Posted on: 28/05/2026
Description :
- 6+ years of progressively responsible experience in application security, DevSecOps, product security, and/or security architecture, with increasing scope and ownership; including 2+ years in consulting, project leadership, or client-facing delivery.
- Strong knowledge of application, API, IAM, data, and cloud security architecture (authn/authz, encryption, key management, secrets, network trust boundaries, logging/monitoring, resiliency, and third-party dependencies).
- Hands-on experience designing or building AI agents/agentic workflows and securing LLM-enabled applications (chatbots/copilots), RAG pipelines, and tool/function calling patterns.
- Hands-on familiarity with agent frameworks and the AI agent stack (e.g., LangGraph, LangChain, CrewAI, AutoGen or equivalent), vector stores, evaluation/observability tooling, guardrails, and sandboxing patternsable to review engineers implementations.
- Familiarity with MCP (Model Context Protocol) or equivalent agent-to-system integration patterns, and ability to guide secure design choices when connecting agents to enterprise systems.
- Strong understanding of security frameworks/standards such as NIST 800-53, ISO 27001, CIS Controls, PCI DSS, plus AI-focused guidance such as NIST AI RMF and OWASP Top 10 for LLM Applications.
- Experience conducting LLM threat modeling and security testing (abuse/misuse cases, prompt injection/jailbreak testing, adversarial evaluation, and documenting mitigations and residual risk).
- Experience with AWS, Azure, and/or GCP security architectures, including identity, segmentation, encryption, logging, and workload protection for cloud-native and AI workloads (e.g., managed AI services, model endpoints, and data pipelines).
- Strong understanding of secure SDLC and AI secure-by-design practices, including design-time guardrails, privacy-by-design, and enforcing controls via automation (e.g., CI/CD policy gates, configuration baselines, and policy-as-code).
- Proficiency in risk assessment and threat modeling methodologies, and ability to translate findings into actionable architecture requirements and engineering backlogs.
- Exposure to zero trust architecture principles, including least privilege and continuous authorization patterns relevant to AI agents and tool access.
- Executive-level communication and stakeholder managementcomfortable presenting to CISOs/CTOs and driving decisions; strong documentation and quality-review skills for client deliverables.
Good-to-have skills / project experience / certifications (Advanced AI Security) :
- Experience implementing LLM security controls such as prompt/output filtering, LLM gateways / LLM firewall patterns, DLP for prompts and outputs, and safe content transformation/escaping.
- Experience with LLM evaluation and assurance : building evaluation criteria, maintaining test sets, running continuous evals for regression/drift, and supporting LLM red teaming operations.
- Model and data governance experience : dataset lineage/provenance, licensing/usage constraints, model provenance, dependency governance (model artifacts, packages), and documentation practices (e.g., model cards, risk registers).
- Experience translating architecture review findings into enterprise AppSec/DevSecOps program controls, including SAST, DAST, SCA, IaC scanning, container security, CI/CD policy gates, and vulnerability SLAs/prioritization.
- Experience reviewing third-party model providers, model hosting patterns, vector databases/embedding stores, and plugin/tool boundaries, including data residency, abuse controls, and shared responsibility.
- Familiarity with major AI platforms and deployment patterns (e.g., Azure OpenAI, AWS Bedrock, Google Vertex AI) and securing model endpoints, private networking, and keys/secrets.
- Experience with cloud security tooling such as CSPM/CNAPP, CIEM, container security, and policy enforcement tooling used to operationalize architecture standards.
- Familiarity with architecture and threat modeling tools such as :
1. Microsoft Threat Modeling Tool
2. IriusRisk
3. OWASP Threat Dragon
4. Microsoft Visio, Lucidchart, draw.io, or equivalent diagramming tools
- Experience integrating threat modeling or architecture review outputs into CI/CD or design governance workflow.
- Preferred certifications : SABSA, TOGAF, CCSP, AWS/Azure/GCP Security Architect certifications, CISSP, CSSLP, or equivalent.
Did you find something suspicious?
Posted by
Lalith Vuddagiri
Director - Strategy and Partnerships at Hawk Sense Business Solution pvt. ltd.
Last Active: 17 Aug 2026
Posted in
CyberSecurity
Functional Area
IT Security
Job Code
1639835