AI Security Manager
McKinsey & Company · Prague +1 · 5h ago
ManagerOn-siteSecurity
Who you'll work with
You are someone who thrives in a high-performance environment, bringing a growth mindset and entrepreneurial spirit to tackle meaningful challenges that have a real impact.
In return for your drive, determination, and curiosity, we’ll provide the resources, mentorship, and opportunities to help you quickly broaden your expertise, grow into a well-rounded professional, and contribute to work that truly makes a difference.
When you join us, you will have:
- Continuous learning: Our learning and apprenticeship culture, backed by structured programs, is all about helping you grow while creating an environment where feedback is clear, actionable, and focused on your development. The real magic happens when you take the input from others to heart and embrace the fast-paced learning experience, owning your journey.
- A voice that matters: From day one, we value your ideas and contributions. You’ll make a tangible impact by offering innovative ideas and practical solutions, all while upholding our unwavering commitment to ethics and integrity. We not only encourage diverse perspectives, but they are critical in driving us toward the best possible outcomes.
- Global community: With colleagues across 65+ countries and over 100 different nationalities, our firm’s diversity fuels creativity and helps us come up with the best solutions. Plus, you’ll have the opportunity to learn from exceptional colleagues with diverse backgrounds and experiences.
- Exceptional benefits: On top of a competitive salary (based on your location, experience, and skills), we provide a comprehensive benefits package to enable holistic well-being for you and your family.
What you'll do
You will help enable the secure, responsible, and scalable adoption of AI.
You will lead and support AI security work across AI control design and implementation, product security reviews with AI use cases, threat modelling, and practical AI security enablement for engineering, product, client-service, and citizen-developer communities.
You will operate across a fast-moving portfolio of AI security priorities, partnering with security capability teams, Responsible AI, Red Team, Technology Risk, product and engineering teams, and 2nd Line Risk stakeholders. Syndicating with multiple stakeholders, you will translate emerging AI risks, including prompt injection, data leakage, unsafe tool execution, agentic actions into practical controls, design patterns, testing approaches, and guidance that can be embedded into AI products, platforms, and delivery processes.
Your responsibilities will focus on maturing the AI security program by designing, operationalizing, and embedding security controls across the AI lifecycle. You will conduct threat modeling, lead security reviews for AI products, and support red-team evaluations of AI models to ensure secure adoption. A key part of your work will involve enabling secure agentic AI by defining controls for agent authentication, authorization, and monitoring. You will also strengthen AI security governance, partner with various technology, AI security tooling and cross-functional risk teams to align on security priorities and develop reusable guidance and training materials to build security capability across engineering, product, and client-service teams.
Your work is central to helping McKinsey innovate with AI while protecting client, colleague, and firm information and maintaining trust. Your work will turn rapidly evolving AI security risks into scalable safeguards that enable teams to move quickly and responsibly.
Your background
- 5+ years of experience in information security, product security, cloud security, security architecture, or a comparable technical security role; experience securing AI/ML or data platforms is strongly preferred
- Strong background in secure SDLC, DevSecOps, and cloud architectures (AWS/Azure/GCP), microservices, serverless, APIs, containers, databases, disaster recovery, observability with the ability to apply Threat Modeling methodologies such as STRIDE, MAESTRO or equivalent approaches to AI use cases
- Demonstrated understanding of emerging AI technologies, GenAI and agentic-AI security risks and mitigations, including prompt injection, data leakage and exfiltration, unsafe tool execution, model and supply-chain risks, context and prompt-engineering risks, agent identity, and delegated permissions
- Experience designing and implementing security controls and translating risk or policy requirements into practical technical requirements, design patterns, implementation roadmaps, and operating procedures, underpinned by strong IAM knowledge (OAuth/OIDC, service principals, token scopes, secrets management, and policy enforcement)
- Experience conducting risk assessments, product-security reviews, audits, and red-team/adversarial testing, with working knowledge of standards like ISO 27001, SOC 2, NIST CSF, NIST SP 800-53, and GDPR
- Experience with security technologies and tooling, such as SAST, DAST, vulnerability scanning, secrets scanning, cloud security posture management, IAM, SIEM, IDS/IPS, firewalls, network monitoring, and AI-security tooling. Familiarity with platforms such as Wiz, Prisma AIRS, GitGuardian, Koi, or comparable tools is beneficial
- Ability to communicate complex AI security risks and controls clearly to technical and non-technical stakeholders, and to create effective guidance, training, and reusable materials for engineering, data science, product, and citizen-developer communities
- Strong analytical, organisational, stakeholder-management, written, and verbal communication skills, with the ability to independently manage competing priorities and work effectively across multiple teams and seniority levels