31 Jul
|
ShyftLabs
|
Noida
Key Responsibilities
- Framework evaluation: Own the evaluation of agentic AI frameworks and architectures, assessing them from a security, identity, and data-flow perspective.
- Approved path ownership: Define and maintain an approved, repeatable build-and-deploy path for agentic workflows — the reference architecture, guardrails, and checklist teams follow to take an agent from prototype to production safely.
- Secure architecture: Design and review secure architectures for cloud-native and agentic applications, with a focus on AWS and GCP.
- Threat modeling: Lead threat modeling for agentic systems specifically — covering tool and function-calling misuse, excessive agency, prompt injection, data exfiltration, and unsafe autonomous actions — and turn findings into concrete mitigations.
- Early engagement: Partner with product and engineering teams during design to review proposed agent architectures and unblock them against the approved path, rather than gatekeeping after the fact.
- Agent identity: Define identity, permissioning, and least-privilege models for agents and the tools and APIs they can invoke.
- Pipeline integration: Collaborate with DevOps and Platform teams to embed agentic-workflow guardrails into CI/CD pipelines and Infrastructure as Code.
- Risk and vulnerability management: Support risk assessment and vulnerability management for agentic and cloud-native systems, including triage, prioritization, and remediation guidance.
- Advisory: Act as the go-to security advisor for agentic AI questions from cross-functional teams based in the Americas.
- Horizon scanning: Stay current on the fast-evolving agentic AI landscape and continuously refine the approved path as the ecosystem matures.
Required Qualifications
- 5–8 years of experience in Application Security, Cloud Security, or Security Architecture roles.
- Hands-on familiarity with agentic AI frameworks and concepts (e.g., agent-orchestration frameworks such as LangGraph or similar). You do not need to be a model researcher, but you understand how agents plan, use tools, and act autonomously — and where that introduces risk.
- Robust hands-on experience securing applications and infrastructure on AWS and/or GCP; multi-cloud experience is a plus.
- Solid understanding of secure architecture design principles, threat modeling methodologies (e.g., STRIDE), and the OWASP Top 10 and OWASP ASVS.
- Proven ability to turn architecture evaluations into practical, repeatable standards other teams can self-serve against.
- Experience with Infrastructure as Code (Terraform, CloudFormation, or similar) and CI/CD security practices.
- Familiarity with container and orchestration security (Docker, Kubernetes).
- Excellent written and verbal communication skills in English; comfortable working with distributed, cross-cultural teams.
Preferred
Qualifications
- Direct hands-on experience building, evaluating, or securing agentic AI systems in production.
- Familiarity with the OWASP Top 10 for LLM Applications.
- Experience with SAST/DAST tooling, secure code review, or application penetration testing.
- Prior experience defining governance frameworks or centers of excellence for emerging technology.
Education & Certifications
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related field — or equivalent hands-on experience.
- Security certifications such as AWS Certified Security – Specialty, GCP Professional Cloud Security Engineer, CISSP, or OSCP are a plus.
📌 Senior Cloud & AI Security Engineer (Noida)
🏢 ShyftLabs
📍 Noida