Data & Society Research Institute logo
Data & Society Research Institute

Data & Society studies the social implications of data-centric technologies and automation.

Post-Doctoral Fellow, AI-Enabled Scams as a Systemic Security Challenge

Security EngineerSecurity EngineerOtherRemoteMid LevelTeam 11-50Since 2014H1B No SponsorCompany SiteLinkedIn

Location

United States

Posted

1 day ago

Salary

$68K - $80K / year

Seniority

Mid Level

Job Description

Post-Doctoral Fellow, AI-Enabled Scams as a Systemic Security Challenge

Data & Society Research Institute

Role Description Data & Society is seeking a post-doctoral research fellow for our AI-Enabled Scams as a Systemic Security Challenge project, housed under our AI & Democracy initiative and led by Director of Research Dr. Alice Marwick. This position will report to the Director of Research, Alice Marwick, and will not have people manager responsibilities. This position is fully remote and will begin in September 2026 with an end date of May 31, 2028. The overall AI Scams project looks at how artificial intelligence is supercharging scams, frauds, and hoaxes. This specific project examines young people’s (Gen A/Z) susceptibility to scams, and how trust, legitimacy, and risk are constructed in online interactions. We are particularly interested in youth financial cultures, such as: - Cryptocurrency - Multi-level marketing schemes - Sports betting - Influencers - Prediction markets - Retail arbitrage - Memestocks - Drop-shipping - “Hustle and grind” culture The post-doctoral fellow will be working on a qualitative research project with two components: - Conducting interviews and focus groups with: - Individuals who have encountered or been harmed by AI-enabled scams - Youth involved in risky financial subcultures - Qualitative discourse and/or content analysis of scam materials, workflows, and use of generative tools. The end goal of this project is to translate our findings into bipartisan policy and governance recommendations, and to bring together consumer protection and cybersecurity perspectives on scams. Qualifications - PhD in any number of disciplines, with a strong background conducting empirical, qualitative research - Interest in questions related to youth, finance, risk, and emerging technology - Experience recruiting and working with populations for qualitative interview studies - Experience with discourse or content analysis (ideally) - Self-motivated and ambitious, with a collaborative spirit - Strong desire to understand how technology and power shape society - Able to write for multiple audiences Requirements - Excellent research, writing, and communication skills supported by a strong empirical foundation - Ability to independently conduct high-level qualitative research, including interviews, focus groups, content/discourse analysis, and other research methods - Experience with study recruitment - Expertise/interest in financial cultures, scams, generative AI, youth studies, economic sociology, or other relevant topics - Ability to work independently in a remote environment - Collaborative and generous intellectual partner - A strong history of work demonstrating a desire to understand how technology and power shape our sociotechnical society - Ability to translate research for non-academic audiences - A deep commitment to social change and the practical applications of research - Must be able to travel for conferences, workshops, or team meetings during the appointment Benefits - Salary range: $68,000 to $80,000 annually, commensurate with experience - Generous benefits package including medical, dental, and vision insurance - Access to a range of opt-in products and services including additional insurance and 401k management - Paid time off and paid federal holidays To Apply Please submit the following items by July 15, 2026: - A cover letter explaining your interest in this role and the research topic - An academic CV - The names, affiliations, and contact information for three (3) references - A 2-page research statement describing your research accomplishments and future trajectory - Two writing samples: one for an academic audience and one for a broad audience Applications will be reviewed beginning July 16, 2026. Please feel free to contact us at jobs@datasociety.net with any questions. Practical Considerations Data & Society has committed to safety requirements to protect our staff from the COVID-19 pandemic. We require that prospective employees are fully vaccinated against COVID-19 before joining our organization. This is currently a full-time, remote position in the AI & Democracy program with an expected start date in September 2026 and an end date of May 31, 2028. You must be living and authorized to work in the United States; we are unable to sponsor visas.

Related Categories

Related Job Pages

More Security Engineer Jobs

Role Description We are looking for a seasoned Cybersecurity Technical Architect to serve as the enterprise design authority for cybersecurity. This is a high-impact leadership role responsible for defining, governing, and continuously evolving the organization's end-to-end security architecture — spanning identities, applications, infrastructure, data, AI systems, and third-party ecosystems. You will combine deep technical expertise with strategic architectural leadership, translating business priorities and emerging threats into scalable, resilient, and compliant security capabilities. Experience: 12–18+ years overall | 6+ years in security architecture Key Responsibilities - Enterprise Security Architecture - Own and continuously evolve the enterprise cybersecurity architecture aligned with NIST CSF, ISO 27001, Zero Trust Architecture (ZTA), and Secure-by-Design principles. - Act as Security Design Authority for major enterprise initiatives, cloud transformations, and AI/digital programs. - Translate business strategy, regulatory requirements, and threat models into reusable security architecture patterns and reference designs. - Asset Management - Define and govern IT and Information Asset Management strategy. - Ensure accurate discovery, classification, and ownership of applications, APIs, infrastructure, data assets, and AI/ML models. - Integrate asset inventory with risk, vulnerability, and incident response functions. - Identity & Access Management (Zero Trust) - Architect and oversee IAM capabilities including identity lifecycle management, PAM, SSO, MFA, and adaptive access controls. - Drive enterprise-wide Zero Trust adoption across users, devices, workloads, services, and APIs. - DevSecOps & Secure Development - Lead the Secure SDLC strategy and define security guardrails for CI/CD pipelines, IaC, APIs, microservices, and cloud-native workloads. - Govern SAST, DAST, SCA, secrets scanning, and container/Kubernetes security tooling. - Endpoint Security - Architect endpoint and workload protection across laptops, mobile, servers, VMs, and cloud workloads. - Govern enterprise standards for EDR/XDR, device compliance, encryption, OS hardening, and baseline configurations. - Security Testing & Assurance - Own the security testing framework including continuous vulnerability scanning, penetration testing, and red/purple team exercises. - Establish remediation tracking and risk acceptance aligned with enterprise risk appetite. - AI Governance & Security - Define and enforce AI security controls covering GenAI/ML model use, data privacy, model integrity, prompt security, and abuse detection. - Assess AI-driven threats including model poisoning, data leakage, and adversarial prompts. - Third-Party Risk Management - Lead cybersecurity architecture for supplier and third-party risk, including due diligence, contractual security clauses, and continuous monitoring. Qualifications - Enterprise security architecture (on-prem, cloud, hybrid) - Identity & Access Management and Zero Trust frameworks - DevSecOps and application security - SIEM, SOAR, EDR/XDR, and vulnerability management - API, data, and cloud security - AI/ML security principles and governance Preferred Qualifications - Bachelor's degree in Computer Science or equivalent - Certifications: CISSP, CISM, SABSA, CCSP, TOGAF - Cloud security certifications (AWS, Azure, GCP) - Experience in regulated industries and global security programs Leadership & Influence - Proven experience leading cross-functional, enterprise-scale security initiatives - Ability to influence senior leaders, architects, and engineering teams - Strong architectural documentation, communication, and decision-making skills

India
₹5,000K - ₹6,000K / year
Part TimeRemoteTeam 501-1,000H1B No Sponsor

• Teaching graduate level courses in the field of cybersecurity through an interactive and online environment. • Participate in course development and review as needed and recommend changes to courses and curriculum design. • Manage an online classroom environment and assist in creating an effective Christian learning environment. • Motivate students to learn and grow in their knowledge and skills associated with cybersecurity within a Christian environment. • Perform other duties as needed.

Texas
Rimini Street logo

Associate Architect, SAP Security, Threat Mitigation

Rimini Street

Extraordinary technology solutions powered by extraordinary people

Full TimeRemoteTeam 1,001-5,000Since 2005H1B Sponsor

• Support the Rimini Protect! Security Services team to research threats, vulnerabilities, and weaknesses that affect the products and services supported and delivered by Rimini Street. • Work with the Rimini Protect team to research the applicability of reported Vulnerabilities to understand the weaknesses and exposures, determine applicable mitigations, and assist in the documentation of those mitigations. • Write, document and recommend work arounds and mitigations to assist in the development of new solutions and security controls that will be utilized by Rimini Street clients to proactively address vulnerabilities from a 0-day context as well as our regularly schedule Security Vulnerability Analysis Report (SVAR). • Closely work with the Client Success Managers (CSM) to conduct, review and make recommendations in the process of conducting a Security Audit for the customer’s ERP solution and Database environment.

Mexico
S + S Regeltechnik GmbH logo

Senior IT-Security Experte, m/w/d

S + S Regeltechnik GmbH

Ihr zuverlässiger Partner für Regelungstechnik, Sensorik & Messgeräte S+S Regeltechnik GmbH

Full TimeRemoteTeam 51-200H1B No Sponsor

• Konzeption, Umsetzung und Pflege von IT-Sicherheits- und Gesamtsicherheitskonzepten, inkl. Überführung in ein DB-gestütztes Content-Management-Systemen • Durchführung von Risikoanalysen, Schutzbedarfsfeststellungen sowie Ableitung geeigneter Maßnahmen • Coaching und fachliche Unterstützung bei der Erstellung, Pflege und Weiterentwicklung von IT-Sicherheitskonzepten und -Richtlinien • Beratung von technischen Produktverantwortlichen und IT-Sicherheitsverantwortlichen, insbesondere im Umgang mit dem ISMS-Tool • Abstimmung und Umsetzung neuer IT-Grundschutz- und BSI-Anforderungen in bestehenden Sicherheitskonzepten • Durchführung von internen Audits nach Vorgaben sowie Unterstützung bei IT-Sicherheitsanfragen • Erstellung, Review und Pflege aller mit geltenden sicherheitsrelevanten Dokumentationen

Germany