AI Security Engineer
Air India Limited
Role tags
Tech stack mentioned
Role overview
Formatting this description...
Job Title: AI Security Engineer JOB PURPOSE Air India is rapidly expanding its use of Generative AI and autonomous AI agents across customer-facing, operational, and enterprise functions. The AI Security Engineer will be a specialist responsible for identifying, testing, and mitigating security risks specific to AI and LLM-based systems deployed on Azure AI Foundry, AWS Bedrock, GCP Vertex AI, and Microsoft Copilot Studio. The role sits at the intersection of AI engineering, offensive security, and risk governance — working closely with the AI Security Posture Management (AISPM) platform and the wider D&T EA and security team. KEY RESPONSIBILITIES LLM & AI Risk Assessment Conduct formal threat modelling of AI systems using the OWASP AI Exchange matrix — covering input threats, development-time threats, runtime threats, and agentic threats. Assess LLM-specific risks: model inversion, membership inference, training data extraction, adversarial evasion, AI resource exhaustion (cost explosion attacks), and disclosure in output. Evaluate retrieval-augmented generation (RAG) pipelines for augmentation data integrity, context injection, and knowledge base poisoning risks. Review and classify AI-BOM (AI Bill of Materials) — model provenance, dependency chain, and supply chain risk for open-source models ingested into Bedrock or Azure AI Foundry. Identify and document "lethal trifecta" exposure across all AI agents: attacker-controlled input, access to sensitive data, and external send capability. Cloud AI Platform Security Assess security configurations of Azure AI Foundry, Azure API Management (APIM), AWS Bedrock, AWS API Gateway, and GCP Apigee as AI gateway layers. Review model deployment configurations, IAM policies, network controls, and logging coverage across all three cloud AI platforms. Validate AISPM prompt firewall rules and monitor alert patterns across all integrated AI gateways Support integration of cloud AI telemetry (CloudTrail, Azure Monitor, Chronicle) into AISPM for unified detection and response. Assess Microsoft Copilot Studio agents, AWS AgentCore agents, and GCP Agent Engine deployments for misconfigurations and privilege escalation paths. Security Architecture & Governance Conduct security architecture reviews of new AI systems and integrations before go-live, using the Air India OWASP-based AI review framework. Assess third-party AI vendor integrations for supply chain risk, DPA compliance, tenant isolation, and data exposure. Support Air India's ISO 42001:2023 AI risk assessment — provide evidence from red team findings and threat models. Work with application teams to implement OWASP AI Security controls Contribute to the Air India AI Security Matrix — maintain and update threat assessments for all AI systems in production. AISPM Operations & Detection Triage AISPM alerts across all gateways — categorise by attack type, assess false positive rate, and refine detection thresholds. Develop and maintain AI-specific detection rules, guardrails, and block mode policies within the AISPM platform. Monitor AI agent behaviour across cloud environments using AISPM dashboards and generate weekly security reports for application teams. Automate red team test cases and integrate them into CI/CD pipelines for continuous AI security validation. REQUIRED SKILLS & QUALIFICATIONS Technical Skills (Must Have) Preferred experience with AccuKnox AISPM — prompt firewall configuration, agent monitoring, AI Detection & Response (AI-DR), and policy management across cloud gateways. Azure AI Foundry / AWS Bedrock: Working knowledge of at least one cloud AI platform — model deployment, API gateway configuration, IAM, logging, and runtime security controls. AI Risk Frameworks: Familiarity with OWASP AI Exchange, MITRE ATLAS, or equivalent AI threat taxonomy. Ability to map findings to named controls and STRIDE threats. Cloud Security: Understanding of cloud IAM, API gateway security, network policies, and logging on at least one of: Azure, AWS, or GCP. Offensive Security Basics: Solid grounding in web application security (OWASP Top 10), API security, and at least one of: penetration testing, VAPT, bug bounty, or CTF experience. Good to Have Experience with GCP Vertex AI, GCP Agent Engine, or Microsoft Copilot Studio agent security. Knowledge of ML model security: serialisation exploits, model poisoning, and supply chain attacks on open-source models. Understanding of ISO 42001:2023 AI management system controls or ISO 27001 information security. Exposure to agentic AI frameworks: LangChain, LangGraph, AutoGen, CrewAI, AWS Strands, or equivalent. Experience with DPDP Act 2023 or GDPR data protection obligations for AI systems. Qualifications Bachelor's or Master's degree in Computer Science, Information Security, or a related technical field. 3 years of experience in information security, with at least 1 year focused on AI/LLM security, adversarial ML, or cloud AI platform security. Security certifications preferred: CEH, OSCP, GPEN, GWAPT, or equivalent offensive security credential. AI/cloud certifications a plus: AWS Certified Security Specialty, Microsoft Azure Security Engineer (AZ-500), Google Cloud Security Engineer, or an LLM/AI-specific certification. TOOLS & TECHNOLOGIES The successful candidate will work with or be expected to learn: AISPM Platform AccuKnox AISPM — prompt firewall, agent monitoring, AI Detection & Response (AI-DR) Cloud AI Platforms Azure AI Foundry, AWS Bedrock, GCP Vertex AI, Microsoft Copilot Studio AI Gateways Azure APIM, AWS API Gateway, GCP Apigee Web / API Security Burp Suite, nuclei, sqlmap, ffuf, zaproxy, nikto ML Model Security fickling, modelscan, YARA, Syft (AI-BOM generation) Frameworks OWASP AI Exchange, MITRE ATLAS, NIST AI RMF, ISO 42001 Show more