NTT DATA

Enterprise Security Architect - Agentic AI Platform Security

NTT DATA  •  Bengaluru, IN (Onsite)  •  2 hours ago
Apply
AI can make mistakes so check important info. Chat history is never stored.

Job Description

Req ID: 390592

NTT DATA strives to hire exceptional, innovative and passionate individuals who want to grow with us. If you want to be part of an inclusive, adaptable, and forward-thinking organization, apply now.

We are currently seeking a Enterprise Security Architect - Agentic AI Platform Security to join our team in Bangalore, Karnātaka (IN-KA), India (IN).

About the Role

We are looking for an experienced Enterprise Security Architect who will own the security architecture and risk posture for our Agentic AI platforms — the systems where autonomous or semi-autonomous AI agents plan, reason, invoke tools, and take actions across enterprise environments. This is a senior, hands-on architecture role that sits at the intersection of traditional enterprise security, cloud/application security, and the emerging discipline of AI/LLM security.

You will design the security controls, reference architectures, and governance frameworks that allow the business to deploy agentic AI (LLM agents, multi-agent orchestration, tool-calling/function-calling systems, RAG pipelines, autonomous workflows) safely, at scale, and in compliance with regulatory and internal risk requirements.

Key Responsibilities

Architecture & Design

  • Design end-to-end security architecture for agentic AI platforms, including agent orchestration layers, tool/plugin integrations, model endpoints, memory/context stores, and inter-agent communication.
  • Define reference architectures and security patterns for safe tool use, function calling, plugin sandboxing, and API access by autonomous agents.
  • Establish identity and access models for non-human/agent identities, including scoped credentials, delegated authority, and least-privilege action permissions.
  • Architect guardrails for prompt injection, jailbreaking, data exfiltration, and unauthorized tool invocation across single- and multi-agent systems.
  • Design secure patterns for RAG (retrieval-augmented generation), vector databases, and knowledge base access controls.

Risk & Governance

  • Build threat models specific to agentic AI (e.g., goal hijacking, tool misuse, cascading multi-agent failures, insecure output handling, excessive agency).
  • Define and maintain an AI security risk framework aligned to standards such as OWASP Top 10 for LLM Applications, MITRE ATLAS, NIST AI RMF, and ISO/IEC 42001.
  • Partner with GRC, Legal, and Privacy teams to ensure agentic AI deployments meet regulatory requirements (data residency, model governance, auditability, explainability).
  • Establish approval gates, security review processes, and architecture standards for teams building or integrating agentic systems.

Platform & Operational Security

  • Define monitoring, logging, and observability requirements for agent behavior, tool calls, and decision trails to support detection and forensic investigation.
  • Work with SOC/detection engineering to build detection use cases for anomalous agent behavior (e.g., unexpected tool chains, privilege escalation attempts, data exfiltration patterns).
  • Define incident response playbooks specific to agentic AI incidents.
  • Evaluate and harden CI/CD and MLOps pipelines feeding agentic systems (model supply chain, dependency, and plugin/tool vetting).

Cloud & Network Security

  • Architect secure cloud landing zones and network segmentation for agentic AI workloads, isolating agent runtimes, model endpoints, tool/plugin execution environments, and data stores from broader enterprise networks.
  • Define secure patterns for outbound/inbound agent network calls, including egress control, allow-listing of external tools/APIs, and prevention of unauthorized or unbounded network access by autonomous agents.
  • Establish cloud security controls (IAM policies, VPC/VNet design, security groups, private endpoints, service mesh policies) tailored to multi-tenant AI platforms and agent orchestration layers.
  • Design network-level guardrails to contain agent "blast radius" — e.g., microsegmentation, zero-trust network access (ZTNA), and just-in-time network permissions for agent-initiated actions.
  • Partner with cloud platform and network engineering teams to secure model inference endpoints, API gateways, service-to-service communication (mTLS), and data-in-transit for agent-to-agent and agent-to-tool traffic.
  • Evaluate and harden cloud-native AI/ML services (e.g., SageMaker, Azure AI Foundry, Vertex AI, Bedrock) and their associated networking, storage, and access control configurations.
  • Define DDoS, WAF, and API gateway protections for externally exposed agentic AI services and endpoints.

Leadership & Collaboration

  • Act as the security architecture authority and trusted advisor to AI/ML engineering, platform engineering, product, and data science teams.
  • Review and approve architecture designs for new agentic AI use cases before production deployment.
  • Mentor security engineers and evangelize secure-by-design principles for AI systems across the organization.
  • Represent the organization in industry forums, vendor evaluations, and internal executive briefings on agentic AI risk.

Required Qualifications

  • 10+ years in security architecture, application security, or cloud security roles, including enterprise-scale environments.
  • 3+ years of hands-on experience securing AI/ML or LLM-based systems, with direct exposure to agentic architectures (tool/function calling, multi-agent frameworks, autonomous workflows).
  • Strong understanding of LLM-specific threat models: prompt injection, jailbreaking, insecure output handling, training data poisoning, model extraction, excessive agency, and sensitive information disclosure.
  • Familiarity with agentic AI frameworks and protocols (e.g., LangChain, LangGraph, AutoGen, CrewAI, Model Context Protocol (MCP), OpenAI Assistants/function calling, Semantic Kernel).
  • Deep knowledge of identity and access management, including workload identity, OAuth/OIDC, secrets management, and zero-trust principles as applied to non-human/agent identities.
  • Solid grounding in cloud security architecture (AWS/Azure/GCP), container and Kubernetes security, and API security.
  • Strong network security fundamentals: network segmentation, microsegmentation, firewalls, ZTNA, VPN, private connectivity (PrivateLink/Private Endpoint), and secure API gateway design.
  • Hands-on experience designing cloud landing zones, VPC/VNet architecture, IAM, security groups/NSGs, and service mesh (e.g., Istio) policies for multi-service or multi-agent platforms.
  • Experience securing data-in-transit and service-to-service communication (mTLS, certificate management) across hybrid or multi-cloud environments.
  • Working knowledge of frameworks: OWASP Top 10 for LLM Applications, MITRE ATLAS, NIST AI RMF, ISO/IEC 42001, and relevant data privacy regulations (GDPR, CCPA, etc.).
  • Experience producing architecture artifacts: threat models, data flow diagrams, control matrices, and security design reviews.
  • Strong stakeholder communication skills — able to translate technical AI security risk into business risk for executives and non-technical audiences.

Preferred Qualifications

  • Relevant certifications: CISSP, SABSA, CCSP, or equivalent; cloud certifications (AWS/Azure/GCP Security Specialty) and AI/ML security certifications a plus.
  • Experience with SD-WAN, cloud-native firewalls (e.g., Azure Firewall, AWS Network Firewall, Palo Alto/Cisco), and network detection & response (NDR) tooling.
  • Experience with red-teaming or adversarial testing of LLM/agentic systems.
  • Hands-on experience with vector databases, embedding pipelines, and RAG security controls.
  • Background in MLOps/DevSecOps and securing model training/inference pipelines.
  • Prior experience building or contributing to an enterprise AI governance program.
  • Familiarity with guardrail/evaluation tooling (e.g., Guardrails AI, NeMo Guardrails, Lakera, model evaluation harnesses).

What Success Looks Like in the First 6–12 Months

  • A published enterprise reference architecture and security standard for agentic AI deployments.
  • A threat model and control catalog specific to the organization's agentic AI use cases, reviewed and adopted by engineering teams.
  • Security review and sign-off process integrated into the AI platform's SDLC.
  • At least one detection/monitoring capability live for agentic AI-specific anomalies.
  • Strong working relationships established with AI/ML, platform, GRC, and legal stakeholders.

About NTT DATA

NTT DATA is a $30 billion business and technology services leader, serving 75% of the Fortune Global 100. We are committed to accelerating client success and positively impacting society through responsible innovation. We are one of the world's leading AI and digital infrastructure providers, with unmatched capabilities in enterprise-scale AI, cloud, security, connectivity, data centers and application services. our consulting and Industry solutions help organizations and society move confidently and sustainably into the digital future. As a Global Top Employer, we have experts in more than 50 countries. We also offer clients access to a robust ecosystem of innovation centers as well as established and start-up partners. NTT DATA is a part of NTT Group, which invests over $3 billion each year in R&D.

Whenever possible, we hire locally to NTT DATA offices or client sites. This ensures we can provide timely and effective support tailored to each client’s needs. While many positions offer remote or hybrid work options, these arrangements are subject to change based on client requirements. For employees near an NTT DATA office or client site, in-office attendance may be required for meetings or events, depending on business needs. At NTT DATA, we are committed to staying flexible and meeting the evolving needs of both our clients and employees. NTT DATA recruiters will never ask for payment or banking information and will only use @nttdata.com, @nttdatafed.com and @talent.nttdataservices.com email addresses. If you are requested to provide payment or disclose banking information, please submit a contact us form, https://us.nttdata.com/en/contact-us.

NTT DATA endeavors to make https://us.nttdata.com accessible to any and all users. If you would like to contact us regarding the accessibility of our website or need assistance completing the application process, please contact us at https://us.nttdata.com/en/contact-us. This contact information is for accommodation requests only and cannot be used to inquire about the status of applications. NTT DATA is an equal opportunity employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or protected veteran status. For our EEO Policy Statement, please click here. If you'd like more information on your EEO rights under the law, please click here. For Pay Transparency information, please click here.

NTT DATA

About NTT DATA

NTT DATA – a part of NTT Group – IT and business services headquartered in Tokyo. We help clients transform through consulting, industry solutions, business process services, digital & IT modernization and managed services. NTT DATA enables them, as well as society, to move confidently into the digital future. We are committed to our clients’ long-term success and combine global reach with local client attention to serve them in over 50 countries around the globe.

Industry
IT & Software
Company Size
10,000+ employees
Headquarters
Tokyo, JP
Year Founded
Unknown
Social Media