Staff Engineer (AI Security and DevSecOps )
- Full-time
- Service Region: South Asia
Company Description
👋🏼We're Nagarro.
We are a Digital Product Engineering company that is scaling in a big way! We build products, services, and experiences that inspire, excite, and delight. We work at a scale — across all devices and digital mediums, and our people exist everywhere in the world (18500+ experts across 40 countries, to be exact). Our work culture is dynamic and non-hierarchical. We are looking for great new colleagues. That is where you come in!
Job Description
Requirements
- Experience : 5.5+ yrs
- Strong experience in DevOps, DevSecOps, Cloud Infrastructure, or AI/ML Security engineering.
- Strong experience in Machine Learning environments, securing ML pipelines, or LLM-powered applications.
- Hands-on experience building and securing unstructured data pipelines for AI/ML workloads.
- Proficiency in Python and Bash scripting for automation, infrastructure management, and security tooling.
- Experience with Infrastructure as Code (IaC) tools such as Terraform or Pulumi.
- Strong understanding of cloud platforms including AWS, Azure, or GCP and cloud security best practices.
- Experience implementing security controls across CI/CD pipelines, including SAST, DAST, dependency scanning, and secrets management.
- Solid understanding of OWASP security principles, Zero Trust architecture, and secrets management solutions such as HashiCorp Vault or AWS Secrets Manager.
- Experience implementing AI security controls, including prompt injection mitigation, input/output filtering, abuse detection, and secure LLM integrations.
- Knowledge of AI/ML security risks such as model inversion, data poisoning, prompt injection, and adversarial attacks.
- Familiarity with data privacy regulations such as GDPR, CCPA, HIPAA, and compliance frameworks including SOC 2, ISO 27001, or NIST AI RMF.
- Experience implementing data classification, lineage tracking, PII detection, anonymization, and retention policies.
- Knowledge of Kubernetes, container security, and cloud-native infrastructure hardening.
- Experience building observability, monitoring, and alerting solutions for AI systems, infrastructure, and security events.
- Familiarity with Azure DevOps pipeline strategy and CI/CD automation is an advantage.
- Exposure to AI/ML frameworks such as PyTorch, LangChain, vector databases, or similar technologies is preferred.
- Professional certifications such as AWS Security Specialty, CISSP, CISM, or Google Professional Cloud Security Engineer are desirable.
- Excellent analytical, troubleshooting, communication, and stakeholder management skills.
Responsibilities
- Design, implement, and maintain security controls for AI/ML platforms and LLM-powered applications.
- Perform threat modeling for AI systems, identifying and mitigating risks including prompt injection, model inversion, data poisoning, and adversarial attacks.
- Implement guardrails, input/output validation, abuse detection, and security controls for Generative AI applications.
- Conduct security assessments and reviews of third-party AI services, APIs, and model integrations.
- Monitor AI applications and infrastructure for security incidents, anomalies, and emerging threats, and coordinate timely incident response.
- Design and secure data pipelines for structured and unstructured AI datasets while ensuring regulatory compliance.
- Implement data classification, lineage tracking, retention policies, and governance frameworks for AI training and inference data.
- Develop and maintain PII detection, anonymization, and data protection mechanisms across AI datasets.
- Embed security throughout CI/CD pipelines using automated scanning, dependency management, secrets management, and infrastructure validation.
- Provision and manage secure cloud infrastructure using Infrastructure as Code and cloud-native security best practices.
- Harden containerized environments and Kubernetes platforms to ensure secure AI application deployment.
- Build monitoring, observability, and alerting solutions for model performance, drift detection, infrastructure health, and security events.
- Develop and maintain incident response playbooks for AI platforms, cloud infrastructure, and security-related events.
- Support security audits, compliance assessments, and documentation for regulatory and organizational standards.
- Collaborate with AI engineers, DevOps teams, data engineers, and security stakeholders to deliver secure, scalable, and compliant AI solutions.
- Continuously evaluate emerging AI security threats, industry standards, and best practices to strengthen the organization's AI security posture.
Qualifications
Bachelor’s or master’s degree in computer science, Information Technology, or a related field.
By clicking the link above or any third-party link within this posting, you are leaving this site and going to a third-party website where the third-party website's terms and privacy policy apply