17 Sep
|
Syneos Health
|
Pune
17 Sep
Syneos Health
Pune
- Lead implementation and operationalization of enterprise AI security tools and controls across Microsoft Copilot, Azure OpenAI, Foundry, Gemini Enterprise, Claude, AWS Bedrock, and other sanctioned AI platforms.
- Design, deploy, and maintain AI security guardrails including prompt injection protection, jailbreak detection, content filtering, sensitive-data protection, and runtime safety controls.
- Develop and maintain standardized AI security baselines, system prompts, security patterns, and reusable guardrail configurations for enterprise use cases.
- Operationalize AI security technologies including Microsoft Defender for Cloud AI Services, Model Armor, Zscaler AI Guard, CASB controls, API gateway protections, and AI telemetry integrations.
- Build and mature AI threat detection and response capabilities by integrating AI security telemetry into Sentinel and Cyber Threat Defense workflows.
- Develop AI-specific security monitoring use cases, detection logic, alerting strategies, investigation runbooks, and containment procedures.
- Establish and execute a repeatable AI red teaming program focused on prompt injection, jailbreak attacks, sensitive data leakage, unsafe outputs, agent misuse, model abuse, and guardrail bypass testing.
- Design red team methodologies, testing frameworks, playbooks, rules of engagement, and evidence collection procedures for AI systems and agents.
- Execute adversarial testing against AI models, agents, copilots, retrieval-augmented generation (RAG) solutions, and AI-enabled applications prior to production deployment.
- Assess AI platforms and applications against OWASP LLM Top 10, CSA AI Controls, NIST AI RMF, and internal security standards.
- Analyze AI-related findings, identify root causes, prioritize risk,
and provide actionable remediation guidance to engineering and product teams.
- Partner with AI developers and architects to implement secure-by-design AI patterns including pre-processing and post-processing controls, safety checkpoints, MCP governance, and tool-access restrictions.
- Conduct security architecture reviews of AI solutions, agents, AI-assisted workflows, and external AI integrations.
- Support enterprise AI governance initiatives including AI inventory, AI asset discovery, AI risk assessment, and non-human identity governance initiatives.
- Develop metrics, dashboards, and executive reporting that demonstrate AI security posture, AI risk reduction, guardrail effectiveness, and red team outcomes.
- Coordinate with Cyber Threat Defense, Security Operations, Cloud Operations, Enterprise Architecture, AI Governance, and application teams to operationalize AI security controls and response processes.
- Evaluate emerging AI security technologies, AI gateways, AI firewalls, AI posture management solutions, and AI security tooling to support the evolving AI security roadmap.
- Create and maintain SOPs, runbooks, and process documentation.
- Ensure consistency across teams and shifts in how security tasks are performed.
- Partner with SOC analysts, cyber threat intelligence & incident response, vulnerability managers, network engineers and others to understand pain points and requirements.
- Work within Tech Solutions, DevOps,
and compliance teams to align security processes with broader organizational goals.
- Mentor and coach team members on best practices and process adherence.
- Lead initiatives for process maturity (e.g., adopting industry standard frameworks, improving alert triage).
- Stay current with industry best practices and emerging technologies.
- Ensure processes meet regulatory and policy requirements.
- Support internal and external audits by providing process evidence and documentation.
Qualification Requirements
- 8+ years in cybersecurity, security engineering, cloud security, application security, or security operations.
- 3+ years designing or securing AI/ML, Generative AI, LLM, agent-based, or cloud-native applications.
- Experience with Microsoft Security, Azure AI/Foundry, Defender for Cloud, Sentinel, Zscaler, CASB, GCP, AWS, and contemporary security monitoring platforms.
- Deep understanding of prompt injection, jailbreak attacks, LLM security risks, agentic AI security, RAG security, data leakage controls, and AI adversarial testing.
- Strong written and verbal communication skills with the ability to operate at both technical and executive levels.
- Self-directed and able to manage individual projects or work as part of a larger team.
- Highly technical, detail-oriented, and organized individual with advanced skills in incident response and threat hunting.
Preferred: Proficiency in a wide range of security tools such as vulnerability scanning, endpoint protection/EDR, SIEM, SOAR, IPS/IDS, WAF, SASE, perimeter firewall, reverse proxy, defense in depth practices, malware analysis tools, etc.
Programming experience in bash, python, or PowerShell.
Prior experience in the healthcare or pharmaceutical industry.
📌 Principal Security Operation Analyst (Pune)
🏢 Syneos Health
📍 Pune