Cybersecurity AI Platform Advisor (R5)
Eli Lilly · Bengaluru
- Experience10–11 yrs
- SalaryNot disclosed
- Work modeonsite
- Posted29 Sept 2026
About Eli Lilly
Eli Lilly is hiring in Bengaluru in pharma biotech. This role looks for around 10+ years of experience.
Skills
- Agentic AI
- RAG
- Python
- LangChain
- LlamaIndex
- SIEM
- EDR
- Network security
- Threat intelligence
- Identity platforms
- OWASP Top 10 for LLM Applications
- MITRE ATLAS
- CI/CD
- AWS
- Azure
- GCP
- PowerShell
- Bash
- RESTful APIs
The role
A security architect at a pharmaceutical company designs Agentic AI security architectures and RAG pipelines for cybersecurity platforms, using Python and cloud security. The role also applies threat modeling and AI governance to secure regulated production deployments.
Full job description
At Lilly, the work is demanding because patients are waiting. We unite caring with discovery to help make life better for people around the world, knowing that every decision, every detail, and every day matters. Headquartered in Indianapolis, Indiana, our over 50,000 employees around the globe take on complex challenges to discover and deliver life-changing medicines, strengthen how health is understood and managed, and support the communities we serve. This is hard, urgent, selfless work—but it’s work worth doing. If you’re driven by purpose and ready to bring your best to work that truly matters for patients, we invite you to join us.
Job Title: Cybersecurity AI Platform Advisor (R5)
Role Overview
Cybersecurity AI Platform Advisor provides senior technical leadership and advisory guidance for AI-powered use cases across Eli Lilly's Cybersecurity platforms. This role owns the architectural vision and technical direction across the full delivery lifecycle — from identifying and scoping use cases through design, build, test, and production deployment — while partnering with engineering teams to execute against that architecture. Core responsibilities include architecting Agentic AI automation pipelines and RAG workflows that address real security challenges such as platform operations automation. The role requires close collaboration with security operations, data privacy, compliance, and platform engineering teams to ensure solutions are secure, explainable, and appropriate for a highly regulated pharmaceutical environment.
Key Responsibilities
Agentic AI Use Case Discovery & Architecture
Serve as the principal technical translator, converting complex business challenges into clear, actionable Agentic AI requirements.
Architect end-to-end agentic systems by defining solution blueprints, staging plans, agent roles, tool inventories, memory strategies, orchestration patterns, and inter-agent communication protocols.
Advise business stakeholders in refining AI adoption objectives and translating them into scalable, viable AI architectures.
Guide stakeholders through Proof of Concepts (PoCs) and development initiatives, from opportunity identification to production handover.
Establish agentic AI guardrails and approved architecture patterns that address prompt injection, unintended action loops, tool misuse, autonomy escalation, and lateral movement risks arising from agent-to-agent trust.
Define agentic AI security acceptance criteria, including sandboxing requirements, permission boundaries, HITL trigger conditions, and kill-switch mechanisms, before solutions progress to development.
Partner with cross-functional teams to identify, scope, and prioritise agentic AI use cases.
Maintain a version-controlled registry of agentic AI use cases, including design blueprints, threat models, tool manifests, and reusable agent patterns to support cross-team adoption.
Agentic AI Architecture & Technical Advisory
Define reference architectures and technical standards for AI agents built on frameworks such as LangGraph, AutoGen, and CrewAI, enabling engineering teams to execute multi-step cybersecurity workflows autonomously and reliably
Establish and promote Agentic AI coding standards and best practices across engineering teams
Design and provide guidance on agent tool layers for security platforms, defining least-privilege access controls and strict input/output contracts for implementation by engineering teams
Architect RAG pipelines for agent knowledge retrieval by defining source validation, document-level injection protections, and context boundaries to prevent data exfiltration through agent outputs
Implement runtime enforcement engines that intercept, validate, and sanitise agent inputs, tool calls, and outputs against configurable security policies, blocking unsafe actions before execution
Implement and motivate teams to implement automations in different manual work done by teams today
Apply CI/CD, Infrastructure-as-Code, and version control practices to agent configurations, tool definitions, prompt templates, and orchestration logic to ensure reproducibility and auditability
Testing, & Safety Validation
Design and execute agentic-specific test plans covering multi-step reasoning accuracy, tool call correctness, loop detection, boundary enforcement, and failure mode handling across diverse scenario types
Validate that human-in-the-loop checkpoints, sandboxing controls, permission gates, and emergency kill-switch mechanisms engage correctly under adversarial and edge-case conditions
Benchmark production-candidate agents against security policy compliance, action explainability, latency SLAs, and cost efficiency before sign-off for deployment
Production Deployment & Lifecycle Management
Deploy agentic AI systems to enterprise cloud environments (AWS, Azure, GCP) with structured action logging, decision tracing, cost monitoring, and real-time alerting on anomalous agent behaviour
Implement agent health monitoring covering task completion rates, tool failure patterns, reasoning drift, and policy enforcement effectiveness — with automated alerts and rollback triggers
Manage the full agentic lifecycle: version-controlled agent releases, controlled rollouts, A/B evaluation of agent variants, scheduled re-validation against updated threat landscapes, and deprecation of obsolete agents
Integrate agents with upstream / downstream security platforms — SIEM, SOAR, EDR, identity, and ticketing systems — through governed API layers that enforce authentication, rate limits, and action audit trails
Provide Level 3 engineering support for agentic incidents including runaway action loops, unexpected tool invocations, and agent-induced security events — with structured post-incident reviews
Governance, Collaboration & Knowledge Sharing
Define and maintain agentic AI governance standards covering action logging requirements, human oversight triggers, permissible tool scopes, and escalation procedures for high-risk autonomous decisions
Collaborate with data privacy, legal, compliance, and quality assurance teams to ensure agentic systems meet regulatory obligations around auditability, explainability, and high-risk AI classifications
Create and maintain comprehensive documentation: agent architecture diagrams, tool manifests, decision trace examples, red-team reports, runbooks, and post-deployment model cards
Mentor junior engineers and security operations personnel on safe agentic design patterns, tool authoring best practices, and responsible AI principles in cybersecurity contexts
Engage with vendors, open-source communities, and technology partners to evaluate emerging agentic frameworks, influence platform roadmaps, and bring best practices back into Lilly's engineering standards
Qualifications
Required
10+ years of software or platform engineering experience, including significant experience in an architecture, technical leadership, or senior advisory capacity, with at least 2 years focused on AI/ML or LLM application development
Demonstrated experience delivering AI use cases end-to-end: from design through testing to production deployment
Working knowledge of cybersecurity domains including SIEM, EDR, network security, threat intelligence, or identity platforms
Proficiency in Python for ML model development, LLM orchestration (e.g. LangChain, LlamaIndex), and API integration
Strong understanding of LLM-specific threat models: prompt injection (direct and indirect), hallucination, jailbreaks, data poisoning, and model misuse
Familiarity with OWASP Top 10 for LLM Applications and MITRE ATLAS adversarial AI threat framework
Experience building or operating CI/CD pipelines for ML/LLM systems including automated testing and deployment gates
Solid understanding of cloud security across AWS, Azure, and GCP environments
Strong scripting capabilities in Python, PowerShell, or Bash; proficient in RESTful APIs and system integration patterns
Excellent written and verbal communication skills with the ability to translate AI concepts for both technical and business audiences
Bachelor’s degree in computer science, Cybersecurity, Information Systems, or related technical field, or equivalent practical experience
Preferred
Experience with AI security reviews, adversarial red-teaming, or AI governance frameworks in regulated industries
Exposure to agentic AI frameworks (AutoGen, CrewAI, LangGraph) and associated safety mechanisms such as HITL, sandboxing, and tool-call guardrails
Familiarity with AI regulatory expectations including high-risk AI classifications, auditability requirements, and conformity assessments
Experience with containerization (Docker, Kubernetes) and cloud-native architectures for ML workloads
Project management exposure or Agile / Scrum experience within cross-functional AI delivery teams
Eli Lilly is an equal opportunity employer and is committed to creating a diverse and inclusive workplace.
Lilly is dedicated to helping individuals with disabilities to actively engage in the workforce, ensuring equal opportunities when vying for positions. If you require accommodation to submit a resume for a position at Lilly, please complete the accommodation request form (https://careers.lilly.com/us/en/workplace-accommodation) for further assistance. Please note this is for individuals to request an accommodation as part of the application process and any other correspondence will not receive a response.
Lilly does not discriminate on the basis of age, race, color, religion, gender, sexual orientation, gender identity, gender expression, national origin, protected veteran status, disability or any other legally protected status.
#WeAreLilly