Cybersecurity AI Platform Advisor (R5)

Eli Lilly · Bengaluru

  • Experience10–11 yrs
  • SalaryNot disclosed
  • Work modeonsite
  • Posted29 Sept 2026

About Eli Lilly

Eli Lilly is hiring in Bengaluru in pharma biotech. This role looks for around 10+ years of experience.

Skills

  • Agentic AI
  • RAG
  • Python
  • LangChain
  • LlamaIndex
  • SIEM
  • EDR
  • Network security
  • Threat intelligence
  • Identity platforms
  • OWASP Top 10 for LLM Applications
  • MITRE ATLAS
  • CI/CD
  • AWS
  • Azure
  • GCP
  • PowerShell
  • Bash
  • RESTful APIs

The role

A security architect at a pharmaceutical company designs Agentic AI security architectures and RAG pipelines for cybersecurity platforms, using Python and cloud security. The role also applies threat modeling and AI governance to secure regulated production deployments.

Full job description

At Lilly, the work is demanding because patients are waiting. We unite caring with discovery to help make life better for people around the world, knowing that every decision, every detail, and every day matters. Headquartered in Indianapolis, Indiana, our over 50,000 employees around the globe take on complex challenges to discover and deliver life-changing medicines, strengthen how health is understood and managed, and support the communities we serve. This is hard, urgent, selfless work—but it’s work worth doing. If you’re driven by purpose and ready to bring your best to work that truly matters for patients, we invite you to join us.

Job Title: Cybersecurity AI Platform Advisor (R5)

Role Overview

Cybersecurity AI Platform Advisor provides senior technical leadership and advisory guidance for AI-powered use cases across Eli Lilly's Cybersecurity platforms. This role owns the architectural vision and technical direction across the full delivery lifecycle — from identifying and scoping use cases through design, build, test, and production deployment — while partnering with engineering teams to execute against that architecture. Core responsibilities include architecting Agentic AI automation pipelines and RAG workflows that address real security challenges such as platform operations automation. The role requires close collaboration with security operations, data privacy, compliance, and platform engineering teams to ensure solutions are secure, explainable, and appropriate for a highly regulated pharmaceutical environment.

Key Responsibilities

Agentic AI Use Case Discovery & Architecture

Serve as the principal technical translator, converting complex business challenges into clear, actionable Agentic AI requirements.

Architect end-to-end agentic systems by defining solution blueprints, staging plans, agent roles, tool inventories, memory strategies, orchestration patterns, and inter-agent communication protocols.

Advise business stakeholders in refining AI adoption objectives and translating them into scalable, viable AI architectures.

Guide stakeholders through Proof of Concepts (PoCs) and development initiatives, from opportunity identification to production handover.

Establish agentic AI guardrails and approved architecture patterns that address prompt injection, unintended action loops, tool misuse, autonomy escalation, and lateral movement risks arising from agent-to-agent trust.

Define agentic AI security acceptance criteria, including sandboxing requirements, permission boundaries, HITL trigger conditions, and kill-switch mechanisms, before solutions progress to development.

Partner with cross-functional teams to identify, scope, and prioritise agentic AI use cases.

Maintain a version-controlled registry of agentic AI use cases, including design blueprints, threat models, tool manifests, and reusable agent patterns to support cross-team adoption.

Agentic AI Architecture & Technical Advisory

Define reference architectures and technical standards for AI agents built on frameworks such as LangGraph, AutoGen, and CrewAI, enabling engineering teams to execute multi-step cybersecurity workflows autonomously and reliably

Establish and promote Agentic AI coding standards and best practices across engineering teams

Design and provide guidance on agent tool layers for security platforms, defining least-privilege access controls and strict input/output contracts for implementation by engineering teams

Architect RAG pipelines for agent knowledge retrieval by defining source validation, document-level injection protections, and context boundaries to prevent data exfiltration through agent outputs

Implement runtime enforcement engines that intercept, validate, and sanitise agent inputs, tool calls, and outputs against configurable security policies, blocking unsafe actions before execution

Implement and motivate teams to implement automations in different manual work done by teams today

Apply CI/CD, Infrastructure-as-Code, and version control practices to agent configurations, tool definitions, prompt templates, and orchestration logic to ensure reproducibility and auditability

Testing, & Safety Validation

Design and execute agentic-specific test plans covering multi-step reasoning accuracy, tool call correctness, loop detection, boundary enforcement, and failure mode handling across diverse scenario types

Validate that human-in-the-loop checkpoints, sandboxing controls, permission gates, and emergency kill-switch mechanisms engage correctly under adversarial and edge-case conditions

Benchmark production-candidate agents against security policy compliance, action explainability, latency SLAs, and cost efficiency before sign-off for deployment

Production Deployment & Lifecycle Management

Deploy agentic AI systems to enterprise cloud environments (AWS, Azure, GCP) with structured action logging, decision tracing, cost monitoring, and real-time alerting on anomalous agent behaviour

Implement agent health monitoring covering task completion rates, tool failure patterns, reasoning drift, and policy enforcement effectiveness — with automated alerts and rollback triggers

Manage the full agentic lifecycle: version-controlled agent releases, controlled rollouts, A/B evaluation of agent variants, scheduled re-validation against updated threat landscapes, and deprecation of obsolete agents

Integrate agents with upstream / downstream security platforms — SIEM, SOAR, EDR, identity, and ticketing systems — through governed API layers that enforce authentication, rate limits, and action audit trails

Provide Level 3 engineering support for agentic incidents including runaway action loops, unexpected tool invocations, and agent-induced security events — with structured post-incident reviews

Governance, Collaboration & Knowledge Sharing

Define and maintain agentic AI governance standards covering action logging requirements, human oversight triggers, permissible tool scopes, and escalation procedures for high-risk autonomous decisions

Collaborate with data privacy, legal, compliance, and quality assurance teams to ensure agentic systems meet regulatory obligations around auditability, explainability, and high-risk AI classifications

Create and maintain comprehensive documentation: agent architecture diagrams, tool manifests, decision trace examples, red-team reports, runbooks, and post-deployment model cards

Mentor junior engineers and security operations personnel on safe agentic design patterns, tool authoring best practices, and responsible AI principles in cybersecurity contexts

Engage with vendors, open-source communities, and technology partners to evaluate emerging agentic frameworks, influence platform roadmaps, and bring best practices back into Lilly's engineering standards

Qualifications

Required

10+ years of software or platform engineering experience, including significant experience in an architecture, technical leadership, or senior advisory capacity, with at least 2 years focused on AI/ML or LLM application development

Demonstrated experience delivering AI use cases end-to-end: from design through testing to production deployment

Working knowledge of cybersecurity domains including SIEM, EDR, network security, threat intelligence, or identity platforms

Proficiency in Python for ML model development, LLM orchestration (e.g. LangChain, LlamaIndex), and API integration

Strong understanding of LLM-specific threat models: prompt injection (direct and indirect), hallucination, jailbreaks, data poisoning, and model misuse

Familiarity with OWASP Top 10 for LLM Applications and MITRE ATLAS adversarial AI threat framework

Experience building or operating CI/CD pipelines for ML/LLM systems including automated testing and deployment gates

Solid understanding of cloud security across AWS, Azure, and GCP environments

Strong scripting capabilities in Python, PowerShell, or Bash; proficient in RESTful APIs and system integration patterns

Excellent written and verbal communication skills with the ability to translate AI concepts for both technical and business audiences

Bachelor’s degree in computer science, Cybersecurity, Information Systems, or related technical field, or equivalent practical experience

Preferred

Experience with AI security reviews, adversarial red-teaming, or AI governance frameworks in regulated industries

Exposure to agentic AI frameworks (AutoGen, CrewAI, LangGraph) and associated safety mechanisms such as HITL, sandboxing, and tool-call guardrails

Familiarity with AI regulatory expectations including high-risk AI classifications, auditability requirements, and conformity assessments

Experience with containerization (Docker, Kubernetes) and cloud-native architectures for ML workloads

Project management exposure or Agile / Scrum experience within cross-functional AI delivery teams

Eli Lilly is an equal opportunity employer and is committed to creating a diverse and inclusive workplace.

Lilly is dedicated to helping individuals with disabilities to actively engage in the workforce, ensuring equal opportunities when vying for positions. If you require accommodation to submit a resume for a position at Lilly, please complete the accommodation request form (https://careers.lilly.com/us/en/workplace-accommodation) for further assistance. Please note this is for individuals to request an accommodation as part of the application process and any other correspondence will not receive a response.

Lilly does not discriminate on the basis of age, race, color, religion, gender, sexual orientation, gender identity, gender expression, national origin, protected veteran status, disability or any other legally protected status.

#WeAreLilly