AI and Cloud Security Analyst

AI and Cloud Security Analyst

Vollzeit 63000 - 77000 € / Jahr (geschätzt) Homeoffice (teilweise)
Embedded Shishya

Auf einen Blick

  • Aufgaben: Überwache und analysiere KI-Sicherheitsereignisse in einer dynamischen Umgebung.
  • Unternehmen: Weltweit führendes IT-Vertriebsunternehmen mit innovativer Kultur.
  • Vorteile: Flexible Arbeitszeiten, Karriereentwicklung und Gesundheitsprogramme.
  • Weitere Informationen: Vielfältige Teamkultur und Möglichkeiten zur persönlichen Weiterentwicklung.
  • Warum dieser Job: Gestalte die Zukunft der KI-Sicherheit und arbeite an spannenden Projekten.
  • Qualifikationen: Kenntnisse in Cybersecurity und Datenanalyse sind von Vorteil.

Das prognostizierte Gehalt liegt zwischen 63000 - 77000 € pro Jahr.

TD SYNNEX (NYSE: SNX) is the world's largest IT distributor, adopting AI at speed across Azure AI Foundry, AWS Bedrock, Copilot Studio, Databricks, and self-hosted agent environments.

Our security model is runtime-first: instead of blocking AI adoption with slow approvals, we intercept, analyze, and enforce at the moment of execution — which means high-quality monitoring, triage, analytics, and reporting are what keep the system honest.

As our AI and Cloud Security Analyst, you provide day-to-day L2 coverage of the AI security detection fabric — triaging and supporting investigation of AI-specific detections from runtime defense, behavioral/intent monitoring, model-security, and adversarial-testing platforms.

You turn that telemetry into insight through data analytics and produce the OCR (operational, compliance, and risk) reporting that gives leadership, control owners, and auditors a continuous picture of AI and cloud risk.

You also help monitor the security posture of our Azure, AWS, and GCP environments.

You **escalate** to a dedicated L3 engineer and work alongside two AI & Cloud Security Architects.

The analyst will report to AI & Cloud Security leadership and have strong working relationships with other Cybersecurity, IT and application development teams.

Responsibilities

  • L2 coverage of the AI Security toolset.

Monitor AI security detections across the detection fabric — runtime defense/AIDR events, intent and behavioral anomalies, model-level detections, and adversarial-testing signals.

Validate detections, classify severity and impact, propose and implement policy updates, and **escalate** complex cases to L3 with complete, reusable context.

  • Investigate AI-specific events across all five AI archetypes (embedded Saa S copilots, low-code/no-code agents, homegrown agentic pipelines, device-based coding agents, homegrown models): direct and indirect prompt injection, jailbreaks, sensitive-data leakage, RAG poisoning indicators, unauthorized MCP/tool activity, agent hijacking, and rogue or overprivileged agent behavior — using prompt/response logs, decision traces, identity context, and agent inventory data.
  • Support the AI asset-intelligence layer: help maintain agent inventory hygiene, ownership attribution, MCP registry accuracy, and risk-scoring context that feeds runtime enforcement decisions and fast-track approval workflows.
  • Data analytics.

Query and correlate AI and security telemetry (KQL), identify anomalies and attack patterns, and build/maintain dashboards tracking the program's key metrics — detection volumes, runtime containment rate, mean time to detect/contain/resolve, agent-visibility coverage, approval-SLA performance, and top policy-violation categories — feeding tuning recommendations back to the L3 engineer.

  • OCR reporting (operational, compliance, and risk).

Produce recurring dashboards and executive summaries communicating AI-security posture, KPIs, and trends to stakeholders and control owners; support automated NIST AI RMF compliance evidence generation and audit/regulatory reporting, including EU AI Act–related evidence for EU scope.

  • Maintain rigorous case documentation and shift/handover notes; contribute observed patterns to detection-rule tuning, runbook refinement, and the closed-loop improvement cycle (red-team findings → policy and detection updates → re-test validation).
  • Build working fluency in the OWASP Top 10 for LLM Applications 2025, the OWASP Top 10 for Agentic Applications, and MITRE ATLAS as the shared investigation taxonomy.
  • Monitor and triage cloud security alerts across Azure, AWS, and GCP from company CSPM platform — misconfigurations, security risks, exposed resources, excessive permissions, workload threats — and route, remediate, or escape per playbook.
  • Support cloud compliance monitoring and reporting against CIS Benchmarks and NIST 800-53 r5 / CSF 2.0 baselines, tracking remediation to closure and integrating cloud posture into the consolidated OCR reporting.

Support L3 engineer with policy updates.

  • Assist with cloud workload vulnerability triage (VMs, containers, images) and with Microsoft 365 / Google Workspace security-signal review.
  • Partner with the L3 engineer, SOC, cloud teams, and incident responders on investigations and enrichment spanning cloud, identity, endpoint, and AI telemetry.
  • Critical Skills
  • Solid security operations fundamentals: alert monitoring, triage, validation, incident classification, **escalate**, and case management against SLAs, working from runbooks in a follow-the-sun/handover model.
  • Strong data analytics and reporting: KQL (and/or SQL) for querying and correlation; dashboard and report development; the ability to turn telemetry into clear, decision-ready operational, compliance, and risk reporting.
  • Foundational AI/Gen AI security awareness: LLM risks (prompt injection, jailbreaks, data leakage), agentic AI and MCP concepts, AI guardrails, and familiarity with the OWASP LLM Top 10 and MITRE ATLAS.

Exposure to AI security platforms is a strong plus.

  • Working knowledge of cloud security in at least one of Azure/AWS/GCP (multi-cloud exposure preferred), including CSPM/CWPP concepts and cloud identity basics.
  • Scripting for automation and enrichment (Power Shell and/or Python).
  • Familiarity with CIS Benchmarks and NIST (800-53, CSF); awareness of NIST AI RMF and the EU AI Act is beneficial, particularly for EU-based candidates.
  • Analytical rigor, attention to detail, and clear English communication across a globally distributed team spanning multiple time zones.

Experience

  • SOC, security operations, cloud security, or security-analyst role with hands-on monitoring, triage, and investigation experience; exposure to AI/Gen AI security is an advantage.
  • Demonstrable experience producing analytics, dashboards, and reporting from security telemetry for technical and executive audiences.
  • Experience supporting compliance or audit evidence collection (NIST, CIS, ISO, or similar) is a plus.
  • Certifications are an advantage, not mandatory: Comp TIA Security+, Cy SA+, SC-200, SC-900, AZ-500, AWS or GCP security/foundational credentials; AI-security coursework or credentials are a plus.
  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or equivalent practical experience.
  • Working conditions
  • Willing to work nonstandard business hours for projects, business impact issues and incident response.
  • Some travel required.
  • Flexible remote work.

At Tech Data, a TD SYNNEX Company, our values guide everything we do: Together, We Own It, We Dare to Go, We Grow and Win, and above all, We Do the Right Thing.

These principles shape how we work with each other, our partners, and our communities as we drive innovation and create lasting impact.

What’s In It For You?

  • Elective Benefits: Our programs are tailored to your country to best accommodate your lifestyle.
  • Grow Your Career: Accelerate your path to success (and keep up with the future) with formal programs on leadership and professional development, and many more on-demand courses.
  • Elevate Your Personal Well-Being: Boost your financial, physical, and mental well-being through seminars, events, and our global Life Empowerment Assistance Program.
  • Diversity, Equity & Inclusion: It’s not just a phrase to us; valuing every voice is how we succeed.

Join us in celebrating our global diversity through inclusive education, meaningful peer-to-peer conversations, and equitable growth and development opportunities.

  • Make the Most of our Global Organization: Network with other new co-workers within your first 30 days through our onboarding program.
  • Connect with
  • Your

Community: Participate in internal, peer-led inclusive communities and activities, including business resource groups, local volunteering events, and more environmental and social initiatives.

We are an equal opportunity employer and committed to building a diverse team that represents and empowers a variety of backgrounds, perspectives, and skills.

All qualified applicants will receive consideration for employment based on merit, without regard to race, colour, religion, national origin, gender, gender identity or expression, sexual orientation, protected veteran status, disability, genetics, age, or any other characteristic protected by law.

To support our diversity and inclusion efforts, we may ask for voluntary gender disclosure information.

This data will be used solely to improve our hiring practices and ensure fair treatment for all candidates.

#J-18808-Ljbffr

AI and Cloud Security Analyst Arbeitgeber: Embedded Shishya

Jitterbit ist ein hervorragender Arbeitgeber, der Ihnen die Möglichkeit bietet, in einem dynamischen und wachsenden Umfeld zu arbeiten, das sich auf die Integration von Plattformen als Dienstleistung (iPaaS) spezialisiert hat. Mit einem flexiblen, remote-freundlichen Arbeitsmodell und einer Unternehmenskultur, die auf Zusammenarbeit und persönlichem Wachstum basiert, fördern wir Ihre Karriere durch Mentorship und kontinuierliche Entwicklung. Hier haben Sie die Chance, bedeutende Partnerschaften zu entwickeln und die Zukunft der API-Nutzung in geschäftskritischen Prozessen mitzugestalten.

Embedded Shishya

Kontaktdaten:

Embedded Shishya Recruiting-Team

StudySmarter Expertenrat🤫

Wir sind der Meinung, dass du so AI and Cloud Security Analyst erhalten könntest

Werde sichtbar in der IT-Sicherheits-Community

In der IT-Sicherheit gibt’s eine Menge Fachkreise und Konferenzen, die super für Networking sind. Schau dir Events wie die "IT-Security Convention" oder regionale Meetups an, um Gleichgesinnte und potenzielle Arbeitgeber wie Embedded Shishya kennenzulernen!

Kollaboriere an Open-Source-Projekten

Zeig dein Können und engagiere dich in Open-Source-Projekten, die auf IT-Sicherheit abzielen. Das ist nicht nur eine tolle Möglichkeit, praktische Erfahrungen zu sammeln, sondern auch, um dein Portfolio zu erweitern und Sichtbarkeit in der Branche zu gewinnen.

Nutze spezielle Jobportale für IT-Sicherheit

Schau auf spezialisierten Jobportalen wie "heise jobs" oder "StepStone" nach offenen Stellen in der IT-Sicherheit. Hier findest du viele Angebote, die nicht immer auf den großen Plattformen gelistet sind. Vergiss nicht, dich direkt auf der Website von Embedded Shishya zu bewerben!

Halte deine Skills up-to-date

In der IT-Sicherheit bleibt nichts stehen, also bleib am Ball! Investiere Zeit in Weiterbildung und besuche Online-Kurse oder Webinare zu aktuellen Sicherheitsthemen. Das zeigt nicht nur dein Engagement, sondern stärkt auch dein Profil bei Embedded Shishya.

Wir glauben, dass du diese Fähigkeiten brauchst, um AI and Cloud Security Analyst mit Bravour zu bestehen

AI-Sicherheitsbewusstsein
Cloud-Sicherheit (Azure, AWS, GCP)
Datenanalyse (KQL, SQL)
Überwachung und Triage von Sicherheitswarnungen
Erstellung von Dashboards und Berichten
Incident-Management
Scripting für Automatisierung (PowerShell, Python)

Einige Tipps für deine Bewerbung 🫡

Zeig deine technischen Skills!:Im Bereich IT-Sicherheit ist es wichtig, dass du deine technischen Fähigkeiten klar kommunizierst. Stelle sicher, dass dein Lebenslauf relevante Zertifikate (wie CEH oder CISSP) sowie praktische Erfahrungen bei Sicherheitsprojekten oder Penetrationstests zeigt. Dies wird uns helfen, einen besseren Eindruck von deinem Fachwissen zu bekommen.

Präsentiere dein Wissen über aktuelle Trends:Wir möchten sehen, dass du über die neuesten Entwicklungen im Bereich IT-Sicherheit informiert bist. In deinem Anschreiben kannst du beispielsweise auf ein aktuelles Sicherheitsproblem oder einen neuen Standard eingehen, den du für relevant hältst. Dadurch zeigst du uns, dass du dich aktiv mit dem Thema auseinandersetzt und für die Position brennst.

Mach deine Leidenschaft deutlich:Da es sich um eine Vollzeitposition handelt, ist es wichtig, dass du uns in deinem Anschreiben zeigst, warum du in der IT-Sicherheit arbeiten möchtest. Erzähl uns von deinen Erfahrungen, wie du zur Cyber-Security gekommen bist und was dich motiviert, in dieser Branche zu arbeiten. Deine Motivation spielt eine große Rolle bei der Auswahl!

Referenzen oder Projekte anfügen:Wenn du bereits an interessanten Projekten gearbeitet hast oder relevante Referenzen hast, die deine Fähigkeiten unterstreichen, füge diese in deine Bewerbung hinzu. Das gibt uns einen Einblick in deine praktische Erfahrung und zeigt, was du wirklich drauf hast. Ein Link zu einem GitHub-Profil oder Sicherheitsanalysen, die du durchgeführt hast, wäre hier super hilfreich!

Wie man sich auf ein Vorstellungsgespräch bei Embedded Shishya vorbereitet

Sicherheitsprotokolle dominiert!

Mach dich mit den neuesten Sicherheitsprotokollen und -standards vertraut. Bei Embedded Shishya könnte es sein, dass du in technisch anspruchsvollen Fragen zu Netzwerksicherheit und Schwachstellenmanagement gefordert wirst – zeig, dass du die Grundlagen und die aktuellen Trends im Bereich IT-Sicherheit beherrschst!

Praktische Erfahrung zählt!

Bereite dich darauf vor, über frühere Projekte oder Erfahrungen im Bereich IT-Sicherheit zu sprechen. Es ist wichtig, Beispiele zu haben, wie du Sicherheitslücken identifiziert und behoben hast oder welche Tools du verwendet hast, um Systeme abzusichern. Embedded Shishya sucht nach jemandem, der die Theorie auch anwenden kann!

Teamarbeit nicht vergessen!

IT-Sicherheit ist oft Teamarbeit. Sei bereit, Fragen zu beantworten, wie du in einem Team umgehst, um Sicherheitsprobleme zu lösen. Denk auch an Beispiel-Situationen, in denen du optimal mit anderen zusammengearbeitet hast – das könnte einen großen Unterschied machen!

Motivation und Lernbereitschaft zeigen!

Da es sich um eine Vollzeitstelle handelt, wird Embedded Shishya auch wissen wollen, wie motiviert du bist und welche Schritte du unternimmst, um dein Wissen in der sich ständig weiterentwickelnden Welt der IT-Sicherheit auf dem neuesten Stand zu halten. Das könnte in einem Gespräch über deine Weiterbildung oder zertifikatsbezogenen Pläne relevant sein!