14 hours ago
Chennai, IndiaStaff+
Responsibilities
- Own and maintain AI security reference architectures across Azure, AWS, and GCP AI service stacks.
- Define security baselines for Azure OpenAI Service, Azure AI Foundry, Microsoft Copilot, Amazon Bedrock, SageMaker, Vertex AI, and GCP Gemini services.
- Conduct STRIDE-based threat modeling and develop platform-specific security controls, standards, and implementation requirements.
- Co-design secure AI solutions and provide architecture guidance, security blueprints, design reviews, and formal security sign-off.
- Develop AI-native security patterns for identity, data protection, AI supply chains, guardrails, and secure infrastructure deployment.
- Design security controls for prompt injection defenses, agentic AI workflows, and multi-agent orchestration platforms.
- Integrate security requirements into Infrastructure as Code and infrastructure delivery pipelines.
Requirements
- 10+ years of cloud security architecture experience, including at least three years focused on AI/ML security in public cloud environments.
- Hands-on experience with at least two of Azure AI Foundry, Azure OpenAI Service, Amazon Bedrock, or Vertex AI, including security configuration, network isolation, and identity architecture.
- Experience developing enterprise-scale cloud security reference architectures and technical security standards.
- Strong STRIDE threat-modeling expertise and familiarity with MITRE ATLAS and OWASP LLM Top 10 for cloud-hosted AI systems.
- Experience designing AI workload identity architectures using managed identities, OAuth 2.0 client credentials, workload identity federation, RBAC, and ABAC.
- Strong understanding of encryption, data residency, tokenization, VPC architectures, and private endpoints.
- Experience addressing AI supply-chain risks, including model provenance, SBOMs, dependency management, and model registry security.
- Hands-on experience with Terraform, Bicep, or CloudFormation and integrating security into infrastructure delivery pipelines.
- Preferred experience with prompt-injection defenses, Azure APIM content filtering, Amazon Bedrock Guardrails, Vertex AI safety controls, LangGraph, AutoGen, or Semantic Kernel.
- Preferred certifications include AZ-500, SC-100, AWS Security Specialty, or GCP Professional Cloud Security Engineer.
- Preferred familiarity with Azure Monitor AI logging, CloudTrail monitoring for Bedrock workloads, and Vertex AI audit logging.
- Experience in consulting, managed security services, product security, or enterprise AI adoption programs is helpful.
- Ability to influence technical decisions and collaborate with hyperscaler solution architects and engineering teams.
Benefits
- Hybrid work arrangement with attendance at a Cognizant or client office based on business and project requirements.
- Wellbeing programs supporting work-life balance.
Tech Stack
Categories
About Cognizant
Cognizant is a public IT services and consulting firm that designs, builds, and runs enterprise technology, including digital engineering, cloud modernization, data/AI, and managed services. It sells consulting, systems integration, and outsourcing on multi-year engagements to large enterprises in healthcare, banking, retail, communications, and manufacturing. Founded in 1994 and headquartered in Teaneck, New Jersey, Cognizant is NASDAQ-listed (CTSH) and a Fortune 500 company.
