02 Oct
|
Invoice Cloud
|
Hyderabad
02 Oct
Invoice Cloud
Hyderabad
Job Summary
Excellence in technology, information security, and regulatory compliance are foundational to our success. InvoiceCloud has chosen an AI First approach with the technology augmenting human activities across the globe. The AI Security Engineer designs and implements security controls for AI/ML systems and generative AI capabilities, enabling safe innovation across InvoiceCloud products and internal operations.
This role partners with Engineering, Data Science, Product, DevSecOps, and Security Operations to threat model AI use cases, build secure AI/ML delivery pipelines (MLSecOps), perform adversarial testing and AI red teaming, and ensure AI solutions meet security, privacy, and compliance expectations.
Mission: The AI Security Engineer plays a key role in the InvoiceCloud Cybersecurity Program. This role requires strong attention to detail, persistence, expertise in application security and AI/ML risk, planning skills, self-motivation, organization, communication, and problem-solving abilities. The primary objective of this position is to consistently identify, prioritize, and reduce AI-specific security risks across the model lifecycle-data, training, evaluation, deployment, and operations-while maintaining business velocity and product quality.
Responsibilities
- AI Security Architecture Secure Design
- Design and implement security controls for AI/ML and generative AI systems across the full lifecycle (data training evaluation deployment monitoring).
- Establish secure reference architectures for common patterns (e.g., retrieval-augmented generation (RAG), model gateways, tool/agent execution) with least privilege, data minimization, and isolation.
- Threat Modeling Risk Assessment
- Perform AI/ML threat modeling for new and existing systems, including prompt injection, data poisoning, model extraction, data leakage, and abuse/misuse scenarios.
- Map risks to industry frameworks (e.g., OWASP Top 10 for LLM Applications, MITRE ATLAS, NIST AI RMF) and drive mitigations with engineering teams.
- Secure MLOps / MLSecOps
- Partner with DevSecOps/MLOps to integrate security into AI delivery pipelines (secure model registry, artifact signing, provenance, access control, dependency scanning, secrets management, CI/CD guardrails).
- Ensure training and inference environments are hardened (cloud IAM, network segmentation, key management, container security).
- AI Security Testing Red Teaming
- Build and execute AI security test plans and adversarial evaluations (prompt injection, jailbreaks, data exfiltration, content policy bypass, model evasion).
- Develop automated test harnesses and regression suites to validate controls over time.
- Monitoring, Detection Incident Response
- Define and implement telemetry for AI systems (prompt/output logging, tool calls, policy decisions) with appropriate privacy controls.
- Integrate AI security signals into SIEM/SOC workflows; create detection logic and response playbooks for AI-specific incidents.
- Governance, Privacy Third-Party Risk
- Support AI governance by defining security requirements for AI use cases, third-party models/vendors, and data usage.
- Partner with Legal/Privacy/Compliance to ensure AI implementations align with internal policy and applicable regulations.
- Cross-Functional Collaboration Enablement
- Provide security guidance, training, and documentation for engineers and data scientists; raise overall AI security maturity.
- Communicate risks and progress updates to Security leadership, ELT stakeholders, and the CISO as needed.
Qualifications
This role has privileged access to highly sensitive information, intellectual property, legal matters, and complex business scenarios. The successful candidate has:
- Bachelor's degree in Computer Science, Cybersecurity, Engineering, Data Science,
or related field (or equivalent practical experience).
- 5+ years of experience in security engineering, application/product security, cloud security, or DevSecOps.
- 2+ years of experience building or securing AI/ML systems (including LLM-based applications) in production environments.
- Strong understanding of AI/ML threats and defenses (e.g., prompt injection, data poisoning, model extraction, model inversion, adversarial inputs, data leakage, abuse/misuse).
- Experience integrating security into CI/CD and MLOps pipelines; comfortable with containerization and cloud platforms (AWS and Azure).
- Preferred: Familiarity with OWASP GenAI guidance/Top 10 for LLM Applications, MITRE ATLAS, and/or NIST AI RMF.
- Preferred: Certifications such as CISSP, CSSLP, CCSP, Azure Security certifications, or relevant GIAC certifications.
Personal Skills
- Optimistic, persistently driving for the positive outcome
- Team player; collaborative and can work independently
- Excellent coordination and orchestration abilities
- Strong work ethic, interpersonal skills, time management, planning and execution skills
- Resourceful, collaborative, out of the box thinking
- Demonstrates a personal code of ethics, integrity, and trust
- Able to successfully navigate within varying degrees of ambiguity in a fast-paced environment
- Efficient communications skills (written/verbal) and interpersonal savvy
- Possess a good sense of self and a robust, approachable personal presence.
- Possess the determination to get results without harm, provide transparent feedback, and prioritize a positive outcome
Outcomes
First 30 days
Immersion and Formulation
- Inventory current and planned AI/ML and generative AI use cases across products and internal operations; document architecture, data flows, and sensitive-data touchpoints.
Disclaimer: This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.
📌 Senior AI Security Engineer (Hyderabad)
🏢 Invoice Cloud
📍 Hyderabad