Source description
About the role
Job Title: AI Security Engineer
Role Overview
We are seeking a skilled AI Security Engineer to help design, implement, and maintain secure cloud-native AI platforms and applications. This role focuses on securing AI/ML workloads, cloud infrastructure, APIs, data pipelines, and modern software supply chains across enterprise environments.
The ideal candidate will have a strong background in cloud security engineering , combined with practical exposure to AI/ML technologies, AI security risks, and MLSecOps practices . You will work closely with cloud, engineering, DevOps, and AI/ML teams to implement scalable security controls and support secure adoption of AI-enabled solutions.
This role also includes supporting software and AI supply chain security initiatives through management and validation of SBOM, CBOM, AIBOM, and KBOM artifacts.
Key Responsibilities
- Cloud Security Engineering
Design, implement, and maintain security controls for cloud-native environments and AI/ML workloads.
Secure cloud infrastructure, services, APIs, containers, and workloads across public cloud platforms.
Experience in managing CSPM tools such as Prisma, wiz, orca etc.
Implement and manage:
IAM and least-privilege access controls
Network segmentation and secure connectivity
Encryption and key management
Secrets management and workload isolation
Logging, monitoring, and alerting controls
Conduct cloud security assessments, configuration reviews, and risk analysis.
Support security hardening for cloud-hosted AI services and model-serving infrastructure.
- AI/ML Security
Support secure deployment and operation of AI/ML systems, including:
LLM-based applications
RAG systems
Model APIs and inference services
Agentic AI workflows
Identify and assess AI-specific security risks such as:
Prompt injection and jailbreak attacks
Model abuse and unauthorized access
Data poisoning and sensitive data leakage
Model inversion and extraction attacks
Implement AI security controls including:
Prompt filtering and validation
Output sanitization
Access restrictions and guardrails
Data protection and context isolation
Participate in AI threat modeling and security design reviews.
- MLSecOps / DevSecOps
Integrate security controls into AI/ML and cloud CI/CD pipelines.
Support secure practices for:
Model training and deployment
Container security
Infrastructure as Code (IaC)
Dependency and artifact validation
Implement automated security checks for:
Models and datasets
APIs and infrastructure
Containers and cloud workloads
Assist with secure model versioning, rollback, and deployment validation.
- Software & AI Supply Chain Security
Support secure software and AI supply chain initiatives.
Generate, validate, and manage:
SBOM (Software Bill of Materials)
CBOM (Cryptography Bill of Materials)
AIBOM (AI Bill of Materials)
KBOM (Knowledge Bill of Materials)
Integrate BOM generation and validation into CI/CD and deployment workflows.
Track dependencies, model provenance, datasets, third-party AI integrations, and cryptographic components.
Support vulnerability management and compliance activities related to software and AI supply chains.
Required Qualifications
Bachelor’s degree in Computer Science, Cybersecurity, Information Security, or related field (or equivalent practical experience).
4–7 years of experience in:
Cloud security engineering
Security operations or security engineering
Application or infrastructure security
Hands-on experience with cloud-native security controls, architectures and CSPM tools.
Understanding of:
IAM, encryption, network security, and secrets management
Secure SDLC and vulnerability management
Containers, APIs, and CI/CD security
Familiarity with AI/ML concepts and AI security risks.
Experience with scripting/programming languages such as:
Python (preferred)
Bash, Go, or JavaScript/TypeScript
Preferred Qualifications
Experience with:
AI/ML platforms and orchestration frameworks
RAG systems, vector databases, and model-serving platforms
Infrastructure as Code (Terraform, CloudFormation, etc.)
Security automation and cloud compliance tooling
Familiarity with:
OWASP Top 10 for LLMs
NIST AI RMF
MITRE ATLAS
MLSecOps and MLOps concepts
Experience working with:
BOM standards and tooling (CycloneDX, SPDX, etc.)
Container and artifact security solutions
Secure software supply chain practices
Relevant cloud or security certifications are a plus.
Core Competencies
Strong analytical and troubleshooting skills
Ability to identify and mitigate cloud and AI security risks
Effective communication and collaboration across technical teams
Strong ownership mindset and attention to detail
Ability to work in fast-paced, engineering-driven environments
What Makes This Role Unique This role combines cloud security engineering with modern AI/ML security practices . You will help secure cloud-native AI systems, protect AI-enabled workloads, and strengthen software and AI supply chain security through practical implementation of controls, automation, and secure engineering practices.
More at AU Small Finance Bank