Director, Security Engineering - AI
Pune Division, Maharashtra, India · Full Time
Be the first to apply
- Experience
- 12+ yrs
- Salary
- —
- Openings
- 1
- Posted
- 16 hours ago
- Work mode
- In office
- Education
- Bachelor's degree in cybersecurity, IT, computer science, engineering, or related field
- Resume
- Required to apply
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
About Cencora and Role Overview
Cencora is dedicated to fostering healthier futures, impacting lives of people and animals globally. We value our team as central to our success. The Director, AI Security position based in Pune will spearhead our India-based AI security engineering and enablement functions, safeguarding the enterprise usage of AI technologies such as generative AI, large language models, machine learning platforms, AI-infused SaaS products, and AI-integrated business workflows.
This role reports to the U.S.-based Senior Director of Data & AI Security and works alongside the India-based Senior Director of Endpoint & Infrastructure Security, focusing on turning global AI security strategies into tangible engineering solutions, control systems, and governance initiatives. It emphasizes security while enabling AI innovation, dealing with challenges like data leakage, prompt injection attacks, model misuse, insecure integrations, shadow AI, agentic workflow threats, and intellectual property risks. The position establishes the India center as a leading global hub for AI security expertise and operations.
Key Responsibilities
- Convert the broader Data & AI Security enterprise strategy into actionable plans, roadmaps, and measurable targets for the India team.
- Design and implement security controls protecting proprietary models, third-party AI tools, SaaS AI features, copilots, retrieval-augmented generation (RAG), agentic workflows, and AI-driven automation.
- Develop pragmatic AI security patterns that protect sensitive and regulated data, credentials, and intellectual property without hindering innovation.
- Oversee AI security architecture encompassing AI platforms, cloud services, model APIs, data pipelines, and AI-enabled applications.
- Create and sustain secure design frameworks for generative AI platforms, LLMs, vector databases, AI agents, prompt handling, and human-in-the-loop mechanisms ensuring confidentiality, integrity, availability, privacy, auditability, resilience, and abuse prevention.
- Define and operationalize controls against risks like prompt injections, data leaks, model abuse, insecure integrations, unauthorized access via connectors or RAG, unsafe automations, shadow AI, insecure model supply chains, and IP exposure.
- Collaborate with risk management, legal, privacy, and compliance teams to ensure AI controls are enforceable and measurable.
- Partner with Data Security and Privacy teams on classification, data minimization, residency, DLP, encryption, key management, entitlement reviews, retention policies, training, and governance of RAG corpus to prevent uncontrolled data replication outside enterprise governance.
- Coordinate with Endpoint & Infrastructure Security leaders to integrate AI security requirements into endpoint, browser, infrastructure, developer tools, and collaboration platforms.
- Enable secure access management for AI tools across managed/unmanaged endpoints, include endpoint DLP, device posture, conditional access, developer workstation protections, secrets security, AI workload hosting, and AI telemetry.
- Establish AI security enablement practices including intake processes, risk tiering, assessment templates, tool guardrails, shadow AI detection, production readiness checks, and exception procedures.
- Lead or facilitate AI security testing including prompt injection, data leakage, authorization bypass, connector misuse, insecure agent behaviors, privilege escalation, adversarial inputs, and AI-generated code risks; partner with app security, red teams, and model risk management.
- Work with cyber defense and SOC teams to set up AI telemetry, monitoring, incident response protocols for AI usage, high-risk prompt/response activity, sensitive data handling, agent behavior, and shadow AI indicators.
- Build, manage, and grow a India-based AI security team covering architecture, engineering, assurance, governance enablement, and program management.
- Develop leadership pipelines and career paths within AI security architecture, cloud/platform security, application/API security, AI security testing, and automation.
Qualifications and Experience
- Minimum of 12 years in cybersecurity, application/data security, cloud or infrastructure security, AI/ML security, or related technology risk fields.
- At least 5 years in leadership roles managing technical cybersecurity or security engineering teams.
- Comprehensive knowledge of generative AI, machine learning platforms, AI-enabled SaaS, APIs, data pipelines, cloud platforms, and enterprise app architectures.
- Experience establishing security controls for emerging or high-risk technology platforms.
- Expertise in data protection, identity management, endpoint security, cloud security, application and infrastructure security, and cyber defense.
- Proven capacity to convert emerging technology risks into actionable architectural and engineering solutions.
- Capability to lead diverse teams across multiple geographies and cultures with strong communication skills at an executive level.
Preferred Expertise:
- Hands-on experience securing enterprise AI ecosystems including generative AI, large language models, RAG systems, vector databases, AI agents, copilots, model APIs, AI gateways, and prompt security.
- Background in regulated sectors such as healthcare, pharmaceuticals, or financial services.
- Familiarity with AI governance, model risk management, privacy engineering, and responsible AI initiatives.
- Knowledge of security frameworks: OWASP Top 10 for LLM, MITRE ATLAS, NIST AI RMF, ISO 27001, NIST CSF, HITRUST.
- Experience with cloud AI environments in Azure, AWS, or Google Cloud Platform.
- Track record of establishing new security capabilities or global security centers in India.
Education & Certifications
Bachelor’s degree in cybersecurity, IT, computer science, engineering, or related fields required; Master’s degree preferred. Certifications in cybersecurity, cloud security, or risk management are desirable.
Additional Information
Benefit plans may vary by country and will be aligned to local market practices. Eligibility and start dates may differ for employees under collective bargaining agreements.
Equal Employment Opportunity: Cencora is an equal opportunity employer committed to diversity and prohibits discrimination or harassment based on legally protected classes. Reasonable accommodations for applicants with disabilities will be provided upon request.
Contact for accommodation requests is available. Communications unrelated to accommodation requests will not be answered.
Minimum education
Bachelor's Degree