28 Sep
|
Biocon Biologics
|
Bengaluru
28 Sep
Biocon Biologics
Bengaluru
KEY RESPONSIBILITIES -
- AI Security Architecture & Governance - Develop and implement enterprise-wide AI security strategies, standards, policies, and guardrails. - Establish governance frameworks for AI and Generative AI solutions to ensure secure, responsible, and compliant adoption. - Conduct AI security assessments, threat modeling, and risk evaluations for AI applications, models, and services. - Define secure AI usage guidelines, acceptable use policies, and AI governance controls. - Evaluate AI platforms, tools, and services from security, privacy, compliance, and operational risk perspectives. - Design secure AI architectures, reference patterns, and security-by-design frameworks. - Review AI solution designs and provide security recommendations throughout the project lifecycle. - Evaluate and manage security risks associated with third-party AI vendors and cloud service providers.
- Security Architecture, Solution Design & Assurance - Act as the security architecture lead for AI, GenAI, and cloud transformation initiatives. - Review and approve solution architectures to ensure alignment with enterprise security standards, policies, and regulatory requirements. - Provide security design guidance throughout the solution lifecycle, from concept and architecture to implementation and operations. - Conduct architecture risk assessments and identify security gaps, design weaknesses, and mitigation strategies. - Develop and maintain reference architectures, security patterns, and reusable design frameworks for AI and cloud platforms. - Participate in Architecture Review Boards (ARB), technical design reviews, and governance forums. - Evaluate emerging AI technologies, cloud services, and platforms to determine security implications and architectural suitability.
- Ensure Security-by-Design and Privacy-by Design principles are embedded within AI and cloud solutions. - Define security requirements for integrations, APIs, data flows, and third-party services. - Collaborate with Enterprise Architecture, Cloud Engineering, Data Engineering, and Application Development teams to establish secure and scalable solutions. - Perform security assurance reviews prior to production deployment and provide risk-based recommendations. - Support threat modeling, attack surface analysis, and architecture assessments for strategic business initiatives.
- Cloud Security & Infrastructure Protection - Design and implement security controls across Azure, AWS, and GCP environments supporting AI workloads. - Secure cloud-native AI services, machine learning platforms, data lakes, and AI development environments. - Ensure cloud architectures comply with enterprise security standards and industry best practices. - Implement Zero Trust Architecture principles across AI and cloud workloads. - Integrate AI security requirements into cloud security frameworks, operating models, and engineering practices.
- Data Security & Privacy - Define and implement controls to protect sensitive, regulated, and business-critical data utilized by AI systems. - Ensure data classification, encryption, tokenization, masking, and privacy-preserving controls are implemented and maintained. - Monitor and prevent data leakage through AI applications, APIs, and cloud services. - Establish secure data-sharing, retention,
and lifecycle management practices. - Ensure compliance with applicable data privacy regulations and organizational data protection policies. Identity & Access Management - Design and implement Identity and Access Management (IAM) controls for AI platforms and cloud services. - Enforce least-privilege access, Privileged Access Management (PAM), and solid authentication controls. - Review access governance processes and ensure secure integration with enterprise identity platforms.
- Security Operations & Threat Management - Develop monitoring, detection, and response use cases for AI-specific threats, including prompt injection, model poisoning, adversarial attacks, data leakage, and unauthorized model access. - Collaborate with SOC, Incident Response, and Threat Intelligence teams to investigate and respond to AI-related security incidents. - Conduct vulnerability assessments, architecture reviews, and security testing activities for AI applications and supporting infrastructure. - Support continuous monitoring and ongoing improvement of AI security controls and capabilities.
- Compliance, Risk Management & Awareness - Ensure compliance with ISO 27001, NIST AI Risk Management Framework (AI RMF), GDPR, HIPAA, and other applicable regulations. - Support internal audits, external assessments, and regulatory reviews related to AI and cloud security. - Develop and maintain AI risk registers, mitigation plans, and governance reporting mechanisms. - Conduct AI security awareness and training programs for employees and technical teams. - Provide guidance to development, cloud, and business teams on secure AI development and deployment practices. - Promote responsible, ethical, and secure use of AI technologies across the organization
📌 Cloud AI Security Specialist (Bengaluru)
🏢 Biocon Biologics
📍 Bengaluru