SECURITY ARCHITECT - AI / GENAI
SIDRAM TECHNOLOGIES · New York, NY · 1 wk ago
On-siteInformation TechnologyFull-time
Client: S&P Global | Location: NYC / NJC Hybrid | Employment Type: Full-Time / FTE
About the role
We are seeking an experienced Application Security Architect with strong expertise in Application Security, Security Architecture, DevSecOps, Cloud Security, and AI/GenAI Security. The role will focus on securing enterprise applications, APIs, microservices, cloud-native platforms, and AI-powered applications while driving security-by-design across the organization.
Responsibilities
- Design and implement application security architecture across enterprise applications, APIs, and microservices.
- Conduct threat modeling, security reviews, and vulnerability assessments.
- Embed security throughout the SDLC and CI/CD pipelines using SAST, DAST, SCA, and related security tools.
- Establish secure coding practices aligned with OWASP Top 10 and API Security standards.
- Secure cloud-native applications across AWS/GCP, Kubernetes, and container environments.
- Define security controls for GenAI, LLM, RAG, and Agentic AI applications.
- Address AI security risks including prompt injection, data leakage, insecure outputs, and excessive agency.
- Implement IAM, authentication, authorization, encryption, Policy-as-Code, and Identity-as-Code.
- Partner with engineering, architecture, and security teams to establish security-by-design practices.
- Drive application security standards, controls, and architectural best practices across enterprise platforms.
AI / GenAI Security Expertise
- Secure LLM and GenAI applications.
- Implement controls for RAG pipelines and Agentic AI workflows.
- Identify and mitigate prompt injection and data leakage risks.
- Establish guardrails for AI-generated outputs.
- Address excessive agency and unauthorized AI actions.
- Secure AI data, models, APIs, and supporting infrastructure.
Requirements
- 15+ years of experience in Application Security, Security Architecture, or related cybersecurity domains.
- Strong expertise in:
- Application Security
- OWASP Top 10
- Threat Modeling
- Secure SDLC
- API Security
- SAST / DAST / SCA
- Hands-on experience with AWS/GCP, Kubernetes, Docker, CI/CD, and Terraform.
- Strong understanding of OAuth2, OIDC, JWT, IAM, RBAC, and ABAC.
- Experience with GenAI / LLM / RAG / Agentic AI / AI Security.
- Knowledge of LangChain / LangGraph, vector databases, and AI security controls is a plus.
- Strong communication, architecture, and stakeholder management skills.