AI and Cloud Security Analyst
TD SYNNEX (NYSE: SNX) is the world's largest IT distributor, adopting AI at speed across Azure AI Foundry, AWS Bedrock, Copilot Studio, Databricks, and self-hosted agent environments. Our security model is runtime-first: instead of blocking AI adoption with slow approvals, we intercept, analyze, and enforce at the moment of execution — which means high-quality monitoring, triage, analytics, and reporting are what keep the system honest.
As our AI and Cloud Security Analyst, you provide day-to-day L2 coverage of the AI security detection fabric — triaging and supporting investigation of AI-specific detections from runtime defense, behavioral/intent monitoring, model-security, and adversarial-testing platforms. You turn that telemetry into insight through data analytics and produce the OCR (operational, compliance, and risk) reporting that gives leadership, control owners, and auditors a continuous picture of AI and cloud risk. You also help monitor the security posture of our Azure, AWS, and GCP environments. You escalate to a dedicated L3 engineer and work alongside two AI & Cloud Security Architects.
The analyst will report to AI & Cloud Security leadership and have strong working relationships with other Cybersecurity, IT and application development teams.
Responsibilities
- L2 coverage of the AI Security toolset. Monitor AI security detections across the detection fabric — runtime defense/AIDR events, intent and behavioral anomalies, model-level detections, and adversarial-testing signals. Validate detections, classify severity and impact, propose and implement policy updates, and escalate complex cases to L3 with complete, reusable context.
- Investigate AI-specific events across all five AI archetypes (embedded SaaS copilots, low-code/no-code agents, homegrown agentic pipelines, device-based coding agents, homegrown models): direct and indirect prompt injection, jailbreaks, sensitive-data leakage, RAG poisoning indicators, unauthorized MCP/tool activity, agent hijacking, and rogue or overprivileged agent behavior — using prompt/response logs, decision traces, identity context, and agent inventory data.
- Support the AI asset-intelligence layer: help maintain agent inventory hygiene, ownership attribution, MCP registry accuracy, and risk-scoring context that feeds runtime enforcement decisions and fast-track approval workflows.
- Data analytics. Query and correlate AI and security telemetry (KQL), identify anomalies and attack patterns, and build/maintain dashboards tracking the program's key metrics — detection volumes, runtime containment rate, mean time to detect/contain/resolve, agent-visibility coverage, approval-SLA performance, and top policy-violation categories — feeding tuning recommendations back to the L3 engineer.
- OCR reporting (operational, compliance, and risk). Produce recurring dashboards and executive summaries communicating AI-security posture, KPIs, and trends to stakeholders and control owners; support automated NIST AI RMF compliance evidence generation and audit/regulatory reporting, including EU AI Act–related evidence for EU scope.
- Maintain rigorous case documentation and shift/handover notes; contribute observed patterns to detection-rule tuning, runbook refinement, and the closed-loop improvement cycle (red-team findings → policy and detection updates → re-test validation).
- Build working fluency in the OWASP Top 10 for LLM Applications 2025, the OWASP Top 10 for Agentic Applications, and MITRE ATLAS as the shared investigation taxonomy.
- Monitor and triage cloud security alerts across Azure, AWS, and GCP from company CSPM platform — misconfigurations, security risks, exposed resources, excessive permissions, workload threats — and route, remediate, or escalate per playbook.
- Support cloud compliance monitoring and reporting against CIS Benchmarks and NIST 800-53 r5 / CSF 2.0 baselines, tracking remediation to closure and integrating cloud posture into the consolidated OCR reporting. Support L3 engineer with policy updates.
- Assist with cloud workload vulnerability triage (VMs, containers, images) and with Microsoft 365 / Google Workspace security-signal review.
- Partner with the L3 engineer, SOC, cloud teams, and incident responders on investigations and enrichment spanning cloud, identity, endpoint, and AI telemetry.
Critical Skills
- Solid security operations fundamentals: alert monitoring, triage, validation, incident classification, escalation, and case management against SLAs, working from runbooks in a follow-the-sun/handover model.
- Strong data analytics and reporting: KQL (and/or SQL) for querying and correlation; dashboard and report development; the ability to turn telemetry into clear, decision-ready operational, compliance, and risk reporting.
- Foundational AI/GenAI security awareness: LLM risks (prompt injection, jailbreaks, data leakage), agentic AI and MCP concepts, AI guardrails, and familiarity with the OWASP LLM Top 10 and MITRE ATLAS. Exposure to AI security platforms is a strong plus.
- Working knowledge of cloud security in at least one of Azure/AWS/GCP (multi-cloud exposure preferred), including CSPM/CWPP concepts and cloud identity basics.
- Scripting for automation and enrichment (PowerShell and/or Python).
- Familiarity with CIS Benchmarks and NIST (800-53, CSF); awareness of NIST AI RMF and the EU AI Act is beneficial, particularly for EU-based candidates.
- Analytical rigor, attention to detail, and clear English communication across a globally distributed team spanning multiple time zones.
Experience
- SOC, security operations, cloud security, or security-analyst role with hands-on monitoring, triage, and investigation experience; exposure to AI/GenAI security is an advantage.
- Demonstrable experience producing analytics, dashboards, and reporting from security telemetry for technical and executive audiences.
- Experience supporting compliance or audit evidence collection (NIST, CIS, ISO, or similar) is a plus.
- Certifications are an advantage, not mandatory: CompTIA Security+, CySA+, SC-200, SC-900, AZ-500, AWS or GCP security/foundational credentials; AI-security coursework or credentials are a plus.
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or equivalent practical experience.
Working conditions
- Willing to work nonstandard business hours for projects, business impact issues and incident response.
- Some travel required.
- Flexible remote work.
At Tech Data, a TD SYNNEX Company, our values guide everything we do: Together, We Own It, We Dare to Go, We Grow and Win, and above all, We Do the Right Thing. These principles shape how we work with each other, our partners, and our communities as we drive innovation and create lasting impact.
What’s In It For You?
- Elective Benefits: Our programs are tailored to your country to best accommodate your lifestyle.
- Grow Your Career: Accelerate your path to success (and keep up with the future) with formal programs on leadership and professional development, and many more on-demand courses.
- Elevate Your Personal Well-Being: Boost your financial, physical, and mental well-being through seminars, events, and our global Life Empowerment Assistance Program.
- Diversity, Equity & Inclusion: It’s not just a phrase to us; valuing every voice is how we succeed. Join us in celebrating our global diversity through inclusive education, meaningful peer-to-peer conversations, and equitable growth and development opportunities.
- Make the Most of our Global Organization: Network with other new co-workers within your first 30 days through our onboarding program.
- Connect with Your Community: Participate in internal, peer-led inclusive communities and activities, including business resource groups, local volunteering events, and more environmental and social initiatives.
Don’t meet every single requirement? Apply anyway.
At Tech Data, a TD SYNNEX Company, we’re proud to be recognized as a great place to work and a leader in the promotion and practice of diversity, equity and inclusion. If you’re excited about working for our company and believe you’re a good fit for this role, we encourage you to apply. You may be exactly the person we’re looking for!
We are an equal opportunity employer and committed to building a diverse team that represents and empowers a variety of backgrounds, perspectives, and skills. All qualified applicants will receive consideration for employment based on merit, without regard to race, colour, religion, national origin, gender, gender identity or expression, sexual orientation, protected veteran status, disability, genetics, age, or any other characteristic protected by law. To support our diversity and inclusion efforts, we may ask for voluntary gender disclosure information. This data will be used solely to improve our hiring practices and ensure fair treatment for all candidates.