Functional Manager - Cyber Security
Date: May 4, 2025
Location: NAVI MUMBAI, IN
Company: icicisecur
AI Cyber Security Architect
Key Responsibilities
• Lead client engagements focused on securing AI, GenAI, and ML workloads across AWS, Microsoft Azure, and Google Cloud.
• Design and implement AI security strategies, architectures, governance models, and control frameworks aligned with business and regulatory requirements.
• Conduct AI security assessments across cloud-hosted AI/ML and GenAI environments.
• Evaluate controls against NIST CSF, CSA CCM, ISO 27001, NIST AI RMF, ISO 42001, and related frameworks.
• Lead threat modelling and architecture reviews for AI and GenAI solutions.
• Assess risks including prompt injection, jailbreaks, insecure output handling, excessive agent permissions, sensitive data exposure, model misuse, and insecure tool integrations.
• Define secure reference architectures for model endpoints, APIs, RAG pipelines, vector stores, plugins, agent frameworks, orchestration layers, and external integrations.
• Guide secure deployment of Amazon Bedrock, SageMaker, Azure AI Foundry, Azure OpenAI, Azure Machine Learning, and Google Vertex AI.
• Implement controls around private connectivity, encryption, key management, secrets management, access restriction, tenant isolation, content safety, logging, and monitoring.
• Integrate security into MLOps, and MLSecOps pipelines.
• Embed policy validation, secrets handling, model governance, and compliance checks into CI/CD and ML workflows.
• Define controls across the full AI lifecycle, including data ingestion, training, validation, deployment, runtime monitoring, incident response, drift review, and retraining.
• Lead AI governance activities covering model inventory, risk classification, approval workflows, traceability, control mapping, audit readiness, and policy alignment.
• Drive AI security posture management using CNAPP, CSPM, CWPP, DSPM, SIEM, and cloud-native security tools.
• Oversee monitoring and incident response for suspicious prompt activity, agent misuse, unauthorized model access, data leakage, and control failures.
• Lead AI security testing including misuse-case testing, prompt attack validation, model guardrail reviews, red-team support, and remediation planning.
• Manage stakeholders across Security, Cloud, DevOps, Architecture, Data, ML Engineering, Privacy, Legal, and Risk teams.
• Contribute to proposals, solutioning, thought leadership, reusable assets, and cloud AI security practice development.