SlipstreamJobsFresh Startup & VC-Backed Jobs

Principal AI Security Engineer

Candescent - Bengaluru, Karnataka, India - Hybrid

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Candescent is seeking a Principal AI Security Engineer to own the security posture of how the company adopts and integrates third-party AI and LLM services across the enterprise. This is a hands-on practitioner role for someone with strong security engineering foundations and meaningful expertise in AI/ML security risks. The role focuses on securing enterprise consumption of external AI providers—not building or training models. Key responsibilities include: **Secure AI Integration**: Define and maintain secure integration patterns for third-party AI and LLM services, including API security, authentication, secrets management, and data-in-transit protections. Establish input/output controls, prompt handling standards, and data classification guardrails. Evaluate security posture of AI service providers. Develop guidance for secure adoption of agentic AI tools and multi-agent integrations with scope containment and human oversight controls. **AI Security Governance**: Build an AI security risk framework aligned to regulatory obligations (GLBA, PCI DSS 4.0.1, DORA ICT third-party risk, NYDFS 23 NYCRR 500). Establish governance controls for enterprise AI adoption, including standards for approved services and shadow AI detection. Align controls to emerging frameworks like NIST AI RMF and ISO/IEC 42001. **Threat Identification & Engineering Controls**: Identify and mitigate AI-specific risks including prompt injection, model manipulation, data leakage, adversarial inputs, and AI-enabled social engineering. Partner with security operations to build detection and response capabilities. Monitor the evolving AI threat landscape. **Cross-Functional Partnership**: Work with engineering, product, and cloud platform teams to embed security-by-design into AI-enabled applications. Communicate AI security risks to technical and non-technical leadership. Contribute to security awareness and internal education. Required: Bachelor's in Computer Science, Information Security, Engineering, or equivalent; 7+ years in security engineering, application security, or cloud security; hands-on experience with cloud-native environments and API integrations (AWS, Azure, GCP); solid understanding of authentication, authorization, secrets management, and data protection; ability to assess technical risk and translate findings into actionable controls; working knowledge of AI/ML security risks (prompt injection, data leakage, insecure API integration, shadow AI, model output manipulation, AI supply chain risk); familiarity with OWASP LLM Top 10 and MITRE ATLAS; experience securing LLM service provider integrations (Azure OpenAI, AWS Bedrock, Google Vertex AI, Anthropic, OpenAI); demonstrated professional engagement with AI security. Security certifications valued: CISSP, CCSP, AWS Security Specialty, AZ-500, Google Professional Cloud Security Engineer, or ISSAP. Preferred: familiarity with GLBA, PCI DSS 4.0.1, NYDFS 23 NYCRR 500, or DORA; experience in regulated financial services; AI security certifications (CAISP, CAISS, AIGP, ISO/IEC 42001 Lead Implementer/Auditor). Hybrid role based in Bangalore office.

Similar roles