Security Engineer
Razorpay Β· Bengaluru, Karnataka, India
Free to search Β· AI fit score against your CV Β· tailor your rΓ©sumΓ© in one click
Razorpay Β· Bengaluru, Karnataka, India
AI Security Engineer Role Summary β We are hiring an AI Engineer who will build agentic systems and AI-driven automation for our security and infrastructure functions. β The ideal candidate is AI-native first β fluent in LLMs, agent frameworks, and prompt/context engineering β with working knowledge of security and a strong grasp of infra/deployment. β This is not a traditional security engineering role. We want someone who thinks in terms of agents, tools, and orchestration, and who can ship AI systems that operate against real production infrastructure. β Reports into Security/Platform leadership; collaborates with SecOps, CloudSec, AppSec, and SRE teams. What You'll Build β Agentic security workflows β multi-agent systems (planner-executor, orchestrator-subagent) for IR triage, threat hunting, alert correlation, and compliance evidence collection. β MCP servers and clients that wrap internal tools (SentinelOne, Zscaler, AWS APIs, Active Directory, Jamf, Semgrep, etc.) so agents can act on production systems. β AI-driven infra automation β agents that deploy, configure, and remediate Kubernetes workloads, IAM policies, network rules, and cloud resources. β L LM-powered detection and response pipelines β log summarisation, anomaly explanation, runbook execution, and automated containment with human-in-the-loop guardrails. β Evals, guardrails, and safety layers for production AI systems handling sensitive data. β Internal AI platform β gateways, model routing, prompt registries, and observability for LLM use across the org. Must-Have: AI Engineering β Hands-on experience building production systems with Claude (Anthropic API), OpenAI, or equivalent frontier LLMs β not just chatbot demos. β Strong prompt engineering and context engineering β understands tool-use loops, structured outputs, evals, and failure modes. β Built at least one agentic system end-to-end β planner-executor, ReAct, orchestrator-subagent, or similar. β Experience with MCP (Model Context Protocol) β has built MCP servers/clients or equivalent tool-wrapping abstractions. β Comfort with agent frameworks β Claude Agent SDK, LangGraph, AutoGen, CrewAI, or custom orchestration. β Working knowledge of local inference β Ollama, LM Studio, vLLM, llama.cpp β and proxy layers like LiteLLM. β Familiarity with fine-tuning, RAG, and embeddings β knows when to reach for each. β Has shipped at least one AI system that took real actions on real systems (not read-only analysis). Must-Have: Infra & Deployment β Strong Kubernetes chops β has deployed and operated workloads on EKS/GKE/AKS, written Helm charts or Kustomize, and debugged pod/networking/RBAC issues. β AWS or GCP depth β IAM, VPC, networking, secrets, observability. β Infrastructure as Code β Terraform, Pulumi, or CDK. β CI/CD β GitHub Actions, ArgoCD, or similar; understands deployment patterns (blue-green, canary). β Comfortable making agents drive infra changes β knows the diff between "agent suggests a Terraform plan" and "agent applies it" and how to gate the latter safely. β Container security basics β image scanning, Pod Security Standards, admission controllers. Nice-to-Have: Security Knowledge (Add-on) β Familiarity with at least one of: SIEM/XDR (SentinelOne, Splunk), SAST/DAST (Semgrep, Burp), CSPM (Wiz, Prowler), or DLP/SSE (Zscaler). β Awareness of OWASP Top 10 for LLMs, prompt injection, jailbreaks, and data exfil via LLMs. β Conceptual understanding of compliance regimes β PCI DSS, ISO 27001, SOC 2, RBI, DPDP β enough to know what "evidence" means. β Threat modelling fundamentals (STRIDE) and MITRE ATT&CK literacy. β Note: We are not looking for a CISSP profile. Security knowledge is an add-on; AI engineering and infra are the primary bar. Mindset β Builder, not just a researcher β ships systems, not just notebooks. β Pragmatic about AI β knows what LLMs are bad at and designs around it (deterministic fallbacks, validators, human-in-the-loop). β Safety-aware β thinks about prompt injection, tool abuse, and blast radius before an agent gets sudo. β Comfortable with ambiguity β this space changes monthly; you should enjoy that. Location - Bangalore