AI Security
The newest branch on this list, and it's genuinely still forming: job titles, career ladders, and even the certifications are only a couple of years old. What's covered below are the roles with real job postings today, but expect this branch to keep reshaping itself fast as the underlying technology and the attacks against it both keep evolving.
Responsible AI / Trust & Safety EngineerAdversarial ML ResearcherAI Supply Chain / MLBOM SecurityTraining Data Security & Poisoning Defense
AI/ML Security Engineer
Builds and hardens the security controls protecting machine-learning pipelines, models, and the infrastructure they run on.
What it's about & how to get in
This is one of the more established of the emerging AI-security titles, but it's still coalescing — postings appear interchangeably as 'AI Security Engineer,' 'ML Security Engineer,' and 'Security Engineer, AI/ML.' The role blends traditional application/cloud security with ML-specific threats such as data poisoning, model theft, and adversarial inputs, using frameworks like MITRE ATLAS and the NIST AI Risk Management Framework as shared reference points.
Most people arrive from application security or cloud security backgrounds and add ML fundamentals (Python, familiarity with training pipelines like SageMaker, Vertex AI, or Azure ML), or come from an ML engineering background and move into security. Strong cloud security skills (AWS/GCP/Azure) are common since most production ML runs there.
Where you can work
- Cloud hyperscaler AI security teams (AWS, Google Cloud, Microsoft)
- AI-native product companies securing training/inference infrastructure
- Enterprise security teams standing up MLSecOps practices for internal ML platforms
- Security vendors building AI/ML security products (model scanning, LLM firewalls)
- Regulated industries (finance, healthcare) deploying production ML models
- Security consultancies performing AI/ML security assessments
What it pays
Certifications that open doors
Where you can actually learn it
GenAI/LLM Security Engineer
Defends generative-AI and LLM-powered applications against prompt injection, data leakage, and other emerging attack patterns.
What it's about & how to get in
The newest of these five specialties, built directly around the risks catalogued in the OWASP Top 10 for LLM Applications. A dedicated 'LLM Security Engineer' job title is still rare in postings — most hiring happens under 'AI Security Engineer' or 'Application Security Engineer (GenAI),' with LLM-specific duties called out in the description rather than the title.
Typical backgrounds are application-security engineers who pick up prompt-injection and RAG-pipeline threat modeling, or LLMOps/ML engineers who pick up security. Hands-on experience with LLM APIs, guardrail/filtering tools, and red-teaming frameworks (e.g., Microsoft PyRIT) is common.
Where you can work
- AI product companies building consumer/enterprise GenAI features
- Frontier AI labs and Big Tech GenAI platform teams
- Enterprise AppSec teams securing internal chatbots, copilots, and RAG systems
- Security startups building LLM firewalls / guardrail products
- Consulting firms offering LLM security assessments
What it pays
Certifications that open doors
AI Red Team Specialist
Attacks AI systems on purpose — prompt injection, jailbreaks, model extraction — to find weaknesses before real adversaries do.
What it's about & how to get in
Grew directly out of traditional penetration testing/red teaming as GenAI adoption accelerated. MITRE ATLAS catalogs the adversary tactics this role tests against, and titles vary widely ('AI Red Teamer,' 'AI Security Researcher,' 'Adversarial ML Engineer') since the discipline is barely a few years old.
Most practitioners come from an offensive-security background (pentesting/red teaming) and add ML fundamentals, or come from ML/adversarial-robustness research and add offensive tradecraft. Comfort with Python, jailbreak/prompt-injection techniques, and tooling such as Microsoft PyRIT is standard.
Where you can work
- Frontier AI labs' pre-release safety/red-team teams
- Big Tech AI security research teams
- Specialized AI red-teaming startups and consultancies
- Government/national-security AI evaluation programs
- Enterprise security teams red-teaming internally deployed GenAI apps
What it pays
Certifications that open doors
Where you can actually learn it
AI Governance & Compliance Analyst
Turns AI regulations and frameworks like the NIST AI RMF into policies, controls, and audits organizations can actually follow.
What it's about & how to get in
The fastest-growing of these five specialties as regulation catches up with AI deployment, but it still overlaps heavily with existing privacy/compliance/GRC roles — 'AI Governance' is often a specialization layered onto a broader compliance or privacy-analyst title rather than a fully standalone job yet.
Typical backgrounds are privacy, compliance, or GRC analysts who add AI-specific frameworks, or legal/policy professionals with enough technical fluency to work with engineering teams. Familiarity with the NIST AI RMF and sector AI regulation is core to the role.
Where you can work
- Enterprise legal/compliance/privacy departments standing up AI governance programs
- Consulting and advisory practices with dedicated AI risk & governance teams
- Regulated industries: financial services, healthcare, insurance
- Tech companies' responsible-AI / trust & safety teams
- Government agencies and regulators building AI oversight capacity
What it pays
Certifications that open doors
Where you can actually learn it
AI Risk Analyst
Assesses and quantifies the risks AI systems introduce to the business, from model failure to regulatory exposure.
What it's about & how to get in
Closely related to — and often indistinguishable from — traditional technology/operational risk analyst roles, now scoped to AI/ML systems specifically. Genuinely dedicated 'AI Risk Analyst' postings and salary data remain thin, so this role is best benchmarked off the broader 'Information/Technology Risk Analyst' family plus AI-specific frameworks and certifications layered on top.
Typical backgrounds are risk management, internal audit, or IT risk professionals (often CRISC-certified) who add AI-model-risk frameworks like the NIST AI RMF and use MITRE ATLAS for threat context. Some come from data science and move into risk/governance.
Where you can work
- Enterprise/model-risk-management teams, especially in banking and insurance
- Internal audit functions auditing AI system controls
- Consulting firms' AI risk advisory practices
- Tech companies' responsible-AI / risk teams
- Government and regulatory bodies assessing AI risk