Senior AI Security Architect
NTT DATA
NTT DATA
NTT DATA seeks a Senior AI Security Architect to enhance security for enterprise AI/ML, GenAI, RAG, and agentic platforms across various cloud environments. The role involves translating AI risks into practical security controls, including guardrails and secure development practices. This position empowers the safe adoption and innovation of AI technologies within the organization.
This role is pivotal in defining and implementing robust security architectures that underpin cutting-edge AI initiatives. It requires a deep understanding of emerging AI risks and the ability to engineer effective mitigation strategies. The ideal candidate will drive a security-first mindset throughout the AI lifecycle.
Define target security architectures and design patterns for LLM/RAG/agent workloads, from prototype to production. Lead AI threat modeling using industry standards (STRIDE/PASTA, OWASP LLM Top 10, MITRE ATLAS, NIST AI RMF) to address complex vulnerabilities. Embed security seamlessly into SDLC/MLOps/LLMOps processes, including CI/CD, IaC, and release gates. Design comprehensive controls for IAM, Zero Trust, API gateways, network security, secrets management, encryption, and data protection across multi-cloud and hybrid environments. Establish AI red-teaming and define observability and SecOps for AI telemetry and incident response. Drive governance with legal, risk, and data teams, ensuring compliance with relevant regulations. Review product designs and influence engineering teams while minimizing delivery friction.
Key responsibilities include establishing baseline security principles and controls that ensure a mandatory minimum security posture. These controls must be adaptable, allowing individual projects to enhance them based on specific risk profiles and regulatory demands. The architect will also champion AI governance, model cards, vendor assessments, and compliance mapping.
A minimum of 10 years in cybersecurity, cloud security, or security architecture, with at least 3 years focused on securing AI/ML/GenAI solutions in production environments. Essential knowledge includes LLMs, embeddings, vector databases, RAG, agentic workflows, model training/inference, data lineage, and model evaluation. Proven hands-on experience with cloud-native architectures, Kubernetes, containerization, API/microservices, and identity platforms, including familiarity with OAuth2, OIDC, mTLS, RBAC/ABAC, WAF, API gateways, and secrets/key management.
Proficiency with AI/security tooling such as promptfoo, garak, PyRIT, Giskard, Guardrails AI, NeMo Guardrails/Llama Guard, MLflow, LangChain/LlamaIndex/LangSmith, SIEM/SOAR, CNAPP/CSPM/CWPP, and SAST/SCA/DAST/container/IaC scanners is expected. Excellent stakeholder communication skills are crucial for creating concise threat models, security standards, risk papers, and executive recommendations. Preferred qualifications include relevant certifications (CISSP, CCSP, CISM, SABSA, TOGAF, cloud security) and experience in regulated industries.
NTT DATA
IT Consulting