Required Skills:
- Application Security
-
RPA Security
-
Threat Modeling
-
IAM Security
-
Security Testing
-
Privacy & Data Protection
-
Security Risk Management
-
Cloud Security
Nice to Have:
- Security Certifications
-
Compliance Frameworks
Designation | Lead RPA/APA Security Advisor Qualification | Bachelor s or master s degree in computer science, Cybersecurity, Software Engineering or equivalent experience. Experience (in years) | 4 Job Description | Job purpose We are looking for a Security Advisor to join the AI Hub and support the secure design, build and operation of Robot Process Automation (RPA) and Agentic Process Automation solutions. You will partner with Product Owners, Architects, Developers, Platform/Operations teams and business stakeholders to embed security-by-design across the automation lifecycle, from ideation and tool selection to deployment, monitoring and continuous improvement. Responsibilities: As a Security Advisor, you will act as an enabler for delivery teams by providing practical guidance, reviews and coaching to ensure RPA and Agentic Process Automation solutions meet security, privacy and compliance expectations. You will help teams apply secure engineering practices (SDL/SDLC), manage risks introduced by automation tooling and agent autonomy, and support the definition of scalable guardrails for citizen and professional developers. In this role, you will: 1. Drive the security-by-design approach for RPA and Agentic Process Automation initiatives across the AI Hub portfolio. 2. Advise Product Owners and Architects on security requirements, acceptable patterns, and risk-based decisions (including agent autonomy, permissions, and human-in-the-loop controls). 3. Perform and/or facilitate threat modeling and attack surface reviews for automation workflows, agent tools, connectors, APIs and orchestrators. 4. Review secure design and implementation topics: identity and access management, least privilege, credential/secrets handling, logging and monitoring, and secure configuration for runtimes and platforms. 5. Support privacy and data protection: data classification, minimization, retention, DPIA/PIA inputs when required, and compliance with applicable standards and regulations. 6. Define and maintain reusable security guardrails for automation at scale (templates, reference architectures, hardening guides, secure coding guidance for low-code/no-code). 7. Coordinate security testing activities (SAST/DAST, configuration reviews, dependency/SBOM checks where applicable, penetration testing planning) and support remediation tracking. 8. Assess third-party and platform risks (tooling, connectors, plugins, SaaS services) in collaboration with procurement, legal and vendor risk stakeholders. 9. Support incident readiness and response for automation solutions (alerting, runbooks, forensics-friendly logging, lessons learned). 10. Contribute to internal reporting and governance: security posture, compliance evidence, key risks, and improvement plans; support customer and auditor security queries when relevant. Human skills Strong stakeholder management: able to influence Product, Engineering and Operations teams with pragmatic, risk-based recommendations. • Clear communication and coaching skills, comfortable explaining security requirements to both technical and non-technical audiences (including citizen developers). • Ability to work in ambiguous, fast-moving environments and adapt to evolving automation and agentic technologies. • Structured and detail-oriented, able to produce audit-ready evidence and track remediation actions to closure. • Collaborative mindset and integrity: challenges constructively, escalate when needed, and maintains a strong customer and business focus. Education: Bachelor’s or master’s degree in computer science, Cybersecurity, Software Engineering or equivalent experience. • Security certification is a plus (e.g., CSSLP, CISSP, CCSP, OSCP/CEH) and/or privacy certification/experience (e.g., CIPP/E or equivalent practical background). Experience: 3+ years of experience in application/product security, secure engineering, or security advisory roles. • Hands-on experience with at least two SDL domains (e.g., secure design review, threat modeling, vulnerability management, security testing, secure coding guidance, cloud security). • Exposure to automation platforms and patterns (RPA, workflow/orchestration, low-code/no-code) and/or agentic systems is highly valued. Knowledge and technical skills: Security risk management fundamentals (identify, assess, document, and track risks) with a pragmatic delivery mindset. • Threat modeling and secure design for automation workflows, including connectors/APIs, orchestration, and agent tool access. • Identity and access management concepts (least privilege, privileged access, service accounts), secrets management, and secure authentication/authorization patterns. • Security testing and vulnerability management: secure code review guidance, configuration reviews, and coordination of security test activities. • Privacy and data protection: data classification, handling controls, and supporting compliance activities (e.g., GDPR) for automation use cases. • Familiarity with relevant standards/regulations is a plus (e.g., ISO/IEC 27001, IEC 62443, CRA, NIS2), and with secure cloud/SaaS usage practices. Skill Set Required | Strong stakeholder management: able to influence Product, Engineering and Operations teams with pragmatic, risk-based recommendations. • Clear communication and coaching skills, comfortable explaining security requirements to both technical and non-technical audiences (including citizen developers). • Ability to work in ambiguous, fast-moving environments and adapt to evolving automation and agentic technologies. • Structured and detail-oriented, able to produce audit-ready evidence and track remediation actions to closure. • Collaborative mindset and integrity: challenges constructively, escalate when needed, and maintains a strong customer and business focus.