Website:
Job details:
Job Title: AI Security Engineer
JOB PURPOSE
Air India is rapidly expanding its use of Generative AI and autonomous AI agents across customer-facing, operational, and enterprise functions. The AI Security Engineer will be a specialist responsible for identifying, testing, and mitigating security risks specific to AI and LLM-based systems deployed on Azure AI Foundry, AWS Bedrock, GCP Vertex AI, and Microsoft Copilot Studio. The role sits at the intersection of AI engineering, offensive security, and risk governance — working closely with the AI Security Posture Management (AISPM) platform and the wider D&T EA and security team.
KEY RESPONSIBILITIES
LLM & AI Risk Assessment
- Conduct formal threat modelling of AI systems using the OWASP AI Exchange matrix — covering input threats, development-time threats, runtime threats, and agentic threats.
- Assess LLM-specific risks: model inversion, membership inference, training data extraction, adversarial evasion, AI resource exhaustion (cost explosion attacks), and disclosure in output.
- Evaluate retrieval-augmented generation (RAG) pipelines for augmentation data integrity, context injection, and knowledge base poisoning risks.
- Review and classify AI-BOM (AI Bill of Materials) — model provenance, dependency chain, and supply chain risk for open-source models ingested into Bedrock or Azure AI Foundry.
- Identify and document "lethal trifecta" exposure across all AI agents: attacker-controlled input, access to sensitive data, and external send capability.
Cloud AI Platform Security
- Assess security configurations of Azure AI Foundry, Azure API Management (APIM), AWS Bedrock, AWS API Gateway, and GCP Apigee as AI gateway layers.
- Review model deployment configurations, IAM policies, network controls, and logging coverage across all three cloud AI platforms.
- Validate AISPM prompt firewall rules and monitor alert patterns across all integrated AI gateways
- Support integration of cloud AI telemetry (CloudTrail, Azure Monitor, Chronicle) into AISPM for unified detection and response.
- Assess Microsoft Copilot Studio agents, AWS AgentCore agents, and GCP Agent Engine deployments for misconfigurations and privilege escalation paths.
Security Architecture & Governance
- Conduct security architecture reviews of new AI systems and integrations before go-live, using the Air India OWASP-based AI review framework.
- Assess third-party AI vendor integrations for supply chain risk, DPA compliance, tenant isolation, and data exposure.
- Support Air India's ISO 42001:2023 AI risk assessment — provide evidence from red team findings and threat models.
- Work with application teams to implement OWASP AI Security controls
- Contribute to the Air India AI Security Matrix — maintain and update threat assessments for all AI systems in production.
AISPM Operations & Detection
- Triage AISPM alerts across all gateways — categorise by attack type, assess false positive rate, and refine detection thresholds.
- Develop and maintain AI-specific detection rules, guardrails, and block mode policies within the AISPM platform.
- Monitor AI agent behaviour across cloud environments using AISPM dashboards and generate weekly security reports for application teams.
- Automate red team test cases and integrate them into CI/CD pipelines for continuous AI security validation.
REQUIRED SKILLS & QUALIFICATIONS
Technical Skills (Must Have)
- Preferred experience with AccuKnox AISPM — prompt firewall configuration, agent monitoring, AI Detection & Response (AI-DR), and policy management across cloud gateways.
- Azure AI Foundry / AWS Bedrock: Working knowledge of at least one cloud AI platform — model deployment, API gateway configuration, IAM, logging, and runtime security controls.
- AI Risk Frameworks: Familiarity with OWASP AI Exchange, MITRE ATLAS, or equivalent AI threat taxonomy. Ability to map findings to named controls and STRIDE threats.
- Cloud Security: Understanding of cloud IAM, API gateway security, network policies, and logging on at least one of: Azure, AWS, or GCP.
- Offensive Security Basics: Solid grounding in web application security (OWASP Top 10), API security, and at least one of: penetration testing, VAPT, bug bounty, or CTF experience.
Good to Have
- Experience with GCP Vertex AI, GCP Agent Engine, or Microsoft Copilot Studio agent security.
- Knowledge of ML model security: serialisation exploits, model poisoning, and supply chain attacks on open-source models.
- Understanding of ISO 42001:2023 AI management system controls or ISO 27001 information security.
- Exposure to agentic AI frameworks: LangChain, LangGraph, AutoGen, CrewAI, AWS Strands, or equivalent.
- Experience with DPDP Act 2023 or GDPR data protection obligations for AI systems.
Qualifications
- Bachelor's or Master's degree in Computer Science, Information Security, or a related technical field.
- 3 years of experience in information security, with at least 1 year focused on AI/LLM security, adversarial ML, or cloud AI platform security.
- Security certifications preferred: CEH, OSCP, GPEN, GWAPT, or equivalent offensive security credential.
- AI/cloud certifications a plus: AWS Certified Security Specialty, Microsoft Azure Security Engineer (AZ-500), Google Cloud Security Engineer, or an LLM/AI-specific certification.
TOOLS & TECHNOLOGIES
The successful candidate will work with or be expected to learn:
AISPM Platform
AccuKnox AISPM — prompt firewall, agent monitoring, AI Detection & Response (AI-DR)
Cloud AI Platforms
Azure AI Foundry, AWS Bedrock, GCP Vertex AI, Microsoft Copilot Studio
AI Gateways
Azure APIM, AWS API Gateway, GCP Apigee
Web / API Security
Burp Suite, nuclei, sqlmap, ffuf, zaproxy, nikto
ML Model Security
fickling, modelscan, YARA, Syft (AI-BOM generation)
Frameworks
OWASP AI Exchange, MITRE ATLAS, NIST AI RMF, ISO 42001
Click on Apply to know more.