AI Security Engineer
Air India · Gurugram, Haryana, India
Air India · Gurugram, Haryana, India
**Job Title: AI Security Engineer Job Purpose** Air India is rapidly expanding its use of Generative AI and autonomous AI agents across customer-facing, operational, and enterprise functions. The AI Security Engineer will be a specialist responsible for identifying, testing, and mitigating security risks specific to AI and LLM-based systems deployed on Azure AI Foundry, AWS Bedrock, GCP Vertex AI, and Microsoft Copilot Studio. The role sits at the intersection of AI engineering, offensive security, and risk governance — working closely with the AI Security Posture Management (AISPM) platform and the wider D&T EA and security team. **KEY RESPONSIBILITIES** **LLM & AI Risk Assessment** - Conduct formal threat modelling of AI systems using the OWASP AI Exchange matrix — covering input threats, development-time threats, runtime threats, and agentic threats. - Assess LLM-specific risks: model inversion, membership inference, training data extraction, adversarial evasion, AI resource exhaustion (cost explosion attacks), and disclosure in output. - Evaluate retrieval-augmented generation (RAG) pipelines for augmentation data integrity, context injection, and knowledge base poisoning risks. - Review and classify AI-BOM (AI Bill of Materials) — model provenance, dependency chain, and supply chain risk for open-source models ingested into Bedrock or Azure AI Foundry. - Identify and document "lethal trifecta" exposure across all AI agents: attacker-controlled input, access to sensitive data, and external send capability. **Cloud AI Platform Security** - Assess security configurations of Azure AI Foundry, Azure API Management (APIM), AWS Bedrock, AWS API Gateway, and GCP Apigee as AI gateway layers. - Review model deployment configurations, IAM policies, network controls, and logging coverage across all three cloud AI platforms. - Validate AISPM prompt firewall rules and monitor alert patterns across all integrated AI gateways - Support integration of cloud AI telemetry (CloudTrail, Azure Monitor, Chronicle) into AISPM for unified detection and response. - Assess Microsoft Copilot Studio agents, AWS AgentCore agents, and GCP Agent Engine deployments for misconfigurations and privilege escalation paths. **Security Architecture & Governance** - Conduct security architecture reviews of new AI systems and integrations before go-live, using the Air India OWASP-based AI review framework. - Assess third-party AI vendor integrations for supply chain risk, DPA compliance, tenant isolation, and data exposure. - Support Air India's ISO 42001:2023 AI risk assessment — provide evidence from red team findings and threat models. - Work with application teams to implement OWASP AI Security controls - Contribute to the Air India AI Security Matrix — maintain and update threat assessments for all AI systems in production. **AISPM Operations & Detection** - Triage AISPM alerts across all gateways — categorise by attack type, assess false positive rate, and refine detection thresholds. - Develop and maintain AI-specific detection rules, guardrails, and block mode policies within the AISPM platform. - Monitor AI agent behaviour across cloud environments using AISPM dashboards and generate weekly security reports for application teams. - Automate red team test cases and integrate them into CI/CD pipelines for continuous AI security validation. **REQUIRED SKILLS & QUALIFICATIONS** **Technical Skills (Must Have)** - Preferred experience with AccuKnox AISPM — prompt firewall configuration, agent monitoring, AI Detection & Response (AI-DR), and policy management across cloud gateways. - **Azure AI Foundry / AWS Bedrock:**Working knowledge of at least one cloud AI platform — model deployment, API gateway configuration, IAM, logging, and runtime security controls. - **AI Risk Frameworks:**Familiarity with OWASP AI Exchange, MITRE ATLAS, or equivalent AI threat taxonomy. Ability to map findings to named controls and STRIDE threats. - **Cloud Security:**Understanding of cloud IAM, API gateway security, network policies, and logging on at least one of: Azure, AWS, or GCP. - **Offensive Security Basics:**Solid grounding in web application security (OWASP Top 10), API security, and at least one of: penetration testing, VAPT, bug bounty, or CTF experience. **Good to Have** - Experience with GCP Vertex AI, GCP Agent Engine, or Microsoft Copilot Studio agent security. - Knowledge of ML model security: serialisation exploits, model poisoning, and supply chain attacks on open-source models. - Understanding of ISO 42001:2023 AI management system controls or ISO 27001 information security. - Exposure to agentic AI frameworks: LangChain, LangGraph, AutoGen, CrewAI, AWS Strands, or equivalent. - Experience with DPDP Act 2023 or GDPR data protection obligations for AI systems. **Qualifications** - Bachelor's or Master's degree in Computer Science, Information Security, or a related technical field. - 3 years of experience in information security, with at least 1 year focused on AI/LLM security, adversarial ML, or cloud AI platform security. - Security certifications preferred: CEH, OSCP, GPEN, GWAPT, or equivalent offensive security credential. - AI/cloud certifications a plus: AWS Certified Security Specialty, Microsoft Azure Security Engineer (AZ-500), Google Cloud Security Engineer, or an LLM/AI-specific certification. **TOOLS & TECHNOLOGIES** The successful candidate will work with or be expected to learn: **AISPM Platform** AccuKnox AISPM — prompt firewall, agent monitoring, AI Detection & Response (AI-DR) **Cloud AI Platforms** Azure AI Foundry, AWS Bedrock, GCP Vertex AI, Microsoft Copilot Studio **AI Gateways** Azure APIM, AWS API Gateway, GCP Apigee **Web / API Security** Burp Suite, nuclei, sqlmap, ffuf, zaproxy, nikto **ML Model Security** fickling, modelscan, YARA, Syft (AI-BOM generation) **Frameworks** OWASP AI Exchange, MITRE ATLAS, NIST AI RMF, ISO 42001