2 months ago
Remote, India +12 moreSenior
Responsibilities
- Build, deploy, and operate the AI runtime control plane and inline enforcement pipeline across Azure AI Foundry, AWS Bedrock, GCP Vertex, Copilot Studio, Databricks, and self-hosted environments.
- Harden AI gateway resilience through buffering, overload management, enforcement timeouts, rate limiting, and prompt-truncation controls.
- Integrate AI asset intelligence, model-security and supply-chain telemetry, red-team signals, SIEM correlation, SOC workflows, decision logs, and policy events.
- Author and tune runtime policies for prompt injection, jailbreaks, PII detection and redaction, data masking, intent filtering, tool-call validation, MCP access control, and agent permission boundaries.
- Translate adversarial-testing findings into policy updates, detection content, guardrail tuning, and validated remediation.
- Lead L3 investigations into AI attacks, perform decision-replay forensics and root-cause analysis, automate containment, and mentor L2 analysts.
- Evaluate AI security vendors and run proofs of concept for runtime defense, AIDR, AI-SPM, AI red-teaming, and model-security platforms.
- Engineer and operate security controls across Azure, AWS, GCP, AKS, and EKS, including posture management, detection tuning, remediation, identity, entitlements, and workload risks.
- Implement secure multi-cloud and zero-trust agent access patterns using least-privilege identities, conditional access, and OAuth scopes.
- Embed security into DevSecOps through Terraform scanning, container and Kubernetes security, secrets management, CI/CD hardening, and pre-deployment AI security testing.
- Support cloud workload vulnerability management across virtual machines, containers, registries, and serverless environments.
- Serve as an escalation point for investigations spanning cloud, identity, endpoint, and AI telemetry.
Requirements
- Significant hands-on engineering responsibility in cloud security across Azure, AWS, and GCP.
- Demonstrable experience securing or operating AI, ML, or LLM-based systems, or strongly evidenced ability to rapidly acquire AI-security expertise.
- Proven experience deploying, integrating, and tuning security platforms in complex enterprise environments and serving as an L3 or senior escalation point.
- Experience with enterprise security platform integration, API and connector engineering, log ingestion and normalization, SIEM/SOAR integration, and multi-vendor inline architectures.
- Strong knowledge of LLM and agentic-AI threat models, OWASP LLM Top 10 2025, OWASP Agentic Top 10, MITRE ATLAS, prompt-injection and jailbreak defense, RAG security, AI guardrails, gateways, MCP security, AI-SPM, AIDR, and AI red-teaming.
- Multi-cloud security engineering experience covering CSPM, CWPP, CNAPP, cloud identity and entitlements, Kubernetes and container security, hub-and-spoke architecture, segmentation, and baseline protection.
- Proficiency in KQL, PowerShell, and Python for automation, detection engineering, and tooling.
- Experience with DevSecOps, Terraform security, and CI/CD pipeline integration.
- Experience operating security tooling in Kubernetes-based environments such as AKS and EKS is advantageous.
- Experience integrating open-source components into enterprise stacks is advantageous.
- Vendor proof-of-concept experience is a plus.
- Relevant certifications such as CISSP, CCSP, SC-100, AZ-500, AWS Certified Security – Specialty, Google Professional Cloud Security Engineer, or AI security credentials strengthen an application.
- Bachelor’s degree in Computer Science, Cybersecurity, Information Systems, or equivalent practical experience.
- Excellent English communication skills, including runbooks, integration documentation, and communicating trade-offs to technical and leadership stakeholders.
- Ability to work effectively in a fast-paced, dynamic, globally distributed environment.
Benefits
- Flexible remote work is available.
- Elective benefits are tailored to the employee’s country.
- Formal leadership and professional development programs and on-demand courses are available.
- Financial, physical, and mental well-being support is provided through seminars, events, and the global Life Empowerment Assistance Program.
- Employees can participate in inclusive communities, business resource groups, volunteering, and environmental and social initiatives.
- The role includes onboarding and networking with new coworkers within the first 30 days.
- Some travel is required, and nonstandard business hours may be needed for projects, business-impact issues, and incident response.
