Competence :
1. GenAI / LLM architecture LLMs, embeddings, RAG, vector DBs, model serving, fine-tuning, inference, context windows, guardrails
2. Agentic AI security Agents, multi-agent orchestration, tool calling, delegated authority, agent identities, memory, human-in-the-loop
3. MCP security MCP clients/servers, tool discovery, authentication/authorization, tool permissions, poisoned MCP servers, data exfiltration, MCP gateway controls
4. AI threat modelling Prompt injection, indirect prompt injection, jailbreaks, model/data poisoning, insecure output handling, excessive agency, supply-chain/model risks
5. IAM amp; Zero Trust OAuth/OIDC, workload identity, RBAC/ABAC, secrets management, least privilege, service-to-service authorization
6. Platform security Kubernetes/OpenShift, containers, APIs, ingress, network policies, image scanning, runtime security, supply-chain security
7. MLSecOps / DevSecOps Secure CI/CD, model registry, artifact provenance, model scanning, dependency scanning, signing, vulnerability management
8. Data security PII/DLP, encryption, data classification, RAG permissions, vector-store isolation, tenant isolation
9. AI monitoring amp; response Security telemetry, anomalous agent actions, prompt/response logging, tool-call monitoring, attack detection, kill switches, incident response
10. AI governance frameworks OWASP GenAI/Agentic Top 10, MITRE ATLAS, NIST AI RMF, ISO 42001 and normal cyber standards.
Certifications that would be nice to have as evidence of depth:
1. GAIPS : GIAC AI Platform SecurityIt explicitly covers agentic systems, RAG, AI architecture, MLOps, deployment security, AI integrations and AI risk. The associated SANS SEC545 also includes hands-on work with Kubernetes and MCP.
2. CKS : Certified Kubernetes Security SpecialistVery valuable in our environment because the AI platform is containerized/OpenShift/Kubernetes based. CKS tests actual Kubernetes security skills across build, deployment and runtime rather than being purely theoretical.
3 . ISACA AAISM — Advanced in AI Security Management