HamburgerMenu
hirist

Virtusa - AI Security & Information Protection Analyst - Agentic AI

Virtusa Consulting Services
5 - 10 Years
Multiple Locations

Posted on: 29/09/2026

showcase-imageshowcase-imageshowcase-image

Job Description

Role Overview :

We are looking for an experienced AI Security & Information Protection Analyst with a strong understanding of Agentic AI, LLMs, RAG, AI security risks, and enterprise Data Loss Prevention (DLP). The ideal candidate will be able to assess AI use cases and deployments for security and data-protection risks while supporting DLP operations, AI governance, investigations, and security controls across enterprise environments.

Key Responsibilities :

- Assess Agentic AI use cases, including LLM agents, tool/function calling, orchestration workflows, and RAG architectures, for security and data-protection risks.

- Identify and evaluate risks such as prompt injection, data exfiltration, model abuse, unsafe tool invocation, privilege escalation, and AI supply-chain threats.

- Support the design and implementation of AI security guardrails, secure configurations, role and data scoping, allow/deny policies, reference architectures, and secure usage guidelines.

- Administer, monitor, and tune DLP controls across endpoints, email, collaboration platforms, cloud environments, SaaS applications, and other enterprise channels.

- Monitor and triage DLP and information-protection alerts, coordinate with data owners and Legal/Privacy teams, and drive remediation.

- Improve enterprise data classification, sensitivity labelling, and protection policies to address AI-related data risks.

- Identify unsanctioned AI applications, risky plugins, browser extensions, shadow AI usage, and unauthorized data uploads.

- Support security investigations using agent logs, tool-call traces, prompt/response histories, and application telemetry.

- Develop and maintain AI security incident-response playbooks, detections, KPIs, and KRIs.

- Contribute to AI security policies, standards, awareness programs, and secure AI adoption guidance.

- Support third-party AI and SaaS security assessments covering data residency, data retention, training-data usage, auditability, transparency, and privacy controls.

- Partner with Cybersecurity, Privacy, Legal, IAM, Data, Engineering, and business teams to implement practical security controls.

- Continuously monitor emerging AI security threats, attack patterns, and defensive techniques and incorporate relevant improvements into security controls and guidance.

Required Skills & Experience:

- 5 - 10 years of experience in cybersecurity, information protection, data security, cloud/SaaS security, security operations, or a closely related field.

- Foundational to hands-on understanding of Agentic AI, LLMs, RAG, prompt injection, data leakage/exfiltration, and AI security risks.

- Strong understanding of DLP policies, classifiers, incident workflows, data classification, and information protection controls.

- Good understanding of IAM, least privilege, network security, cloud security, and SaaS security principles.

- Experience with at least one enterprise DLP, CASB, SSE, SIEM, EDR, cloud-security, or SaaS-governance platform.

- Experience monitoring, investigating, and responding to security or data-protection alerts.

- Ability to analyze logs, JSON, agent traces, tool calls, and security telemetry.

- Strong analytical, documentation, problem-solving, and stakeholder communication skills.

- Ability to work effectively in ambiguous environments and translate emerging technical risks into practical security controls and guidance.

- Strong willingness to learn emerging AI security technologies, threats, and frameworks.

Desirable Skills:

- Exposure to LLM ecosystems, agent frameworks, vector databases/vector stores, model gateways, and AI orchestration platforms.

- Knowledge of prompt-injection, excessive agency, insecure tool usage, data-exfiltration, and other common LLM/Agentic AI attack patterns.

- Experience tuning DLP classifiers, including EDM/IDM fingerprinting and content-based detection.

- Familiarity with privacy and regulatory requirements related to enterprise data and AI.

- Experience performing SaaS, AI vendor, or third-party technology risk assessments.

- Scripting experience with Python and/or PowerShell.

- Knowledge of NIST AI RMF, ISO/IEC 23894, OWASP guidance for LLM applications, or MITRE ATLAS.

- Experience developing security detections, automation, or investigation playbooks.

Expected Outcomes - First Six Months :

- Establish a baseline of sanctioned and unsanctioned AI usage across the environment.

- Improve the precision and effectiveness of AI-focused DLP controls and detections.

- Publish practical secure AI usage and implementation guidance.

- Implement initial detections and response playbooks for prompt injection, risky tool usage, and abnormal data movement.

- Complete at least one AI vendor or AI solution security/risk assessment.

- Establish meaningful AI security KPIs/KRIs and reporting mechanisms.

info-icon

Did you find something suspicious?

Similar jobs that you might be interested in

Loading chat...