Functional Manager - Cyber Security

Date: May 4, 2025

Location: NAVI MUMBAI, IN

Company: icicisecur

AI Cyber Security Architect

Key Responsibilities

• Lead client engagements focused on securing AI, GenAI, and ML workloads across AWS, Microsoft Azure, and Google Cloud.

• Design and implement AI security strategies, architectures, governance models, and control frameworks aligned with business and regulatory requirements.

• Conduct AI security assessments across cloud-hosted AI/ML and GenAI environments.

• Evaluate controls against NIST CSF, CSA CCM, ISO 27001, NIST AI RMF, ISO 42001, and related frameworks.

• Lead threat modelling and architecture reviews for AI and GenAI solutions.

• Assess risks including prompt injection, jailbreaks, insecure output handling, excessive agent permissions, sensitive data exposure, model misuse, and insecure tool integrations.

• Define secure reference architectures for model endpoints, APIs, RAG pipelines, vector stores, plugins, agent frameworks, orchestration layers, and external integrations.

• Guide secure deployment of Amazon Bedrock, SageMaker, Azure AI Foundry, Azure OpenAI, Azure Machine Learning, and Google Vertex AI.

• Implement controls around private connectivity, encryption, key management, secrets management, access restriction, tenant isolation, content safety, logging, and monitoring.

• Integrate security into MLOps, and MLSecOps pipelines.

• Embed policy validation, secrets handling, model governance, and compliance checks into CI/CD and ML workflows.

• Define controls across the full AI lifecycle, including data ingestion, training, validation, deployment, runtime monitoring, incident response, drift review, and retraining.

• Lead AI governance activities covering model inventory, risk classification, approval workflows, traceability, control mapping, audit readiness, and policy alignment.

• Drive AI security posture management using CNAPP, CSPM, CWPP, DSPM, SIEM, and cloud-native security tools.

• Oversee monitoring and incident response for suspicious prompt activity, agent misuse, unauthorized model access, data leakage, and control failures.

• Lead AI security testing including misuse-case testing, prompt attack validation, model guardrail reviews, red-team support, and remediation planning.

• Manage stakeholders across Security, Cloud, DevOps, Architecture, Data, ML Engineering, Privacy, Legal, and Risk teams.

• Contribute to proposals, solutioning, thought leadership, reusable assets, and cloud AI security practice development.