AI and Cloud Security Analyst
name
पदको बारेमा
TD SYNNEX (NYSE: SNX) is the world's largest IT distributor, adopting AI at speed across Azure AI Foundry, AWS Bedrock, Copilot Studio, Databricks, and self-hosted agent environments. Our security model is runtime-first: instead of blocking AI adoption with slow approvals, we intercept, analyze, and enforce at the moment of execution — which means high-quality monitoring, triage, analytics, and reporting are what keep the system honest. As our AI and Cloud Security Analyst, you provide day-to-day L2 coverage of the AI security detection fabric — triaging and supporting investigation of AI-specific detections from runtime defense, behavioral/intent monitoring, model-security, and adversarial-testing platforms.
You turn that telemetry into insight through data analytics and produce the OCR (operational, compliance, and risk) reporting that gives leadership, control owners, and auditors a continuous picture of AI and cloud risk. You also help monitor the security posture of our Azure, AWS, and GCP environments. You escalate to a dedicated L3 engineer and work alongside two AI & Cloud Security Architects.
The analyst will report to AI & Cloud Security leadership and have strong working relationships with other Cybersecurity, IT and application development teams.
Responsibilities
L2 coverage of the AI Security toolset . Monitor AI security detections across the detection fabric — runtime defense/AIDR events, intent and behavioral anomalies, model-level detections, and adversarial-testing signals. Validate detections, classify severity and impact, propose and implement policy updates, and escalate complex cases to L3 with complete, reusable context.
Investigate AI-specific events across all five AI archetypes (embedded SaaS copilots, low-code/no-code agents, homegrown agentic pipelines, device-based coding agents, homegrown models): direct and indirect prompt injection, jailbreaks, sensitive-data leakage, RAG poisoning indicators, unauthorized MCP/tool activity, agent hijacking, and rogue or overprivileged agent behavior — using prompt/response logs, decision traces, identity context, and agent inventory data. Support the AI asset-intelligence layer : help maintain agent inventory hygiene, ownership attribution, MCP registry accuracy, and risk-scoring context that feeds runtime enforcement decisions and fast-track approval workflows. Data analytics .
Query and correlate AI and security telemetry (KQL), identify anomalies and attack patterns, and build/maintain dashboards tracking the program's key metrics — detection volumes, runtime containment rate, mean time to detect/contain/resolve, agent-visibility coverage, approval-SLA performance, and top policy-violation categories — feeding tuning recommendations back to the L3 engineer. OCR reporting (operational, compliance, and risk) . Produce recurring dashboards and executive summaries communicating AI-security posture, KPIs, and trends to stakeholders and control owners; support automated NIST AI RMF compliance evidence generation and audit/regulatory reporting, including EU AI Act–related evidence for EU scope.
Maintain rigorous case documentation and shift/handover notes; contribute observed patterns to detection-rule tuning, runbook refinement, and the closed-loop improvement cycle (red-team findings → policy and detection updates → re-test validation). Build working fluency in the OWASP Top 10 for LLM Applications 2025, the OWASP Top 10 for Agentic Applications, and MITRE ATLAS as the shared investigation taxonomy. Monitor and triage cloud security alerts across Azure, AWS, and GCP from company CSPM platform — misconfigurations, security risks, exposed resources, excessive permissions, workload threats — and route, remediate, or escalate per playbook.
Support cloud compliance monitoring and reporting against CIS Benchmarks and NIST 800-53 r5 / CSF 2.0 baselines, tracking remediation to closure and integrating cloud posture into the consolidated OCR reporting. Support L3 engineer with policy updates. Assist with cloud workload vulnerability triage (VMs, containers, images) and with Microsoft 365 / Google Workspace security-signal review.
Partner with the L3 engineer, SOC, cloud teams, and incident responders on investigations and enrichment spanning cloud, identity, endpoint, and AI telemetry. Critical Skills Solid security operations fundamentals : alert monitoring, triage, validation, incident classification, escalation, and case management against SLAs, working from runbooks in a follow-the-sun/handover model. Strong data analytics and reporting : KQL (and/or SQL) for querying and correlation; dashboard and report development; the ability to turn telemetry into clear, decision-ready operational, compliance, and risk reporting.
Foundational AI/GenAI security awareness : LLM risks (prompt injection, jailbreaks, data leakage), agentic AI and MCP concepts, AI guardrails, and familiarity with the OWASP LLM Top 10 and MITRE ATLAS. Exposure to AI security platforms is a strong plus. Working knowledge of cloud security in at least one of Azure/AWS/GCP (multi-cloud exposure preferred), including CSPM/CWPP concepts and cloud identity basics.
Scripting for automation and enrichment (PowerShell and/or Python). Familiarity with CIS Benchmarks and NIST (800-53, CSF); awareness of NIST AI RMF and the EU AI Act is beneficial, particularly for EU-based candidates. Analytical rigor, attention to detail, and clear English communication across a globally distributed team spanning multiple time zones.
Experience SOC, security operations, cloud security, or security-analyst role with hands-on monitoring, triage, and investigation experience; exposure to AI/GenAI security is an advantage. Demonstrable experience producing analytics, dashboards, and reporting from security telemetry for technical and executive audiences. Experience supporting compliance or audit evidence collection (NIST, CIS, ISO, or similar) is a plus.
Certifications are an advantage, not man