Principal Security Operation Analyst
Syneos Health · Pune, Maharashtra, India
Free to search · AI fit score against your CV · tailor your résumé in one click
Syneos Health · Pune, Maharashtra, India
• Lead implementation and operationalization of enterprise AI security tools and controls across Microsoft Copilot, Azure OpenAI, Foundry, Gemini Enterprise, Claude, AWS Bedrock, and other sanctioned AI platforms. • Design, deploy, and maintain AI security guardrails including prompt injection protection, jailbreak detection, content filtering, sensitive-data protection, and runtime safety controls. • Develop and maintain standardized AI security baselines, system prompts, security patterns, and reusable guardrail configurations for enterprise use cases. • Operationalize AI security technologies including Microsoft Defender for Cloud AI Services, Model Armor, Zscaler AI Guard, CASB controls, API gateway protections, and AI telemetry integrations. • Build and mature AI threat detection and response capabilities by integrating AI security telemetry into Sentinel and Cyber Threat Defense workflows. • Develop AI-specific security monitoring use cases, detection logic, alerting strategies, investigation runbooks, and containment procedures. • Establish and execute a repeatable AI red teaming program focused on prompt injection, jailbreak attacks, sensitive data leakage, unsafe outputs, agent misuse, model abuse, and guardrail bypass testing. • Design red team methodologies, testing frameworks, playbooks, rules of engagement, and evidence collection procedures for AI systems and agents. • Execute adversarial testing against AI models, agents, copilots, retrieval-augmented generation (RAG) solutions, and AI-enabled applications prior to production deployment. • Assess AI platforms and applications against OWASP LLM Top 10, CSA AI Controls, NIST AI RMF, and internal security standards. • Analyze AI-related findings, identify root causes, prioritize risk, and provide actionable remediation guidance to engineering and product teams. • Partner with AI developers and architects to implement secure-by-design AI patterns including pre-processing and post-processing controls, safety checkpoints, MCP governance, and tool-access restrictions. • Conduct security architecture reviews of AI solutions, agents, AI-assisted workflows, and external AI integrations. • Support enterprise AI governance initiatives including AI inventory, AI asset discovery, AI risk assessment, and non-human identity governance initiatives. • Develop metrics, dashboards, and executive reporting that demonstrate AI security posture, AI risk reduction, guardrail effectiveness, and red team outcomes. • Coordinate with Cyber Threat Defense, Security Operations, Cloud Operations, Enterprise Architecture, AI Governance, and application teams to operationalize AI security controls and response processes. • Evaluate emerging AI security technologies, AI gateways, AI firewalls, AI posture management solutions, and AI security tooling to support the evolving AI security roadmap. • Create and maintain SOPs, runbooks, and process documentation. • Ensure consistency across teams and shifts in how security tasks are performed. • Partner with SOC analysts, cyber threat intelligence & incident response, vulnerability managers, network engineers and others to understand pain points and requirements. • Work within Tech Solutions, DevOps, and compliance teams to align security processes with broader organizational goals. • Mentor and coach team members on best practices and process adherence. • Lead initiatives for process maturity (e.g., adopting industry standard frameworks, improving alert triage). • Stay current with industry best practices and emerging technologies. • Ensure processes meet regulatory and policy requirements. • Support internal and external audits by providing process evidence and documentation. Qualification Requirements • 8+ years in cybersecurity, security engineering, cloud security, application security, or security operations. • 3+ years designing or securing AI/ML, Generative AI, LLM, agent-based, or cloud-native applications. • Experience with Microsoft Security, Azure AI/Foundry, Defender for Cloud, Sentinel, Zscaler, CASB, GCP, AWS, and modern security monitoring platforms. • Deep understanding of prompt injection, jailbreak attacks, LLM security risks, agentic AI security, RAG security, data leakage controls, and AI adversarial testing. • Strong written and verbal communication skills with the ability to operate at both technical and executive levels. • Self-directed and able to manage individual projects or work as part of a larger team. • Highly technical, detail-oriented, and organized individual with advanced skills in incident response and threat hunting. Preferred: Proficiency in a wide range of security tools such as vulnerability scanning, endpoint protection/EDR, SIEM, SOAR, IPS/IDS, WAF, SASE, perimeter firewall, reverse proxy, defense in depth practices, malware analysis tools, etc. Programming experience in bash, python, or PowerShell. Prior experience in the healthcare or pharmaceutical industry.