Source description
About the role
Job Title : AI Security Engineer Role Overview : We are seeking a skilled AI Security Engineer to help design, implement, and maintain secure cloud-native AI platforms and applications. This role focuses on securing AI/ML workloads, cloud infrastructure, APIs, data pipelines, and modern software supply chains across enterprise environments. The ideal candidate will have a strong background in cloud security engineering, combined with practical exposure to AI/ML technologies, AI security risks, and MLSecOps practices. You will work closely with cloud, engineering, DevOps, and AI/ML teams to implement scalable security controls and support secure adoption of AI-enabled solutions. This role also includes supporting software and AI supply chain security initiatives through management and validation of SBOM, CBOM, AIBOM, and KBOM artifacts. Key Responsibilities : 1. Cloud Security Engineering : - Design, implement, and maintain security controls for cloud-native environments and AI/ML workloads. - Secure cloud infrastructure, services, APIs, containers, and workloads across public cloud platforms. - Experience in managing CSPM tools such as Prisma, wiz, orca etc. Implement and manage : 1. IAM and least-privilege access controls 2. Network segmentation and secure connectivity 3. Encryption and key management 4. Secrets management and workload isolation 5. Logging, monitoring, and alerting controls - Conduct cloud security assessments, configuration reviews, and risk analysis. - Support security hardening for cloud-hosted AI services and model-serving infrastructure. 2. AI/ML Security : Support secure deployment and operation of AI/ML systems, including : 1. LLM-based applications 2. RAG systems 3. Model APIs and inference services 4. Agentic AI workflows Identify and assess AI-specific security risks such as : 1. Prompt injection and jailbreak attacks 2. Model abuse and unauthorized access 3. Data poisoning and sensitive data leakage 4. Model inversion and extraction attacks Implement AI security controls including : 1. Prompt filtering and validation 2. Output sanitization 3. Access restrictions and guardrails 4. Data protection and context isolation - Participate in AI threat modeling and security design reviews. 3. MLSecOps / DevSecOps : - Integrate security controls into AI/ML and cloud CI/CD pipelines. Support secure practices for : 1. Model training and deployment 2. Container security 3. Infrastructure as Code (IaC) 4. Dependency and artifact validation Implement automated security checks for : 1. Models and datasets 2. APIs and infrastructure 3. Containers and cloud workloads - Assist with secure model versioning, rollback, and deployment validation. 4. Software & AI Supply Chain Security : - Support secure software and AI supply chain initiatives. Generate, validate, and manage : 1. SBOM (Software Bill of Materials) 2. CBOM (Cryptography Bill of Materials) 3. AIBOM (AI Bill of Materials) 4. KBOM (Knowledge Bill of Materials) - Integrate BOM generation and validation into CI/CD and deployment workflows. - Track dependencies, model provenance, datasets, third-party AI integrations, and cryptographic components. - Support vulnerability management and compliance activities related to software and AI supply chains. Required Qualifications : - Bachelors degree in Computer Science, Cybersecurity, Information Security, or related field (or equivalent practical experience). 47 years of experience in : 1. Cloud security engineering 2. Security operations or security engineering 3. Application or infrastructure security - Hands-on experience with cloud-native security controls, architectures and CSPM tools. Understanding of : 1. IAM, encryption, network security, and secrets management 2. Secure SDLC and vulnerability management 3. Containers, APIs, and CI/CD security - Familiarity with AI/ML concepts and AI security risks. Experience with scripting/programming languages such as : 1. Python (preferred) 2. Bash, Go, or JavaScript/TypeScript Preferred Qualifications: Experience with : 1. AI/ML platforms and orchestration frameworks 2. RAG systems, vector databases, and model-serving platforms 3. Infrastructure as Code (Terraform, CloudFormation, etc.) 4. Security automation and cloud compliance tooling Familiarity with : 1. OWASP Top 10 for LLMs 2. NIST AI RMF 3. MITRE ATLAS 4. MLSecOps and MLOps concepts Experience working with : 1. BOM standards and tooling (CycloneDX, SPDX, etc.) 2. Container and artifact security solutions 3. Secure software supply chain practices - Relevant cloud or security certifications are a plus. Core Competencies : - Strong analytical and troubleshooting skills - Ability to identify and mitigate cloud and AI security risks - Effective communication and collaboration across technical teams - Strong ownership mindset and attention to detail - Ability to work in fast-paced, engineering-driven Job Titl
More at AU Small Finance Bank