21 Aug
|
J.S. Held
|
Delhi
Job Description
Role Summary
Based in the Delhi NCR region in a hybrid work model, the Sr. AI & Application Security Specialist will be a founding member of J.S. Held’s AI & Application Security function, helping shape the strategy, standards, and security practices that enable the protected adoption of AI across the organization. This hands-on role focuses on securing AI-enabled applications, agents, RAG architectures, MCP/tool integrations, models, APIs, and cloud services. Working closely with the Senior Application Security Specialist, the successful candidate will help build and scale a modern AI security program while driving day-to-day AI security initiatives, risk management, and technical guardrails to ensure compliance with legal, regulatory, and organizational requirements.
Role Details
- Role focus: approximately 70% AI Security and 30% Application Security
Core Responsibilities
- Develop and maintain the enterprise AI Security Program. Establish AI security policies, standards, control frameworks, and security processes.
- Lead AI Security execution across standards, architecture principles, risk framework, inventory expectations, and business-aligned security requirements.
- Review AI solutions before deployment, including AI-enabled applications, agents, RAG pipelines, APIs, MCP/tool integrations, model workflows, and third-party AI services.
- Perform AI threat modeling for prompt injection, model abuse, data leakage, RAG poisoning, agent misuse, unsafe tool calls, model extraction, and AI supply-chain risk.
- Define practical controls for AI identity, delegated authorization, agent lifecycle, tool permissions, least privilege, revocation, and auditability.
- Secure agentic workflows, including agent-to-agent interactions, MCP servers, autonomous workflows, tool integrations, and SharePoint-grounded AI use cases.
- Help define runtime guardrails, including prompt/content controls, tool restrictions, behavioral monitoring, runtime enforcement, and escalation paths.
- Lead or coordinate AI security testing and red teaming for priority AI systems, agents, models, workflows, and integrations.
- Define AI logging, monitoring, detection use cases, SecOps handoffs, and AI-specific incident response procedures.
- Review model provenance, model hosting platforms, open-source models, dependencies, plugins, and third-party AI services for security and governance risk.
- Support AI governance, risk, and compliance activities, including AI policies, risk classification, inventory requirements, evidence needs, and alignment with NIST AI RMF.
- Help identify shadow AI, unmanaged agents, risky connectors, overshared knowledge sources, and other exposure paths, then drive practical remediation with owners.
- Partner with the Senior Application Security Specialist on Application Security reviews, secure SDLC, architecture reviews, code reviews, API reviews, deployment reviews, and design approvals.
- Serve as the Senior Application Security Specialist’s backup when they are out of office or when AppSec demand requires additional coverage.
- Evaluate SaaS applications for secure configuration, identity access settings, risky integrations, excessive permissions, and secure-by-design implementation.
- Review APIs for authentication, authorization, input validation, data exposure, logging, rate limiting, and secure integration patterns.
- Support software composition analysis, dependency review, secrets scanning, code scanning, vulnerability triage, remediation tracking, and risk-based vulnerability management.
- Educate developers, architects, IT, cyber teams, and business stakeholders on secure AI design, Application Security expectations, and safe AI adoption.
📌 Founding Member, Senior AI & Application Security Specialist (Delhi NCR - Hybrid)
🏢 J.S. Held
📍 Delhi