Senior AI & Application Security Architect
Job Title: Senior AI & Application Security Architect
Location: India
Reports To: Security & Infra Director
Role Overview
We are seeking a highly experienced Senior AI & Application Security Architect to lead security architecture for AI-driven and business-critical applications across the enterprise. This role is 100% focused on AI and application security, including internally built agentic applications, AI-assisted and vibe-coded applications, integrations with existing business applications and data, on-prem and cloud application environments, and API security. The ideal candidate will bring deep technical security expertise, strong application and AI security knowledge, and a solid understanding of infrastructure, identity, cloud, networking, and enterprise architecture to ensure secure-by-design solutions that are practical, scalable, and aligned with business needs.
Key Responsibilities
AI & Application Security Architecture
o Lead security architecture for AI-enabled applications, internal agentic applications, LLM-based solutions, RAG pipelines, AI integrations, and business-critical applications.
o Define secure-by-design architecture patterns, guardrails, and technical standards for applications built internally, by vendors, or using AI-assisted and vibe coding approaches.
o Review and approve application designs, AI workflows, data flows, integrations, APIs, identity models, and access patterns before production deployment.
o Ensure applications are secure across on-prem, cloud, SaaS, hybrid, containerized, and API-driven environments.
o Translate security requirements into practical engineering controls, reference architectures, reusable patterns, and automated guardrails.
AI, Agentic Apps & Data Security
o Lead AI security reviews for internal and third-party AI solutions, including agentic applications, copilots, chatbots, automation agents, AI-assisted workflows, and embedded AI features.
o Design security controls for prompt injection, data leakage, excessive agency, insecure tool use, model/API abuse, unsafe plugins, malicious content handling, and sensitive data exposure.
o Define governance, guardrails, approval criteria, and secure implementation patterns for AI adoption across enterprise and R&D environments.
o Assess security risks across AI supply chains, including third-party models, AI APIs, training data, embeddings, vector databases, orchestration layers, and connected tools.
o Establish monitoring, logging, auditability, and incident response requirements for AI and application security events.
o Architect API security controls, including authentication, authorization, OAuth/OIDC, service-to-service access, rate limiting, API gateway protections, API discovery, inventory, and abuse prevention.
o Define threat modeling practices for applications, APIs, AI workflows, agentic behavior, data access, and integrations with enterprise systems.
Application Security, DevSecOps & Secure SDLC
o Embed security into the full application lifecycle, from ideation and architecture through development, testing, deployment, and operations.
o Partner with R&D, DevOps, IT, cloud, data, and business application teams to identify risks and implement scalable security controls.
o Define and improve secure SDLC processes, including SAST, DAST, SCA, secrets scanning, IaC scanning, container security, dependency governance, and remediation workflows.
o Guide vulnerability management for applications and APIs, including risk-based prioritization, remediation guidance, exception handling, and recurring risk reduction.
Technical Leadership & Advisory
o Act as the security authority for AI and application architecture decisions, providing clear guidance to engineering, IT, data, and leadership teams.
o Evaluate emerging AI, agentic, application, API, and cloud technologies and define secure adoption requirements.
o Lead architecture reviews, security design discussions, risk acceptance processes, and technical governance for AI and application initiatives.
Qualifications
- Experience:
o 10 years in cybersecurity, with deep experience in application security, AI security, cloud security, secure architecture, and technical security leadership.
o Proven experience securing enterprise applications, business systems, APIs, integrations, SaaS platforms, cloud-native applications, and on-prem application environments.
o Strong hands-on understanding of infrastructure security, including identity, networking, endpoint security, cloud platforms, containers, monitoring, SIEM/XDR, and security operations.
o Deep expertise in application security, API security, threat modeling, secure SDLC, DevSecOps, vulnerability management, authentication, authorization, encryption, secrets management, and secure coding practices.
o Extensive experience working with R&D, DevOps, product engineering, IT, cloud, data, and business application teams.
o Hands-on experience with AI security, including LLM applications, agentic applications, RAG architectures, AI APIs, prompt injection risks, AI data protection, model/API risk, and AI governance.
o Experience reviewing AI-assisted and vibe-coded applications, including validation of generated code, dependencies, permissions, data handling, and production readiness.
o Hands-on experience with Linux and Windows based platforms, cloud services, containers, CI/CD pipelines, and application hosting environments.
o Hands-on experience with AppSec and security tools such as SAST, DAST, SCA, secrets scanning, API security testing, WAF/API gateways, SIEM, XDR, CASB, DLP, and patch management tools.
o Experience with monitoring, automation, orchestration, security-as-code, and automated guardrails for development and deployment environments.
o Certifications: CISSP, CSSLP, GWAPT, AWS/Azure Security, cloud architect certifications, or equivalent hands-on experience.
- Skills:
Strong technical depth, analytical thinking, architecture judgment, and ability to make risk-based decisions in complex application and AI environments.
Excellent spoken and written English.
Ability to influence technical teams without direct authority and translate AI and application security requirements into practical engineering controls.