About this role
Cognizant seeks an AI Security Solution Architect for its AI Security Engineering & Enablement (AISE) team in Chennai. The role focuses on building reusable security guardrails, automating adversarial validation and integrating controls into AI development and production-review processes. It works with platform and hyperscaler security architects, delivery and DevSecOps teams, AI workload owners and other security stakeholders.
Responsibilities
- Design and maintain a guardrail library with prompt-sanitization SDKs, output filters, PII/PHI redaction modules and topic-boundary controls.
- Build adversarial test automation mapped to the OWASP LLM Top 10 and MITRE ATLAS, covering prompt injection, RAG exfiltration, jailbreaks, model extraction, agent abuse and supply-chain attacks.
- Run adversarial tests on AI workloads submitted for production review; document findings and severity, issue residual-risk statements and support approval decisions.
- Add prompt validation, dependency scanning, model-integrity checks and AI workload security requirements to DevSecOps pipelines. Develop reusable IaC security modules, SIEM telemetry, anomaly signatures, detection logic and recommendations for AI development teams.
Required qualifications
- 10+ years in security engineering or application security, including 3+ years directly in AI/ML security, red teaming or AI security tool development.
- Ability to develop and ship production Python; experience integrating or extending at least two tools such as Garak, PyRIT, LLM Guard, Presidio, NeMo Guardrails or Lakera Guard.
- Practical prompt-injection, indirect prompt-injection and jailbreak testing against real LLM applications; knowledge of RAG threats such as retrieval-based exfiltration, embedding inversion and vector-store poisoning, and agentic threats such as loop hijacking, tool abuse and privilege escalation.
- Ability to turn OWASP LLM Top 10 and MITRE ATLAS techniques into test cases and build security stages in CI/CD pipelines such as GitHub Actions, Azure DevOps or Jenkins.
Preferred qualifications include TypeScript or Go; AI-focused SIEM detection using Sigma, KQL or SPL; Terraform or Bicep security modules; code-level familiarity with LangChain, LangGraph, LlamaIndex or Semantic Kernel; published AI-security contributions; enterprise or consulting security experience; and the ability to explain findings to senior leaders and work with developers on mitigations.
This is a hybrid role requiring 2–3 days in the office. Working arrangements may change with project, business or client requirements.