Job description
AI Identity, Authentication & Authorization
- Extend identity and access principles to non‑human identities and autonomous agents.
- Treat AI agents as first‑class identities, defining authentication, authorization, lifecycle management, and revocation.
- Implement delegated and “on‑behalf‑of” authorization patterns to distinguish human‑initiated actions from agent‑initiated actions.
- Apply least‑privilege and scope‑limiting controls to prevent privilege escalation in automated and multi‑agent workflows.
Threat Modeling & Risk Reduction
- Identify and mitigate AI‑specific risks including data leakage, prompt injection, jailbreaks, model abuse, data poisoning, model extraction, and AI supply‑chain risk.
- Ensure appropriate security testing and validation is embedded into AI development and deployment workflows.
Monitoring & Incident Readiness
- Define logging, monitoring, and detection requirements for AI systems, models, and agent activity.
- Partner with SecOps to ensure AI‑related events are observable, auditable, and actionable.
- Support incident response and post‑incident analysis for AI‑related security events.
Cross‑Functional Delivery
- Work closely with IAM, SecOps, AppSec, GRC, IT engineering, AI platform teams, and business stakeholders to embed security controls where they belong.
Data Security Engineering (Secondary – ~30%)
Data Protection & Governance
- Design and enhance enterprise data security controls with a focus on AI‑driven data access.
- Implement and optimize Microsoft Purview, including data classification, sensitivity labeling, DLP, information protection, and visibility.
AI‑Aware Data Security
- Ensure data security controls are aligned to AI architectures, reducing risk of sensitive data exposure via prompts, agents, outputs, and downstream sharing.
- Support secure use of enterprise data in RAG pipelines, AI workflows, and training environments.
Multi‑Platform Data Flows
- Contribute to data protection strategies across collaboration platforms, cloud services, and endpoints, ensuring consistent enforcement where possible.