Cloud AI Security Specialist
Biocon Biologics Limited · Bengaluru
- Experience8–12 yrs
- SalaryNot disclosed
- Work modeonsite
- Levelexecutive
- Posted21 Sept 2026
About Biocon Biologics Limited
Biocon Biologics Limited is hiring in Bengaluru in pharma biotech. This role looks for around 8+ years of experience.
Skills
- Generative AI
- AI security governance
- threat modeling
- security architecture
- cloud security
- Azure
- Amazon Web Services
- Google Cloud Platform
- Zero Trust Architecture
- data classification
- encryption
- tokenization
- masking
- Identity and Access Management
- Privileged Access Management
- vulnerability assessment
- ISO 27001
- NIST AI Risk Management Framework
- General Data Protection Regulation
- Health Insurance Portability and Accountability Act
The role
A security architect at a pharmaceutical biotechnology company designs AI and cloud security controls using Generative AI, Zero Trust Architecture, and Identity and Access Management. The role develops governance frameworks, threat models, privacy safeguards, and compliance practices for secure AI platforms and regulated data.
Full job description
KEY RESPONSIBILITIES -
AI Security Architecture & Governance - Develop and implement enterprise-wide AI security strategies, standards, policies, and guardrails. - Establish governance frameworks for AI and Generative AI solutions to ensure secure, responsible, and compliant adoption. - Conduct AI security assessments, threat modeling, and risk evaluations for AI applications, models, and services. - Define secure AI usage guidelines, acceptable use policies, and AI governance controls. - Evaluate AI platforms, tools, and services from security, privacy, compliance, and operational risk perspectives. - Design secure AI architectures, reference patterns, and security-by-design frameworks. - Review AI solution designs and provide security recommendations throughout the project lifecycle. - Evaluate and manage security risks associated with third-party AI vendors and cloud service providers.
Security Architecture, Solution Design & Assurance - Act as the security architecture lead for AI, GenAI, and cloud transformation initiatives. - Review and approve solution architectures to ensure alignment with enterprise security standards, policies, and regulatory requirements. - Provide security design guidance throughout the solution lifecycle, from concept and architecture to implementation and operations. - Conduct architecture risk assessments and identify security gaps, design weaknesses, and mitigation strategies. - Develop and maintain reference architectures, security patterns, and reusable design frameworks for AI and cloud platforms. - Participate in Architecture Review Boards (ARB), technical design reviews, and governance forums. - Evaluate emerging AI technologies, cloud services, and platforms to determine security implications and architectural suitability. - Ensure Security-by-Design and Privacy-by Design principles are embedded within AI and cloud solutions. - Define security requirements for integrations, APIs, data flows, and third-party services. - Collaborate with Enterprise Architecture, Cloud Engineering, Data Engineering, and Application Development teams to establish secure and scalable solutions. - Perform security assurance reviews prior to production deployment and provide risk-based recommendations. - Support threat modeling, attack surface analysis, and architecture assessments for strategic business initiatives.
Cloud Security & Infrastructure Protection - Design and implement security controls across Azure, AWS, and GCP environments supporting AI workloads. - Secure cloud-native AI services, machine learning platforms, data lakes, and AI development environments. - Ensure cloud architectures comply with enterprise security standards and industry best practices. - Implement Zero Trust Architecture principles across AI and cloud workloads. - Integrate AI security requirements into cloud security frameworks, operating models, and engineering practices.
Data Security & Privacy - Define and implement controls to protect sensitive, regulated, and business-critical data utilized by AI systems. - Ensure data classification, encryption, tokenization, masking, and privacy-preserving controls are implemented and maintained. - Monitor and prevent data leakage through AI applications, APIs, and cloud services. - Establish secure data-sharing, retention, and lifecycle management practices. - Ensure compliance with applicable data privacy regulations and organizational data protection policies. Identity & Access Management - Design and implement Identity and Access Management (IAM) controls for AI platforms and cloud services. - Enforce least-privilege access, Privileged Access Management (PAM), and strong authentication controls. - Review access governance processes and ensure secure integration with enterprise identity platforms.
Security Operations & Threat Management - Develop monitoring, detection, and response use cases for AI-specific threats, including prompt injection, model poisoning, adversarial attacks, data leakage, and unauthorized model access. - Collaborate with SOC, Incident Response, and Threat Intelligence teams to investigate and respond to AI-related security incidents. - Conduct vulnerability assessments, architecture reviews, and security testing activities for AI applications and supporting infrastructure. - Support continuous monitoring and ongoing improvement of AI security controls and capabilities.
Compliance, Risk Management & Awareness - Ensure compliance with ISO 27001, NIST AI Risk Management Framework (AI RMF), GDPR, HIPAA, and other applicable regulations. - Support internal audits, external assessments, and regulatory reviews related to AI and cloud security. - Develop and maintain AI risk registers, mitigation plans, and governance reporting mechanisms. - Conduct AI security awareness and training programs for employees and technical teams. - Provide guidance to development, cloud, and business teams on secure AI development and deployment practices. - Promote responsible, ethical, and secure use of AI technologies across the organization