14 hours ago
Chennai, IndiaStaff+
Responsibilities
- Design, build, and maintain reusable AI security guardrails, including prompt sanitization SDKs, output filtering, PII/PHI redaction, and topic boundary enforcement.
- Develop and maintain adversarial test automation for prompt injection, RAG exfiltration, jailbreaks, model extraction, agent abuse, and supply-chain attacks.
- Run adversarial validation tests against AI workloads submitted for production review, document findings and severity, and issue residual risk statements.
- Integrate AI security controls into DevSecOps pipelines, including prompt validation, dependency scanning, model integrity checks, and workload security requirements.
- Engineer reusable IaC security modules, SIEM telemetry, anomaly signatures, detection logic, and implementation recommendations.
- Communicate adversarial findings to senior security leaders and partner with development teams on mitigations.
Requirements
- 10+ years of experience in security engineering or application security, including 3+ years directly in AI/ML security, red teaming, or AI security tool development.
- Hands-on experience writing and shipping production Python; TypeScript or Go experience is preferred.
- Experience integrating or extending at least two AI security tools such as Garak, PyRIT, LLM Guard, Presidio, NeMo Guardrails, or Lakera Guard.
- Experience executing prompt injection, indirect prompt injection, and jailbreak attacks against real LLM applications.
- Experience securing RAG pipelines, including retrieval-based data exfiltration, embedding inversion, vector store poisoning, and related defenses.
- Experience testing agentic systems for agent loop hijacking, tool abuse, and privilege escalation in multi-agent orchestration frameworks.
- Strong understanding of OWASP LLM Top 10 and MITRE ATLAS and the ability to map TTPs to adversarial test cases.
- Experience integrating security into pipelines using GitHub Actions, Azure DevOps, or Jenkins.
- Preferred experience with SIEM detection logic, Sigma rules, KQL, SPL, Terraform, Bicep, LangChain, LangGraph, LlamaIndex, or Semantic Kernel.
- Published research, CVE disclosures, blog posts, conference talks, or other externally recognized AI or LLM security contributions are preferred.
- Experience in security engineering or red-team functions within a large enterprise or consulting organization is preferred.
- Ability to communicate findings to senior security leaders and collaborate with development teams.
Benefits
- Hybrid work model requiring 2–3 days in the office.
- Wellbeing programs and support for work-life balance.
- Flexibility may vary based on project and client requirements.
Tech Stack
Categories
About Cognizant
Cognizant is a public IT services and consulting firm that designs, builds, and runs enterprise technology, including digital engineering, cloud modernization, data/AI, and managed services. It sells consulting, systems integration, and outsourcing on multi-year engagements to large enterprises in healthcare, banking, retail, communications, and manufacturing. Founded in 1994 and headquartered in Teaneck, New Jersey, Cognizant is NASDAQ-listed (CTSH) and a Fortune 500 company.
