HamburgerMenu
hirist

AppSec & AI Security Manager

Hawk Sense Business Solution pvt. ltd.
8 - 10 Years
Multiple Locations

Posted on: 28/05/2026

Job Description

Description :

- 6+ years of progressively responsible experience in application security, DevSecOps, product security, and/or security architecture, with increasing scope and ownership; including 2+ years in consulting, project leadership, or client-facing delivery.

- Strong knowledge of application, API, IAM, data, and cloud security architecture (authn/authz, encryption, key management, secrets, network trust boundaries, logging/monitoring, resiliency, and third-party dependencies).

- Hands-on experience designing or building AI agents/agentic workflows and securing LLM-enabled applications (chatbots/copilots), RAG pipelines, and tool/function calling patterns.

- Hands-on familiarity with agent frameworks and the AI agent stack (e.g., LangGraph, LangChain, CrewAI, AutoGen or equivalent), vector stores, evaluation/observability tooling, guardrails, and sandboxing patternsable to review engineers implementations.

- Familiarity with MCP (Model Context Protocol) or equivalent agent-to-system integration patterns, and ability to guide secure design choices when connecting agents to enterprise systems.

- Strong understanding of security frameworks/standards such as NIST 800-53, ISO 27001, CIS Controls, PCI DSS, plus AI-focused guidance such as NIST AI RMF and OWASP Top 10 for LLM Applications.

- Experience conducting LLM threat modeling and security testing (abuse/misuse cases, prompt injection/jailbreak testing, adversarial evaluation, and documenting mitigations and residual risk).

- Experience with AWS, Azure, and/or GCP security architectures, including identity, segmentation, encryption, logging, and workload protection for cloud-native and AI workloads (e.g., managed AI services, model endpoints, and data pipelines).

- Strong understanding of secure SDLC and AI secure-by-design practices, including design-time guardrails, privacy-by-design, and enforcing controls via automation (e.g., CI/CD policy gates, configuration baselines, and policy-as-code).

- Proficiency in risk assessment and threat modeling methodologies, and ability to translate findings into actionable architecture requirements and engineering backlogs.

- Exposure to zero trust architecture principles, including least privilege and continuous authorization patterns relevant to AI agents and tool access.

- Executive-level communication and stakeholder managementcomfortable presenting to CISOs/CTOs and driving decisions; strong documentation and quality-review skills for client deliverables.

Good-to-have skills / project experience / certifications (Advanced AI Security) :

- Experience implementing LLM security controls such as prompt/output filtering, LLM gateways / LLM firewall patterns, DLP for prompts and outputs, and safe content transformation/escaping.

- Experience with LLM evaluation and assurance : building evaluation criteria, maintaining test sets, running continuous evals for regression/drift, and supporting LLM red teaming operations.

- Model and data governance experience : dataset lineage/provenance, licensing/usage constraints, model provenance, dependency governance (model artifacts, packages), and documentation practices (e.g., model cards, risk registers).

- Experience translating architecture review findings into enterprise AppSec/DevSecOps program controls, including SAST, DAST, SCA, IaC scanning, container security, CI/CD policy gates, and vulnerability SLAs/prioritization.

- Experience reviewing third-party model providers, model hosting patterns, vector databases/embedding stores, and plugin/tool boundaries, including data residency, abuse controls, and shared responsibility.

- Familiarity with major AI platforms and deployment patterns (e.g., Azure OpenAI, AWS Bedrock, Google Vertex AI) and securing model endpoints, private networking, and keys/secrets.

- Experience with cloud security tooling such as CSPM/CNAPP, CIEM, container security, and policy enforcement tooling used to operationalize architecture standards.

- Familiarity with architecture and threat modeling tools such as :

1. Microsoft Threat Modeling Tool

2. IriusRisk

3. OWASP Threat Dragon

4. Microsoft Visio, Lucidchart, draw.io, or equivalent diagramming tools

- Experience integrating threat modeling or architecture review outputs into CI/CD or design governance workflow.

- Preferred certifications : SABSA, TOGAF, CCSP, AWS/Azure/GCP Security Architect certifications, CISSP, CSSLP, or equivalent.

info-icon

Did you find something suspicious?

Similar jobs that you might be interested in

Loading chat...