Summary
Position Summary
Cyber
Deloitte Cyber understands the unique challenges and opportunities businesses face in cybersecurity. Join our team to deliver powerful insights to help our clients navigate the ever-changing threat design, and technology as we partner with clients to transform finance.
Job Title: Manager - Cloud AI Security
Are you interested in working in a dynamic environment that offers opportunities for professional growth and new responsibilities? If so, Deloitte could be the place for you. Traditional security programs have often been unsuccessful in unifying the need to both secure and support technology innovation required by the business. Join Deloitte's Cyber Cloud AI Security team and become a member of the largest group of cybersecurity professionals worldwide.
Work you’ll do
As a Cloud AI Security Manager, you will lead client engagements focused on securing AI, generative AI, and ML workloads across cloud platforms. You will help clients define and implement secure AI strategies, architectures, governance models, and control frameworks across the AI lifecycle, including data ingestion, model development, validation, deployment, runtime monitoring, and retraining. You will be expected to lead engagement delivery, manage senior client stakeholders, guide cross-functional teams, mentor junior practitioners, and drive high-quality outcomes across AI security, cloud security, governance, compliance, and risk management.
Responsibilities as a Cloud AI Security Senior Consultant will include:
- Lead client engagements focused on AI, GenAI, and ML security across AWS, Microsoft Azure, and Google Cloud environments.
- Lead the design and implementation of AI security solutions aligned to client business objectives, enterprise architecture, regulatory expectations, and security requirements.
- Oversee AI security assessments for cloud-hosted AI/ML and GenAI workloads, evaluating controls against frameworks and standards such as NIST CSF, CSA CCM, ISO 27001, NIST AI RMF, and ISO 42001.
- Lead threat modeling, architecture reviews, and control design for AI and GenAI solutions, including risks related to prompt injection, jailbreaks, insecure output handling, excessive agent permissions, sensitive data exposure, model misuse, and insecure tool or connector use.
- Define secure AI reference architectures spanning model endpoints, APIs, retrieval pipelines, vector stores, plugins, agent frameworks, orchestration layers, and external integrations.
- Guide secure deployment and configuration of cloud-native AI services including Amazon Bedrock, Amazon SageMaker, Azure AI Foundry, Azure OpenAI, Azure Machine Learning, and Google Vertex AI.
- Oversee implementation of platform-specific controls such as private connectivity, encryption, key management, secrets management, access restrictions, tenant isolation, content safety controls, and service-native logging and monitoring.
- Lead DevSecOps, MLOps, and MLSecOps integration by embedding security checks, policy validation, secrets handling, model governance, and compliance controls into CI/CD and ML pipelines.
- Establish secure AI lifecycle controls across data ingestion, training, validation, deployment, runtime monitoring, incident response, drift review, and retraining.
- Lead AI governance and compliance activities including model inventory, risk classification, approval workflows, traceability, control mapping, audit readiness, and policy alignment.
- Drive AI security posture management using cloud-native tooling, CNAPP, CSPM, CWPP, DSPM, SIEM, and related capabilities to identify misconfiguration, data exposure, anomalous activity, and policy violations.
- Oversee AI-specific monitoring and incident response capabilities for suspicious prompt behavior, agent misuse, unauthorized model access, data leakage, and control failures.
- Lead or coordinate AI security testing activities including misuse-case testing, prompt attack validation, model guardrail reviews, red-team support, and remediation planning.
- Manage client stakeholders across security, cloud engineering, DevOps, architecture, data, ML engineering, privacy, legal, and risk teams.
- Lead teams of analysts, consultants, and senior consultants by assigning work, reviewing outputs, coaching team members, and ensuring quality of delivery.
- Contribute to business development, proposals, solutioning, thought leadership, reusable assets, and practice development initiatives related to cloud AI security.
The team
Deloitte Cyber team helps complex organizations more confidently pursue their growth, innovation and performance agendas through proactive management of the associated cyber risks. Our professionals provide advisory and implementation services that integrate risk, regulatory, and technology skills to help clients transform their legacy programs into proactive cyber risk programs. Join the team developing the future state of cyber risk solutions. Learn more about Deloitte Advisory’s Cyber Risk Services practice.
Required:
- 9+ years of experience in cloud security, cybersecurity consulting, cloud engineering, DevSecOps, AI security, or related disciplines.
- Demonstrated experience leading client-facing engagements or major workstreams in security, cloud, or AI-related programs.
- Experience designing, assessing, or implementing security controls for cloud-hosted applications, platforms, and AI/ML environments.
- Strong experience with one or more major cloud platforms, with working knowledge across AWS, Microsoft Azure, and Google Cloud.
- Strong understanding of AI/ML and GenAI security concepts, including prompt injection, model misuse, data leakage, secure model access, agent security, model governance, and responsible AI controls.
- Experience implementing cloud security controls across IAM, network security, encryption, key management, secrets management, logging, monitoring, and policy enforcement.
- Experience with Infrastructure as Code and automation using tools such as Terraform, CloudFormation, Ansible, Bash, and PowerShell.
- Experience with DevSecOps, CI/CD, and secure engineering practices, including policy validation, secrets handling, and continuous compliance.
- Familiarity with cloud AI services such as Amazon Bedrock, Amazon SageMaker, Azure AI Foundry, Azure Machine Learning, Azure OpenAI, Mythos, Anthropic, and Vertex AI.
- Familiarity with governance and security frameworks such as NIST CSF, ISO 27001, NIST AI RMF, ISO 42001, and related control frameworks.
- Strong written and verbal communication skills, including experience communicating technical and risk matters to executive and non-technical stakeholders.
- Experience leading teams, mentoring junior practitioners, and managing quality across client deliverables.
Preferred:
- Experience leading AI security assessments, architecture reviews, control design, remediation programs, or transformation initiatives across one or more major cloud platforms.
- Deep hands-on experience with identity and access management, including AWS IAM, Microsoft Entra ID, Azure RBAC, and Google Cloud IAM.
- Experience designing governance and guardrails for cloud AI environments using services such as AWS Organizations, AWS Control Tower, Azure Policy, Security Command Center, and equivalent policy enforcement capabilities.
- Experience with cloud-native monitoring and security tooling such as AWS Security Hub, CloudTrail, AWS Config, Microsoft Defender for Cloud, Azure Policy, and Google Security Command Center.
- Experience with CNAPP, CSPM, CWPP, DSPM, SIEM, vulnerability management, container security, and posture management tools supporting AI workloads.
- Experience with prompt security, content safety, model guardrails, AI runtime monitoring, and agent security for generative AI applications.
- Exposure to AI red teaming, misuse-case testing, prompt attack validation, or adversarial testing of LLM-enabled applications.
- Experience securing containerized, API-driven, and agent-based AI applications.
- Knowledge of privacy, legal, and data governance considerations relevant to AI workloads, including data residency, retention, sensitive data handling, and auditability.
- Experience establishing AI governance processes such as AI inventory, model classification, approval gates, traceability, documentation standards, and audit support.
- Experience contributing to proposals, solution development, go-to-market offerings, and practice-building activities.
- Relevant certifications such as CISSP, CCSP, AWS Certified Security – Specialty, Google Professional Cloud Security Engineer, Microsoft Azure security certifications, or comparable senior-level cloud and security credentials.
How You’ll Grow
At Deloitte, our professional development plan focuses on helping people at every level of their career to identify and use their strengths to do their best work every day. From entry-level employees to senior leaders, we believe there’s always room to learn. We offer opportunities to help sharpen skills in addition to hands-on experience in the global, fast-changing business world. From on-the-job learning experiences to formal development programs at Deloitte University, our professionals have a variety of opportunities to continue to grow throughout their career. Explore Deloitte University, The Leadership Center.
Benefits
At Deloitte, we know that great people make a great organization. We value our people and offer employees a broad range of benefits. Learn more about what working at Deloitte can mean for you.
Deloitte’s culture
Our positive and supportive culture encourages our people to do their best work every day. We celebrate individuals by recognizing their uniqueness and offering them the flexibility to make daily choices that can help them to be healthy, centered, confident, and aware. We offer well-being programs and are continuously looking for new ways to maintain a culture where our people excel and lead healthy, happy lives. Learn more about Life at Deloitte.
Corporate citizenship
Deloitte is led by a purpose: to make an impact that matters. This purpose defines who we are and extends to relationships with our clients, our people and our communities. We believe that business has the power to inspire and transform. We focus on education, giving, skill-based volunteerism, and leadership to help drive positive social impact in our communities. Learn more about Deloitte’s impact on the world.
Recruiter tips
We want job seekers exploring opportunities at Deloitte to feel prepared and confident. To help you with your interview, we suggest that you do your research: know some background about the organization and the business area you’re applying to. Check out recruiting tips from Deloitte professionals.
Our purpose
Deloitte’s purpose is to make an impact that matters for our people, clients, and communities. At Deloitte, purpose is synonymous with how we work every day. It defines who we are. Our purpose comes through in our work with clients that enables impact and value in their organizations, as well as through our own investments, commitments, and actions across areas that help drive positive outcomes for our communities.
Our people and culture
Our inclusive culture empowers our people to be who they are, contribute their unique perspectives, and make a difference individually and collectively. It enables us to leverage different ways of thinking, ideas and perspectives, and bring more creativity and innovation to help solve our clients’ most complex challenges. This makes Deloitte one of the most rewarding places to work.
Professional development
At Deloitte, professionals have the opportunity to work with some of the best and discover what works best for them. Here, we prioritize professional growth, offering diverse learning and networking opportunities to help accelerate careers and enhance leadership skills. Our state-of-the-art DU: The Leadership Center in India, located in Hyderabad, represents a tangible symbol of our commitment to the holistic growth and development of our people. Explore DU: The Leadership Center in India .
Benefits To Help You Thrive
At Deloitte, we know that great people make a great organization. Our comprehensive rewards program helps us deliver a distinctly Deloitte experience that helps that empowers our professionals to thrive mentally, physically, and financially—and live their purpose. To support our professionals and their loved ones, we offer a broad range of benefits. Eligibility requirements may be based on role, tenure, type of employment and/ or other criteria. Learn more about what working at Deloitte can mean for you.
Recruiting tips
From developing a stand out resume to putting your best foot forward in the interview, we want you to feel prepared and confident as you explore opportunities at Deloitte. Check out recruiting tips from Deloitte recruiters.
Requisition code: 352606