{"id":1899671,"url":"https://alion.io/job/pa-consulting-ai-security-engineer","title":"AI Security Engineer","company":{"id":6225,"name":"PA Consulting","domain":"paconsulting.com","url":"https://alion.io/company/pa-consulting","size_band":"501-1000","is_staffing_agency":false,"employer_type":"services","is_intermediary":false,"listed_via":null,"ats_vendor":"SmartRecruiters","truth_index":{"grade":"B","score":84,"open_postings":44,"ghost_share":0,"stale_share":0.659,"repost_share":0,"time_to_fill_p50_days":36,"computed_at":"2026-10-10T05:45:15Z"}},"role":"AI/ML","role_family":"AI/ML","seniority":"senior","employment_type":"full_time","work_mode":"hybrid","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Melbourn, United Kingdom"],"countries":["GB"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":115000,"max_usd":211000,"period":"year","method":"role_seniority_country_remote_cell","sample_n":35},"experience_years_min":5,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"AI Agents","optional":false},{"name":"Anomaly Detection","optional":false},{"name":"EU AI Act","optional":false},{"name":"Human-in-the-Loop","optional":false},{"name":"LLM","optional":false},{"name":"LLM Guardrails","optional":false},{"name":"NIST AI RMF","optional":false},{"name":"OWASP Top 10","optional":false},{"name":"Python","optional":false},{"name":"RAG","optional":false},{"name":"Red Teaming","optional":false},{"name":"SIEM","optional":false}],"status":"live","first_seen_at":"2026-10-05T08:33:31Z","employer_posted_date":"2026-10-05","last_verified_at":"2026-10-11T18:52:56Z","board_verified":true,"closed_at":null,"days_open":6,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":6},"description":"We believe in the power of ingenuity to build a positive human future.\nAs strategies, technologies, and innovation collide, we create opportunity from complexity.\nOur teams of interdisciplinary experts combine innovative thinking and breakthrough technologies to progress further, faster. Our clients adapt and transform, and together we achieve enduring results.\nWe are over 4,000 strategists, innovators, designers, consultants, digital experts, scientists, engineers, and technologists. And we have deep expertise in consumer and manufacturing, defence and security, energy and utilities, financial services, government and public services, health and life sciences, and transport.\nOur teams operate globally from offices across the UK, Ireland, US, Nordics, and Netherlands.\nPA. Bringing Ingenuity to Life.\n Hybrid working - our approach is to be in the office a minimum of 2 days per week.\nPA’s IT team, internally known as Group Systems, is comprised of a variety of areas that support the wider firm, consisting of four key pillars: Strategy, Architecture and Infrastructure Services; Enterprise Solutions; Technology and Operations; and Cyber Security and Compliance.\nThe successful candidate will be covered two primary areas: the security of AI (protecting the organisation's own AI systems and use of AI) and AI for security (using AI to strengthen protection, detection and response). This role will sit within Cyber Security and Compliance.\nTechnical ownership of AI security tool selection and deployment\nDefine requirements, run structured evaluations and proofs of concept, and judge vendor claims on evidence rather than marketing.\nThat means measuring detection efficacy, false positive rates, latency and operational overhead. The tool categories to cover include AI security posture management, LLM guardrails and firewalls, model and supply-chain scanning, GenAI data loss prevention, and AI-enabled SOC tooling.\nThey should also own the deployment itself: integration with existing SIEM, SOAR, EDR and identity tooling, architecture decisions, and making sure the tools are tuned and producing value after go-live rather than becoming shelfware.\nInput to vendor risk assessments fits here too, particularly on how vendors handle your data in their own models.\nUnderstanding the AI threat landscape\nThey need a working knowledge of AI-specific attack techniques and should be fluent in the reference frameworks, mainly the OWASP Top 10 for LLM Applications and MITRE ATLAS. Key threats include:\nDirect and indirect prompt injection\nData and model poisoning\nSensitive data leakage through prompts and outputs\nModel theft and extraction\nMalicious model files in the supply chain\nThe growing set of risks from agentic AI, such as excessive permissions and tool misuse\nThey also need to understand how attackers use AI against the organisation (more convincing phishing, deepfake-enabled fraud, faster reconnaissance and exploit development) and how that changes your threat model. Shadow AI, meaning unsanctioned use of AI tools by staff, is a practical, near-term issue they should be able to discover and manage.\nDemonstrating AI in protection, detection and response\nThis is where the role earns its keep with stakeholders. In protection, that might mean AI-assisted vulnerability prioritisation, secure code review, or posture analysis. In detection, it covers behavioural anomaly detection, alert triage and enrichment, and LLM-assisted threat hunting. In response, it includes AI copilots for investigation and incident summarisation, automated playbooks, and agentic response actions.\nA good candidate will be clear-eyed about limits: where human-in-the-loop controls are needed, how to validate AI outputs, and how to avoid automating mistakes at speed. The ability to build or run demonstrators that show value concretely is a strong differentiator.\nAssurance and testing\nThe role should include adversarial testing and red teaming of the organisation's AI systems, whether done directly or by scoping and overseeing third parties. Examples are testing RAG applications for injection and data exposure, or checking that an agent can't be manipulated into acting outside its intended permissions.\nAlignment with governance and standards\nThis isn't primarily a governance role, but the engineer should translate frameworks into technical controls and evidence. The relevant reference points are:\nNCSC's Guidelines for Secure AI System Development\nThe UK government's AI Cyber Security Code of Practice\nNIST AI RMF\nISO/IEC 42001\nThe EU AI Act, where relevant to clients or operations\n Skills and background\nThe ideal profile is a security engineer (typically from cloud security, security architecture, or SOC engineering) who has built genuine ML and LLM literacy. That means understanding how models, RAG pipelines and agents work, reasonable Python or scripting ability, and cloud platform experience. Communication matters more than usual: this person will regularly need to explain AI risk and capability to non-specialist decision-makers without overselling or scaremongering.\nMeasures of success\nUseful indicators:\nTools selected and deployed against defined requirements, with measurable outcomes (reduced triage time, improved detection coverage)\nAn AI asset inventory and threat model in place\nAI systems tested before deployment\nDemonstrators that have influenced investment or adoption decisions\nWe know the skill-gap and ‘somewhat need to tick every box’ can get in the way of meeting brilliant candidates, so please don’t hesitate to apply - we’d love to hear from you.\nApply today by completing our online application\nPlease be aware that some of our UK roles at PA Consulting require a UK security clearance.\nAll PA people are required to undergo background checks and to achieve the Baseline Personnel Security Standard however, some UK roles also require higher levels of National Security Vetting, where applicants must have at least 5 years of continuous residency in the UK.\nWe therefore ask that you only apply if you meet the residency requirements (i.e. you are a British citizen or have been resident in the UK for the past 5 years), as this is the prerequisite for a security clearance. If you're unsure about your eligibility, we encourage you to review the UK Government’s guidance on security vetting before applying.\n Life At PA encompasses our peoples' experience at PA. It's about how we enrich peoples’ working lives by giving them access to unique people and growth opportunities and purpose led meaningful work.\nWe believe diversity fuels ingenuity. Diversity of thought brings exciting perspectives; diversity of experience brings a wealth of knowledge, and diversity of skills brings the tools we need. When we bring people together with diverse backgrounds, identities, and minds, embracing that difference through an inclusive culture where our people thrive; we unleash the power of diversity - bringing ingenuity to life.\nFind out more about Life at PA here.\nWe are dedicated to supporting the physical, emotional, social and financial well-being of our people. Check out some of our extensive benefits:\nHealth and lifestyle perks accompanying private healthcare for you and your family\n25 days annual leave (plus a bonus half day on Christmas Eve) with the opportunity to buy 5 additional days\nGenerous company pension scheme\nOpportunity to get involved with community and charity-based initiatives\nAnnual performance-based bonus\nPA share ownership\nTax efficient benefits (cycle to work, give as you earn)\nWe recruit, retain, reward and develop our people based solely on their abilities and contributions and without reference to their age, background, disability, genetic information, parental or family status, religion or belief, race, ethnicity, nationality, sex, sexual orientation, gender identity (or expression), political belief, veteran status, or any other range of human difference brought about by identity and experience. We are on a journey towards ensuring our workforce is diverse at all levels and that our firm is representative of the world around us. We welcome applications from underrepresented groups.\nAdjustments or accommodations - Should you need any adjustments or accommodations to the recruitment process, at either application or interview, please contact us.","description_format":"text","description_chars":8357,"description_truncated":false,"requirements":{"experience_years_min":5,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[]},"benefits":["Annual leave","Growth opportunities","Hybrid work"],"hiring_locations":[{"name":"United Kingdom","iso":"GB","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":["Government","Professional Services","Penetration Testing","Management Consulting"],"lifecycle":[{"event":"open","at":"2026-10-05T10:14:53Z"}],"visa":[],"liveness":{"score":63,"band":"ok","label":"Likely open","p_open":1,"p_active":0.632,"p_room":1,"age_days":4,"expected_fill_days":36,"reasons":["conf:1","stale_co","velocity","win:early"],"computed_at":"2026-10-10T05:45:15Z"},"pay":null,"html_url":"https://alion.io/job/pa-consulting-ai-security-engineer","json_url":"https://alion.io/job/pa-consulting-ai-security-engineer.json","meta":{"generated_at":"2026-10-11T20:15:52Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","about":"Alion is a live layer of people, companies and AI agents: who they are, whether they are real and active right now, what they do and how to work with them, readable by people and by agents and paid per call.","catalog":"https://alion.io/catalog.json","usage":{"tier":"crawler_verified","counted_by":"address","units_charged":1,"used_today":7966,"day_limit":null,"remaining_today":null,"minute_limit":300,"resets_at":"2026-10-12T00:00:00Z"}},"offers":[{"id":"company.slices","title":"One company in depth, by slice","status":"live","price":{"credits":0.02,"usd":0.002,"plus_per_slice":{"credits":0.05,"usd":0.005}},"unit":"per company, plus each slice with data","note":"the employer in depth","call":{"mcp_tool":"get_company","arguments":{"id":6225},"rest":"https://alion.io/mcp/rest/get_company?id=6225"},"human":"https://alion.io/catalog?offer=company.slices&for=job%2Fpa-consulting-ai-security-engineer"},{"id":"market.stats","title":"A market slice: pay, demand and time to fill","status":"live","price":{"credits":1,"usd":0.1},"unit":"per slice","note":"pay, demand and time to fill for this role and place","call":{"mcp_tool":"market_stats"},"human":"https://alion.io/catalog?offer=market.stats&for=job%2Fpa-consulting-ai-security-engineer"},{"id":"job.search","title":"Open jobs by role, technology, place, pay and visa","status":"live","price":{"credits":0.02,"usd":0.002},"unit":"per posting in a list","note":"similar open postings","call":{"mcp_tool":"search_jobs"},"human":"https://alion.io/catalog?offer=job.search&for=job%2Fpa-consulting-ai-security-engineer"},{"id":"company.verify","title":"Is this company real and active right now","status":"pilot","price":null,"unit":"per company","request":{"url":"https://alion.io/catalog/request","method":"POST","body":"{\"offer\": \"company.verify\", \"for\": \"job/pa-consulting-ai-security-engineer\", \"note\": \"what you need it for\"}"},"human":"https://alion.io/catalog?offer=company.verify&for=job%2Fpa-consulting-ai-security-engineer"}]}