Job Title: Associate Director – AI Security Engineering
Location: Hyderabad or Mumbai
Job ID: B-26034
EC-Council is the world's largest cyber security technical certification body. We operate in 145 countries globally and we are the owner and developer of various world-famous cyber security programs. We are proud to have trained and certified over 400,000 information security professionals globally that have influenced the cyber security mindset of countless organizations worldwide.
www.eccouncil.org
Role Overview:
We are looking for an Associate Director – AI Security Engineering to lead the design, implementation, and governance of security controls across our AI/ML and agentic systems. This role sits at the intersection of AI engineering, cybersecurity, software engineering, and governance — responsible for securing everything from LLM applications and RAG pipelines to autonomous AI agents, fine-tuned models, and the infrastructure that serves them.
You will build and lead a team responsible for identifying, testing, and mitigating security risks unique to AI systems, while also embedding security-by-design practices into the broader AI development lifecycle.
Key Responsibilities:
Strategy & Leadership
-
Define and drive the AI security engineering roadmap, standards, and governance frameworks across the organization
-
Build, mentor, and lead a team of AI security engineers and researchers
-
Partner with AI/ML engineering, platform, product, and compliance teams to embed security throughout the AI development lifecycle
-
Own AI risk assessments, threat modeling, and security sign-off for new AI/agentic system launches
AI Application & LLM Security
-
Lead defenses against prompt injection, jailbreaks, role overrides, system prompt extraction, prompt leakage, multi-turn manipulation, and context poisoning
-
Oversee security architecture for RAG pipelines — protecting against retrieval poisoning, malicious documents, hidden prompt payloads (HTML/Markdown injection), vector/embedding poisoning, chunk manipulation, and cross-document contamination
-
Establish secure prompt engineering and evaluation standards across product teams
Agentic AI & Tooling Security
-
Design and enforce security models for AI agents, including tool permissioning, least privilege, identity/authentication, session isolation, human-in-the-loop approval workflows, multi-agent trust boundaries, and memory isolation
-
Lead Model Context Protocol (MCP) security initiatives: server trust validation, authorization boundaries, capability restrictions, context/input sanitization, and secure tool sandboxing
-
Drive Security Testing for Agentic AI Systems — including SAST, DAST, and SCA adapted to AI/agentic architectures — across the CI/CD pipeline
Model & Data Security
-
Secure fine-tuning pipelines (SFT, LoRA, QLoRA, PEFT) against dataset/label poisoning, backdoors, and malicious training data
-
Mitigate model-level risks: model theft, model extraction, membership inference, model inversion, and weight tampering
-
Define secure practices for model serving platforms (vLLM, Ollama, TGI) including access control and runtime hardening
Vector Database & Infrastructure Security
-
Establish security standards for vector databases (Qdrant, Pinecone, Weaviate, Milvus, Chroma) — encryption, tenant/namespace isolation, metadata filtering, access control, index poisoning prevention, and secure deletion/retention policies
-
Secure the broader AI attack surface: APIs, agent memory, browsers, code execution sandboxes, databases, and third-party/external service integrations
Governance & Compliance
-
Implement auditability, explainability, and policy enforcement mechanisms across AI systems
-
Support regulatory and internal audit requirements related to AI risk, data protection, and responsible AI use
-
Produce security assessments, incident reports, and executive-level risk communications
Required Qualification
-
10+ years in security engineering, with 3+ years in a technical leadership or management role
-
Demonstrated hands-on experience securing LLM-based applications, RAG systems, and/or AI agents in production
-
Strong understanding of transformer architecture, attention mechanisms, tokens, context windows, embeddings, and semantic search
-
Practical experience with fine-tuning methods (SFT, LoRA, QLoRA, PEFT) and their associated security risks
-
Familiarity with model serving frameworks (vLLM, Ollama, TGI) and vector databases (Pinecone, Qdrant, Weaviate, Milvus, Chroma)
-
Experience implementing SAST, DAST, and SCA tooling, ideally extended or adapted for agentic/AI-specific attack surfaces
-
Working knowledge of MCP (Model Context Protocol) or comparable agent-tool communication standards
-
Strong software engineering fundamentals and secure SDLC experience
Excellent communication skills, able to translate technical AI risk into business and governance language
-
Preferred Qualification:
-
Prior experience in AI red-teaming, adversarial ML, or AI governance/compliance functions
-
Contributions to AI security frameworks, open-source tooling, or published research
-
Relevant certifications (e.g., OSCP, CISSP, GIAC) plus applied AI/ML security experience
-
Experience building AI security practices from the ground up in a fast-moving org
About Our Culture:
EC-Council is driven by a mission to strengthen global cybersecurity capability and advance the profession of ethical hacking and information security. Our teams operate across regions and cultures, united by integrity, professionalism, and a commitment to meaningful impact. Continuous learning and accountability are encouraged, empowering individuals to take ownership of their contributions. Respect, trust, and ethical conduct guide how we work with colleagues, partners, and the global cybersecurity community.
Additional Information:
EC-Council is an equal opportunity workplace and an affirmative action employer. We are committed to providing equal employment opportunities regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity, or veteran status. We do not discriminate based on these or any other characteristics protected by applicable laws or regulations in the locations where we operate.
EC-Council is dedicated to working with and providing reasonable accommodations to individuals with disabilities. If you have a medical condition or disability that limits your ability to complete any part of the application process and require reasonable accommodation, please contact us at
[email protected] and let us know how we can assist.
To be eligible for this position, candidates must be able to provide proof that they are either a citizen of the country or have legal authorization to work in the country where the position is posted and are currently residing there. EC-Council does not offer employment to ineligible candidates and reserves the right to revoke employment in case the candidate loses the authorization to work.
If, as part of the recruitment process, you are required to complete or submit any form of work, project, case study, or assignment, please note that such material will be considered the exclusive property of EC-Council. By submitting such work, you acknowledge that EC-Council retains all rights, title, and interest in the submitted content, including any intellectual property contained therein.
Candidates further waive any intellectual property or moral rights in such submissions, confirm that the work is original and free of third-party infringement, and acknowledge that it is provided solely for evaluation purposes, with no ownership or other rights retained.
Our Privacy Policy outlines how we collect, use, store, and protect your personal data during the recruitment process. This may include information such as your name, contact details, employment history, qualifications, and any other details you provide as part of your application. All data is handled in compliance with applicable data protection and privacy regulations.
Please review our policy here: EC-Council Privacy Policy – User and Company | EC-Council. Submission of your application will be considered as your acceptance of the terms stated above.