Federal security controls apply to AI-enabled systems
Experience evaluating technologies against defined criteria and producing structured assessments, evaluation plans, or analyses of alternatives
Hands-on experience in at least one major cloud service provider (AWS, Azure, or GCP), including its AI services (e.g., Amazon Bedrock, Azure OpenAI/AI Foundry, Google Vertex AI)
Proficiency in Python or a comparable language sufficient to prototype, test, and review data pipelines and model integrations
Strong written communication skills, including the ability to produce data flow diagrams, architecture documentation, and risk assessments for both engineering teams and non-engineering leadership
Client-facing experience, including presenting technical findings to leadership, facilitating workshops or working sessions, and explaining technical topics clearly to non-technical audiences
Preferred Qualifications:
Master's degree in Cybersecurity, Computer Science, Data Science, or a related field
Experience supporting Federal civilian agencies, particularly HHS or other research and health organizations
Experience with SIEM, SOAR, and security analytics platforms such as Splunk, Microsoft Sentinel, or the ELK stack, including detection design for identity threats and credential misuse
Experience designing evaluation methods for security capabilities without large labeled datasets, such as shadow-mode operation, synthetic adversary injection, purple-team exercises, and drift monitoring with defined revalidation cadences
Experience red teaming or adversarially testing LLM, RAG, or agentic AI systems, and securing agent identities, entitlements, and tool use
Familiarity with OMB AI policy for Federal agencies (including OMB M-25-21), Federal AI use case inventory reporting, and HHS AI governance requirements
Experience with data governance and privacy for security telemetry, including data classification, retention, boundary controls, and handling of PII and PHI
Familiarity with ZT enabling technologies such as ICAM, device posture and EDR, micro-segmentation, and policy decision/enforcement points
Experience with LLM gateways and orchestration platforms (e.g., LiteLLM, LibreChat) and cloud-native AI guardrail services
Experience developing and delivering training, briefings, or workshops on AI or security topics
Prior experience in a consulting or professional services environment, including contributing to technical proposals
CertificationsRequired: at least one active cybersecurity certification, such as CompTIA SecurityX (formerly CASP+), GIAC Security Essentials (GSEC), AWS Certified Security – Specialty, Microsoft Certified: Azure Security Engineer Associate, CCSP, or CISSP
Preferred:
IAPP Artificial Intelligence Governance Professional (AIGP), ISACA Advanced in AI Security Management (AAISM), or GIAC AI Platform Security (GAIPS)
Preferred:
CISSP or CCSP, if not held as the required certification
Clearance and SuitabilityMust be a U.S. citizen (client requirement).
Must be able to obtain and maintain a client suitability determination (Public Trust) and a client-issued Personal Identity Verification (PIV) credential, and complete required security and privacy training prior to access.
Responsibilities:
Lead development of the AI Use Case Inventory across all Zero Trust pillars and cross-cutting capabilities, deriving candidates from a matrix of pillars against AI functions (detection and classification, correlation and enrichment, decision support, workflow automation, and evidence generation)
Prioritize use cases by enterprise risk, feasibility, and mission impact, decomposing feasibility into data availability, integration complexity, and governance readiness so the inventory stays tied to what can actually be authorized
Author a data statement for every use case documenting what data the capability consumes, where it originates, how it is classified, whether it leaves its collection boundary, how long it is retained, and who is accountable for it
Lead the assessment of AI effectiveness against Zero Trust threats, including AI-driven detection of credential misuse, device risk classification, automated enforcement of micro-segmentation policies, and continuous monitoring and anomaly detection
Design evaluation approaches that do not assume a large labeled incident corpus, including shadow-mode operation against existing detections, synthetic injection of representative adversary behavior, purple-team scenarios for enforcement use cases, and drift monitoring with defined revalidation cadences
Conduct analyses of alternatives comparing classical ML, agentic AI, and conventional automation for each use case, recommending human-in-the-loop designs wherever an AI output drives an enforcement decision
Partner with the ML/Data Engineer on technical design artifacts, including data flow diagrams, model requirements, trust-scoring logic, and integration patterns, ensuring scoring is explainable to the person it affects, every enforcement decision has a defined appeal path, and decision logic is kept separate from policy-owned weightings and thresholds
Define Zero Trust controls for AI systems themselves, including identity, entitlements, network placement, and action logging for models, agents, and the tools they are permitted to invoke
Threat model AI-enabled Zero Trust controls using MITRE ATLAS and the OWASP Top 10 for LLM Applications, and document compensating controls for residual risk
Align designs with HHS and client AI policy and record the governing policy version in each design artifact, so policy changes become configuration changes rather than re-architecture
Coordinate with the Lead Zero Trust Architect so AI patterns integrate with the enterprise reference architectures, and with the RMF/A&A Specialist so AI-supported controls and their evidence are authorizable
Plan and facilitate use case discovery workshops and working sessions with client security, technology, and program stakeholders, including preparing agendas and materials and tracking decisions and action items
Present AI use case priorities, assessment results, and recommendations to client leadership and governance bodies
Contribute to the coordinated quarterly refresh cycle, ZTA knowledge base content, monthly institute office hours, and enterprise help desk inquiries on AI-related topics
Research emerging AI capabilities, attack techniques, and Federal AI policy through Triple Point's Talent and Innovation Hub, and convert findings into reusable patterns and client-ready guidance
Mentor junior engineers and interns on AI security and Zero Trust fundamentals
Support business development efforts including proposal contributions, technical solutioning, and client presentations
About Triple Point SecurityTriple Point Security is a technical cybersecurity and cloud security firm that provides highly specialized services to organizations with complex, hybrid IT environments. We have experienced tremendous growth through our Zero-Trust Architecture (ZTA), DevSecOps, and secure AI adoption services and are looking to continue this momentum with our cloud service provider, technology, and teaming partners.
Our professionals possess public sector experience in the Department of Health and Human Services (HHS), Department of Defense (DOD), and Department of Justice (DOJ). They also possess private sector experience in telecommunications, finance, managed service providers, and Internet infrastructure. We combine our technical knowledge with best practices from the public and private sectors and apply them to IT security solutions and services that support our clients in achieving their business and mission objectives.
Immediate vesting for 401(k) company matching contributions
100% of premium cost for basic employee coverage: Health, Dental, and Vision
100% of premium cost: Basic Life AD&D, Short Term Disability, and Long Term Disability
Flexible Spending Accounts: Health, Dependent Care, and Mass Transit & Parking
Tuition & Training Reimbursement
Performance and referral Bonus
Flexible work schedule (with client approval)
Employee Assistance Program
Call A Doctor Plus Telemedicine Service
MetLaw Group Legal Services
Technology resources (HW/SW), online training, and virtual labs
This job description is not designed to cover or contain a comprehensive listing of activities, duties or responsibilities that are required of the employee. Duties, responsibilities and activities may change, or new ones may be assigned at any time with or without notice.
Triple Point Security is an equal opportunity employer and does not discriminate on the basis of race, color, religion, sex, gender identity, sexual orientation, pregnancy, status as a parent, national origin, age, disability (physical or mental), family medical history or genetic information, political affiliation, and military service.
Also on the board Same function, level within a rung
Level
Lead
Salary
$140,000 per year
Location
Leesburg, VA
Occupation
Information Security Analysts
Industry
Computer Systems Design Services
Posted
yesterday