AI Security Consultant
Job Summary
We believe in the power of ingenuity to build a positive human future. We challenge where it matters and own the outcome. We combine strategic thinking customer-centric service design and agile engineering practices to accelerate innovation in a tech-driven world.
Why consider joining our Digital & Data community
- Join our Digital & Data team working alongside product design and a wide range of other experts and cross-disciplinary teams to bring ideas to life through innovative software solutions.
- Grow a flexible and unique career within a trust-based inclusive environment that values excellence innovation and curiosity. You have the option to progress with us on a technical career track. No need to go onto the Partner career track if this doesnt align with what you want to do.
- Hybrid working - our approach is to be in the office or on client site a minimum of 2 days per week.
- Work on a broad variety of projects and tech stacks for clients across seven sectors - no project is ever the same
- Join other experts within our supportive and collaborative tech community through knowledge-sharing and peer-level support coaching and mentoring
- Deepen your expertise through our culture of learning and growth youll have budget to take courses (technical and non-technical training) plus gain certifications
Role Overview
We are looking for an AI Security Consultant to help organisations secure the next generation of technology environments including AI-enabled applications LLM integrations and agentic systems.
This is a cyber security consulting role with an AI focus. You will advise clients on core cyber security risks across cloud identity applications data operations and governance while also helping them understand and manage the new risks introduced by AI systems that can reason retrieve data call tools and take action.
You will work with clients to assess AI security risks threat model agentic workflows design practical controls and identify where AI can safely improve cyber security operations. This may include supporting secure AI adoption reviewing LLM-based applications advising on SOC automation developing AI security guardrails and helping organisations use AI to enhance detection response reporting and risk management.
The right candidate will combine strong cyber security fundamentals with curiosity and practical knowledge of AI security. You should be able to explain complex risks clearly work with both technical and senior stakeholders and provide advice that is proportionate actionable and aligned to business outcomes.
Key Responsibilities
Cyber Security Consulting
- Conduct cyber security assessments across technology estates cloud environments applications networks identity platforms and operational processes.
- Review security architectures and provide pragmatic recommendations aligned to business risk.
- Support the design and implementation of security controls across areas such as access management data protection logging and monitoring vulnerability management incident response and third-party risk.
- Help clients interpret security requirements assess control maturity and develop actionable improvement roadmaps.
- Translate technical findings into clear business-relevant advice for senior stakeholders.
AI and Agentic System Security
- Assess the security risks associated with AI-enabled applications LLM integrations AI agents autonomous workflows and model-connected business processes.
- Review AI system designs for risks such as prompt injection excessive agency data leakage insecure tool use unsafe output handling model supply chain exposure and weak human oversight.
- Support threat modelling for agentic systems including how agents access tools call APIs retrieve data make decisions and trigger actions.
- Advise on secure patterns for AI application development including permission boundaries identity controls sandboxing auditability input/output validation and human-in-the-loop controls.
- Help clients establish governance and assurance processes for AI systems across the lifecycle from experimentation through to production deployment.
AI-Enabled Security Operations
- Identify opportunities to use AI safely to improve cyber security operations such as alert triage threat intelligence enrichment incident summarisation detection engineering reporting vulnerability prioritisation and control testing.
- Support the evaluation and adoption of AI-enabled security tools ensuring appropriate security privacy governance and operational safeguards are in place.
- Help security teams design workflows where AI augments analysts without introducing unacceptable risk over-reliance or loss of accountability.
- Develop practical playbooks guardrails and operating models for the responsible use of AI within SOC GRC vulnerability management and incident response functions.
- Work with clients to measure the effectiveness limitations and risks of AI-assisted security processes.
Qualifications :
Essential requirements
Even if you dont meet every requirement below feel free to still apply as we are often hiring for similar roles which your background might be better suited to.
- Strong background in cyber security consulting security architecture risk management or security operations.
- Good understanding of common security domains including identity and access management cloud security application security data protection vulnerability management incident response and security monitoring.
- Ability to assess technical environments and produce clear prioritised recommendations.
- Experience engaging with both technical teams and senior business stakeholders.
- Understanding of AI generative AI or LLM-enabled systems including how AI applications interact with data prompts APIs tools and users.
- Awareness of emerging AI security risks such as prompt injection sensitive information disclosure excessive agency insecure output handling model/data poisoning vector or embedding weaknesses and AI supply chain risk.
- Ability to perform threat modelling for complex systems including AI-assisted or agentic workflows.
- Strong written and verbal communication skills with the ability to explain emerging technical risks in simple practical terms.
Desirable Skills
- Experience with AI governance responsible AI model risk management or AI assurance.
- Familiarity with frameworks and guidance such as NIST AI RMF OWASP Top 10 for LLM Applications OWASP Agentic AI guidance MITRE ATLAS ISO 27001 NIST CSF CIS Controls or cloud security frameworks.
- Experience with SOC operations SIEM/SOAR platforms detection engineering threat intelligence or incident response.
- Knowledge of AI-enabled development platforms agent frameworks retrieval-augmented generation model APIs vector databases or automation/orchestration tools.
- Experience designing guardrails for autonomous systems including least privilege approval workflows action limits logging monitoring and rollback mechanisms.
- Relevant certifications such as CISSP CISM CCSP GIAC ISO 27001 Lead Implementer/Auditor cloud security certifications or AI/security-focused training.
Please be aware that some of our UK roles at PA Consulting require a UK security clearance.
All PA people are required to undergo background checks and to achieve the Baseline Personnel Security Standard however some UK roles also require higher levels of National Security Vetting where applicants must have at least 5 years of continuous residency in the UK.
We therefore ask that you only apply if you meet the residency requirements (i.e. you are a British citizen or have been resident in the UK for the past 5 years) as this is the prerequisite for a security clearance. If youre unsure about your eligibility we encourage you to review the UK Governments guidance on security vetting before applying.
Additional Information :
Assessment process
Please note that the interview stages may be subject to change based on the specific requirements of the role.
- Quick call with one of our Tech Recruiters to discuss your application the role and PA
- Round 1: Either a competency or technical interview (60 mins)
- Round 2: Either a competency or technical interview whichever you didnt do at first round (60 mins)
- Final round : Meeting with a PA leader - a mini case study and discussion around your client-centricity (60 mins)
Life At PA encompasses our peoples experience at PA. Its about how we enrich peoples working lives by giving them access to unique people and growth opportunities and purpose led meaningful work.
Our purpose guides how we work with our clients and our teams and support our communities to deliver insight and impact solving the worlds most complex challenges. Were focused on building a workplace that values human difference and diverse mindsets and a culture of inclusion and equality that unlocks the potential in our people so everyone can be their best self.
Find out more about Life at PA here.
We are dedicated to supporting the physical emotional social and financial well-being of our people. Check out some of our extensive benefits:
- Health and lifestyle perks accompanying private healthcare for you and your family
- 25 days annual leave (plus a bonus half day on Christmas Eve) with the opportunity to buy 5 additional days
- Generous company pension scheme
- Opportunity to get involved with community and charity-based initiatives
- Annual performance-based bonus
- PA share ownership
- Tax efficient benefits (cycle to work give as you earn)
Were committed to advancing equality. We recruit retain reward and develop our people based solely on their abilities and contributions and without reference to their age background disability genetic information parental or family status religion or belief race ethnicity nationality sex sexual orientation gender identity (or expression) political belief veteran status any other range of human difference brought about by identity and experience. We welcome applications from underrepresented groups.
Adjustments or accommodations - Should you need any adjustments or accommodations to the recruitment process at either application or interview please contact us on
#LI-SG1
Remote Work :
Yes
Employment Type :
Full-time
About Company
WERE NOT A TRADITIONAL CONSULTING FIRM Our clients recognize that were different. We stand apart not just in what we do but even more so in how we do it. Our strategy work focuses on turning innovation into real-world outcomes. At the core of our business are our people a divers ... View more