Lowe's Companies, Inc.

Sr Engineer, Information Security

Lowe's Companies, Inc.  •  Bengaluru, IN (Onsite)  •  2 hours ago
Apply
AI can make mistakes so check important info. Chat history is never stored.

Job Description

Innovate in Bengaluru

This position is based at our on-site office in Bengaluru. Lowe's offers an ultramodern work environment, complete with cutting-edge technology, collaborative workspaces, an on-site gym and clinic, and other perks to enhance your work experience. 

About Lowe’s Lowe’s is a FORTUNE® 100 home improvement company serving approximately 16 million customer transactions a week in the United States. With total fiscal year 2024 sales of more than $83 billion, Lowe’s operates over 1,700 home improvement stores and employs approximately 300,000 associates. Based in Mooresville, N.C., Lowe’s supports the communities it serves through programs focused on creating safe, affordable housing, improving community spaces, helping to develop the next generation of skilled trade experts and providing disaster relief to communities in need. For more information, visit Lowes.com

Lowe’s India, the Global Capability Center of Lowe’s Companies Inc., is a hub for driving our technology, business, analytics, and shared services strategy. Based in Bengaluru with over 4,500 associates, it powers innovations across omnichannel retail, AI/ML, enterprise architecture, supply chain, and customer experience. From supporting and launching homegrown solutions to fostering innovation through its Catalyze platform, Lowe’s India plays a pivotal role in transforming home improvement retail while upholding strong commitment to social impact and sustainability. For more information, visit Lowes India



The primary purpose of this role is to provide Cyber Security for Data and Artifical Intelligence (AI) related security services. This includes providing support for security services and engineering efforts pertaining AI Guardrails, Agentic AI, Data Security Posture Management (DSPM), Enterprise Encryption, and Key Management Solutions.

Core Responsibilities:

  • Serve as a hands-on subject matter expert for AI Security, including AI Guardrails, Agentic AI architectures, Agent-to-Agent (A2A) communications, Model Context Protocol (MCP) security, and AI Security Posture Management (AI-SPM).

  • Design, implement, and continuously improve AI guardrail controls to mitigate prompt injection, data leakage, unauthorized access, policy violations, and unsafe AI behaviors.

  • Analyze and investigate flagged AI security violations, conduct root cause analysis, and develop remediation and risk-reduction strategies.

  • Evaluate and secure Agentic AI ecosystems, including autonomous workflows, tool usage, memory stores, agent permissions, and agent orchestration frameworks.

  • Assess and mitigate risks associated with Agent-to-Agent (A2A) interactions, ensuring secure authentication, authorization, trust establishment, and information exchange between autonomous systems.

  • Define and implement security controls for MCP Servers and AI tool integrations, including identity validation, session management, data access governance, and least-privilege enforcement.

  • Develop and maintain AI Security Posture Management (AI-SPM) capabilities to identify misconfigurations, insecure deployments, exposed models, excessive permissions, and AI-related compliance gaps.

  • Monitor, analyze, and prioritize AI-related threats, vulnerabilities, and attack patterns to assess risk, determine severity, and drive mitigation activities.

  • Partner with SOC, threat intelligence, and incident response teams to investigate emerging AI threats and provide expert consultation on AI-related security events.

  • Conduct technical evaluations, proof-of-concepts, and security assessments of emerging AI technologies, frameworks, models, agents, and supporting infrastructure.

  • Perform threat modeling and security architecture reviews for AI applications, agentic workflows, retrieval-augmented systems, MCP services, and third-party AI platforms.

  • Lead engineering efforts to integrate enterprise AI security solutions, including AI governance, AI-SPM, model protection, prompt security, and AI runtime monitoring capabilities.

  • Resolve complex AI security engineering challenges spanning multiple platforms, applications, agents, and cloud environments to improve overall enterprise AI security posture.

  • Respond to escalated AI security incidents and engineering issues, providing technical leadership, troubleshooting, and strategic guidance.

  • Serve as the primary AI security engineering resource for project teams, contributing to AI security standards, reference architectures, governance models, procedures, and secure development practices.

  • Collaborate with business, engineering, and architecture teams to establish secure-by-design principles for AI systems and accelerate the safe adoption of generative and agentic AI capabilities.

Years of Experience:

  • Overall, 5 years of experience in IT, Software engineering or relative field.

  • 3-5 years Information Security experience (or combination of Information Security and Application Development)

Education Qualification & Certifications

Required Minimum Qualifications

  • Bachelors Degree in Computer Science, CIS, Engineering, Cybersecurity, or related field (or equivalent work experience in a related field)

  • Relevant information security certifications (e.g. CISSP, CISM, CEH, GPen)

Primary Skills (must have)

  • Advanced understanding of information security practices and policies

  • Experience working with an IT Infrastructure Library (ITIL) framework

  • Experience in securing retail eCommerce platforms

  • Working knowledge of AI Guardrail policy and best practices

  • Working knowledge of Agent-to-Agent and Model Context Protocol Server security controls

  • Experience in delivering security product deployments, integrations, and operational efforts

  • Experience facilitating vendor security product requests for engineering requirements, enhancements, maintenance, and configuration

Secondary Skills (desired)

  • Knowledge of security controls for data at rest

  • Experience implementing policy and classification controls for DSPM solutions

  • Knowledge of retail regulatory scope (PCI, SOX, etc.)

  • Familiarity with OWASP Top 10 and/or SANS Top 25

  • Familiarity with one or more of the following development languages: Java, Python, JavaScript/Node.js, GO, PHP


Lowe's is an equal opportunity employer and administers all personnel practices without regard to race, color, religious creed, sex, gender, age, ancestry, national origin, mental or physical disability or medical condition, sexual orientation, gender identity or expression, marital status, military or veteran status, genetic information, or any other category protected under federal, state, or local law.

Lowe's Companies, Inc.

About Lowe's Companies, Inc.

Lowe’s Companies, Inc. (NYSE: LOW) is a FORTUNE® 50 home improvement company serving approximately 20 million customers a week in the United States. Lowe’s and its related businesses operate or service more than 2,200 home improvement and hardware stores and employ over 300,000 associates. Based in Mooresville, N.C., Lowe’s supports the communities it serves through programs focused on creating safe, affordable housing and helping to develop the next generation of skilled trade experts. For more information, visit Lowes.com.

Industry
Retail & Ecommerce
Company Size
10,000+ employees
Headquarters
Mooresville, NC
Year Founded
1921
Website
lowes.com
Social Media