Overview
Design, implement, and review security controls and architecture patterns for AI, machine learning, and generative AI solutions across State Street’s technology environment. Partner with engineering, product security, platform, data, and security teams to support secure and responsible AI delivery.
What you'll do
- Contribute to secure architecture patterns for AI/ML and Generative AI systems, including data pipelines, model access, and AI-enabled applications.
- Support the development and documentation of AI security standards, reference architectures, and guardrails.
- Participate in architecture and design reviews for AI-related initiatives under senior architect direction.
- Partner with engineering teams to consider security requirements early in solution design.
- Perform AI-focused threat modeling for AI services, models, and data flows.
- Identify security risks including data leakage, prompt injection, insecure model access, OSS vulnerabilities, and misuse scenarios.
- Recommend mitigations and compensating controls with senior architects and security partners.
- Support integration of AI security controls into software development and DevSecOps workflows.
- Assist in defining security requirements and validation checks for AI pipelines and platforms.
- Help develop repeatable patterns and templates for secure AI adoption.
- Assist with security reviews for emerging AI capabilities, including GenAI tools, internal AI services, and developer productivity use cases.
- Research AI security trends, tooling, and common risk patterns and share internal knowledge.
- Contribute ideas and observations to improve AI security practices across the organization.
- Ensure AI security designs align with internal policies and external standards, including NIST, ISO, and FFIEC concepts.
- Support audit, risk, and compliance efforts by documenting architecture decisions and controls.
- Participate in post-incident reviews and action tracking for AI-related security events.
- Work with security engineering, product security, platform, and data teams to resolve AI security concerns.
- Communicate technical risks and recommendations clearly to engineering audiences.
- Escalate complex or high-risk issues to senior architects with supporting analysis and options.
What you'll need
- Bachelor’s degree in Computer Science, Information Security, Engineering, or a related field.
- 5–7 years of experience in application security, product security, cloud security, or security engineering roles.
- Experience securing cloud-native applications or platforms in an enterprise environment.
- Exposure to AI/ML or data-driven systems, including model usage, APIs, or analytics platforms.
- Familiarity with secure software development practices and DevSecOps concepts.
- Solid technical fundamentals in security architecture and secure design.
- Curiosity and willingness to learn in a rapidly evolving AI security landscape.
- Ability to break down risks and communicate them clearly to engineers.
- Collaborative, execution-focused mindset.
- Comfort working with guidance while progressively taking on more responsibility.
Nice to have
- Relevant security or cloud certifications.
- Experience working in or with regulated environments.
Details
- Location: Bangalore, India.
Read the full description and apply on the company’s own careers page.