Senior AI & Application Security Architect
Explicitly calls out vibe-coded applications and AI-assisted code β role requires reviewing and securing vibe-coded workflows and generated code.
About the Role
Lead security architecture for AI-driven and business-critical applications, ensuring secure-by-design solutions across on-prem, cloud, SaaS, and hybrid environments. Define guardrails, threat models, API and application security controls, and embed secure SDLC and DevSecOps practices for internally built, vendor, and AI-assisted/vibe-coded applications.
Job Description
Role
The Senior AI & Application Security Architect will lead security architecture for AI-enabled and business-critical applications across the enterprise. The role focuses on AI and application security for internally built agentic applications, LLM-based solutions, RAG pipelines, AI integrations, and traditional business applications across on-prem, cloud, SaaS, hybrid, and containerized environments.
Key Responsibilities
- Lead security architecture for AI-enabled applications, agentic applications, LLM-based solutions, RAG pipelines, and business-critical applications.
- Define secure-by-design architecture patterns, guardrails, and technical standards for internally built, vendor-provided, or AI-assisted/vibe-coded applications.
- Review and approve application designs, AI workflows, data flows, integrations, APIs, identity models, and access patterns prior to production.
- Ensure applications are secure across on-prem, cloud, SaaS, hybrid, containerized, and API-driven environments.
- Translate security requirements into engineering controls, reference architectures, reusable patterns, and automated guardrails.
- Lead AI security reviews for internal and third-party AI solutions, including copilots, chatbots, automation agents, and embedded AI features.
- Design controls for prompt injection, data leakage, excessive agency, model/API abuse, insecure tool use, and sensitive data exposure.
- Assess AI supply chain risks including third-party models, AI APIs, training data, embeddings, vector databases, and orchestration layers.
- Establish monitoring, logging, auditability, and incident response requirements for AI and application security events.
- Architect API security: authentication, authorization, OAuth/OIDC, service-to-service access, rate limiting, API gateway protections, discovery, and abuse prevention.
- Define and drive threat modeling practices for applications, APIs, AI workflows, agentic behavior, and integrations.
- Embed security across the full application lifecycle and partner with R&D, DevOps, IT, cloud, data, and business teams to implement scalable security controls.
- Define and improve secure SDLC processes (SAST, DAST, SCA, secrets scanning, IaC scanning, container security) and guide vulnerability management and remediation workflows.
- Serve as the security authority and advisor for AI and application architecture decisions, lead architecture reviews, and set technical governance.
Requirements
Experience
- 10+ years in cybersecurity with deep experience in application security, AI security, cloud security, secure architecture, and technical security leadership.
- Proven experience securing enterprise applications, APIs, integrations, SaaS platforms, cloud-native and on-prem applications.
- Hands-on understanding of infrastructure security (identity, networking, endpoint security), cloud platforms, containers, CI/CD pipelines, monitoring, SIEM/XDR, and security operations.
- Deep expertise in threat modeling, secure SDLC, DevSecOps, vulnerability management, authentication, authorization, encryption, and secrets management.
- Hands-on experience with AI security topics: LLM applications, agentic applications, RAG architectures, AI APIs, prompt injection, AI data protection, and AI governance.
- Experience reviewing AI-assisted and vibe-coded applications for generated code validation, dependency and permission checks, data handling, and production readiness.
- Experience with Linux and Windows platforms, cloud services, containers, CI/CD, and application hosting environments.
- Hands-on with AppSec and security tools including SAST, DAST, SCA, secrets scanning, API security testing, WAF/API gateways, SIEM, XDR, CASB, DLP, and patch management.
- Experience with monitoring, automation, orchestration, security-as-code, and automated guardrails.
Certifications (preferred)
- CISSP, CSSLP, GWAPT, AWS/Azure Security, cloud architect certifications, or equivalent hands-on experience.
Location
Primary location: Chennai, India. Onsite work location: Radware Shield Square India, Chennai (Velachery Main Road, Little Mount - Saidapet).