Job Title: Member of Technical Staff – Information Security
Location: Chennai, India | Work from office
SurveySparrow is looking for an Information Security professional with 3–6 years of experience to strengthen application security while helping secure our growing use of LLMs, RAG pipelines, AI-assisted development, and autonomous agents.
-
Application Security: Conduct security assessments of web applications, APIs, and mobile applications using manual and automated techniques, with strong knowledge of OWASP Top 10 and secure coding practices.
-
AI & LLM Security: Threat-model and assess AI applications for prompt injection, jailbreaks, data leakage, insecure outputs, hallucinations, and guardrail bypasses using frameworks such as OWASP LLM Top 10 and MITRE ATLAS.
-
Agent & MCP Security: Secure AI agents, tools, connectors, and MCP servers through least privilege, credential protection, approval controls, and auditability.
-
AI-Assisted Development Security: Build controls around AI-generated code, including secret leakage, insecure coding patterns, dependency/model supply-chain risks, and code provenance.
-
Security Automation with AI: Build AI-assisted solutions for security triage, false-positive reduction, secure code review, evidence collection, and customer security questionnaires.
-
Security Testing & Tooling: Work with SAST, DAST, IAST, Burp Suite and similar tools, while developing AI-specific testing and model red-teaming capabilities.
-
CI/CD Security: Implement automated security checks and security gates across development and deployment pipelines, including AI-generated code.
-
Vulnerability Management: Demonstrate proof of concept for vulnerabilities, work closely with engineering teams on remediation, and verify fixes before closure.
-
Compliance & Risk: Support ISO 27001 and SOC 2 Type 2 audits and extend security controls for AI systems, considering ISO 42001, NIST AI RMF, EU AI Act, GDPR, HIPAA and DPDPA.
-
Third-Party & AI Vendor Risk: Assess AI vendors, model providers and subprocessors for data retention, training usage, residency, isolation, and security controls.
-
Customer & Stakeholder Security: Handle enterprise security reviews, RFP/RFQ security requirements, audits, and AI-specific customer security questions.
-
Security Culture & Collaboration: Maintain security policies and documentation, conduct security awareness programs, and collaborate with Development, QA, Infrastructure and Legal to embed security throughout the lifecycle.
-
Education: Bachelor's degree in Computer Science or related field.
-
Experience: 3–6 years in Information Security, Application Security, vulnerability management, and security assessments.
-
AI Security: Hands-on exposure to securing or attacking LLM applications, RAG pipelines, or AI agents through professional work, research, CTFs, bug bounty, or open source.
-
Technical Skills: Ability to read code in Ruby, Java, Swift and JavaScript; Python for security tooling; AWS security; Jenkins/CI-CD.
-
Certifications: CISSP, CISA, CISM, CEH, OSCP or ISO 27001 certifications are a plus, but not mandatory.
-
Nice to have: AI red teaming, MCP/agent frameworks, LLM security automation, evaluation frameworks, and experience taking AI products through enterprise security reviews.