Staff Engineer (AI Security and DevSecOps )
Nagarro · Hyderabad, Telangana, India
Nagarro · Hyderabad, Telangana, India
**👋🏼We're Nagarro.** We are a Digital Product Engineering company that is scaling in a big way! We build products, services, and experiences that inspire, excite, and delight. We work at a scale — across all devices and digital mediums, and our people exist everywhere in the world (18500+ experts across 40 countries, to be exact). Our work culture is dynamic and non-hierarchical. We are looking for great new colleagues. That is where you come in! **Requirements** - Experience : 5.5+ yrs - Strong experience in DevOps, DevSecOps, Cloud Infrastructure, or AI/ML Security engineering. - Strong experience in **Machine Learning** environments, securing ML pipelines, or LLM-powered applications. - Hands-on experience building and securing **unstructured data pipelines** for AI/ML workloads. - Proficiency in Python and Bash scripting for automation, infrastructure management, and security tooling. - Experience with Infrastructure as Code (IaC) tools such as Terraform or Pulumi. - Strong understanding of cloud platforms including AWS, Azure, or GCP and cloud security best practices. - Experience implementing security controls across CI/CD pipelines, including SAST, DAST, dependency scanning, and secrets management. - Solid understanding of OWASP security principles, Zero Trust architecture, and secrets management solutions such as HashiCorp Vault or AWS Secrets Manager. - Experience implementing AI security controls, including prompt injection mitigation, input/output filtering, abuse detection, and secure LLM integrations. - Knowledge of AI/ML security risks such as model inversion, data poisoning, prompt injection, and adversarial attacks. - Familiarity with data privacy regulations such as GDPR, CCPA, HIPAA, and compliance frameworks including SOC 2, ISO 27001, or NIST AI RMF. - Experience implementing data classification, lineage tracking, PII detection, anonymization, and retention policies. - Knowledge of Kubernetes, container security, and cloud-native infrastructure hardening. - Experience building observability, monitoring, and alerting solutions for AI systems, infrastructure, and security events. - Familiarity with Azure DevOps pipeline strategy and CI/CD automation is an advantage. - Exposure to AI/ML frameworks such as PyTorch, LangChain, vector databases, or similar technologies is preferred. - Professional certifications such as AWS Security Specialty, CISSP, CISM, or Google Professional Cloud Security Engineer are desirable. - Excellent analytical, troubleshooting, communication, and stakeholder management skills. **Responsibilities** - Design, implement, and maintain security controls for AI/ML platforms and LLM-powered applications. - Perform threat modeling for AI systems, identifying and mitigating risks including prompt injection, model inversion, data poisoning, and adversarial attacks. - Implement guardrails, input/output validation, abuse detection, and security controls for Generative AI applications. - Conduct security assessments and reviews of third-party AI services, APIs, and model integrations. - Monitor AI applications and infrastructure for security incidents, anomalies, and emerging threats, and coordinate timely incident response. - Design and secure data pipelines for structured and unstructured AI datasets while ensuring regulatory compliance. - Implement data classification, lineage tracking, retention policies, and governance frameworks for AI training and inference data. - Develop and maintain PII detection, anonymization, and data protection mechanisms across AI datasets. - Embed security throughout CI/CD pipelines using automated scanning, dependency management, secrets management, and infrastructure validation. - Provision and manage secure cloud infrastructure using Infrastructure as Code and cloud-native security best practices. - Harden containerized environments and Kubernetes platforms to ensure secure AI application deployment. - Build monitoring, observability, and alerting solutions for model performance, drift detection, infrastructure health, and security events. - Develop and maintain incident response playbooks for AI platforms, cloud infrastructure, and security-related events. - Support security audits, compliance assessments, and documentation for regulatory and organizational standards. - Collaborate with AI engineers, DevOps teams, data engineers, and security stakeholders to deliver secure, scalable, and compliant AI solutions. - Continuously evaluate emerging AI security threats, industry standards, and best practices to strengthen the organization's AI security posture. Bachelor’s or master’s degree in computer science, Information Technology, or a related field.