Are you looking to join an organization that is growing and dynamic? What about a high-energy, collaborative environment that rewards hard work? J.S. Held is a global consulting firm that combines technical, scientific, financial, and strategic expertise to advise clients seeking to realize value and mitigate risk. Our professionals serve as trusted advisors to organizations facing high stakes matters demanding urgent attention, staunch integrity, proven experience, clear-cut analysis, and an understanding of both tangible and intangible assets. The firm provides a comprehensive suite of services, products, and data that enable clients to navigate complex, contentious, and often catastrophic situations. Role Summary Based in the Delhi NCR region in a hybrid work model, the Sr. AI & Application Security Specialist will be a founding member of J.S. Held’s AI & Application Security function, helping shape the strategy, standards, and security practices that enable the safe adoption of AI across the organization. This hands-on role focuses on securing AI-enabled applications, agents, RAG architectures, MCP/tool integrations, models, APIs, and cloud services. Working closely with the Senior Application Security Specialist, the successful candidate will help build and scale a modern AI security program while driving day-to-day AI security initiatives, risk management, and technical guardrails to ensure compliance with legal, regulatory, and organizational requirements. Role Details Role focus: approximately 70% AI Security and 30% Application Security Core Responsibilities Develop and maintain the enterprise AI Security Program. Establish AI security policies, standards, control frameworks, and security processes. Lead AI Security execution across standards, architecture principles, risk framework, inventory expectations, and business-aligned security requirements. Review AI solutions before deployment, including AI-enabled applications, agents, RAG pipelines, APIs, MCP/tool integrations, model workflows, and third-party AI services. Perform AI threat modeling for prompt injection, model abuse, data leakage, RAG poisoning, agent misuse, unsafe tool calls, model extraction, and AI supply-chain risk. Define practical controls for AI identity, delegated authorization, agent lifecycle, tool permissions, least privilege, revocation, and auditability. Secure agentic workflows, including agent-to-agent interactions, MCP servers, autonomous workflows, tool integrations, and SharePoint-grounded AI use cases. Help define runtime guardrails, including prompt/content controls, tool restrictions, behavioral monitoring, runtime enforcement, and escalation paths. Lead or coordinate AI security testing and red teaming for priority AI systems, agents, models, workflows, and integrations. Define AI logging, monitoring, detection use cases, SecOps handoffs, and AI-specific incident response procedures. Review model provenance, model hosting platforms, open-source models, dependencies, plugins, and third-party AI services for security and governance risk. Support AI governance, risk, and compliance activities, including AI policies, risk classification, inventory requirements, evidence needs, and alignment with NIST AI RMF. Help identify shadow AI, unmanaged agents, risky connectors, overshared knowledge sources, and other exposure paths, then drive practical remediation with owners. Partner with the Senior Application Security Specialist on Application Security reviews, secure SDLC, architecture reviews, code reviews, API reviews, deployment reviews, and design approvals. Serve as the Senior Application Security Specialist’s backup when they are out of office or when AppSec demand requires additional coverage. Evaluate SaaS applications for secure configuration, identity access settings, risky integrations, excessive permissions, and secure-by-design implementation. Review APIs for authentication, authorization, input validation, data exposure, logging, rate limiting, and secure integration patterns. Support software composition analysis, dependency review, secrets scanning, code scanning, vulnerability triage, remediation tracking, and risk-based vulnerability management. Educate developers, architects, IT, cyber teams, and business stakeholders on secure AI design, Application Security expectations, and safe AI adoption. Required Qualifications 8+ years of cybersecurity engineering experience with meaningful Application Security experience. Recent hands-on experience securing generative AI, LLM-based systems, AI agents, AI-enabled SaaS, or internal AI applications. Strong understanding of secure application/API design, IAM, cloud security, SaaS security, software supply chain risk, and secure SDLC practices. Experience with vulnerability management, application security reviews, dependency risk, and practical remediation tracking. Ability to convert AI and Application Security risk into deployable controls, clear standards, and practical engineering guidance. Strong communication skills with engineering, IT, cyber, GRC, and business stakeholders. Preferred Qualifications Experience with Azure AI Foundry, Copilot Studio, Microsoft Copilot administration, Anthropic, OpenAI, or similar AI platforms. Familiarity with vector databases, embeddings, model hosting, LLM gateways, MCP, RAG architectures, and agentic workflows. Experience with AI red teaming, AI posture management, runtime guardrails, model security, AI observability, or shadow AI discovery. Familiarity with AppSec tooling and practices such as SAST, DAST, SCA, secrets scanning, API testing, code review, and dependency governance. Scripting or automation experience such as Python or PowerShell Required Skills AI threat modeling RAG security Agent security MCP security AI identity and delegated authorization AI security frameworks Application Security reviews API security Secure SaaS configuration review Secure SDLC and architecture review Software composition analysis and dependency risk review Vulnerability management and remediation tracking Cloud security, Azure preferred Detection and incident response Governance, including NIST AI RMF We welcome applications from individuals with disabilities. If you are an individual with a disability and would like to request a reasonable adjustment in relation to any of the above, please email [email protected] and include “Applicant Adjustment” within the subject line with your request and contact information. Some of the Benefits We Have Include J.S. Held understands all of our employees are people and sometimes life needs flexibility. We work to always provide an environment that best supports and suits our team’s needs. Our flexible work environment allows employees to work remotely when needed Generous Annual Leave Policy Comprehensive Medical Insurance Other Duties Please note this job description is not designed to cover or contain a comprehensive listing of activities, duties, or responsibilities required of the employee for this job. Duties, responsibilities, and activities may change at any time with or without notice. By submitting your application, you acknowledge that you have read the J.S. Held Online Privacy Notice and hereby freely and unambiguously give informed consent to the collection, processing, use, and storage of your personal information as required and described therein. Please explore what we’re all about at www.jsheld.com. EEO and Job Accommodations We embrace diversity and our commitment to building a team and environment that fosters professional and personal enrichment is unwavering. We are greater when we are equal! J.S. Held is an equal opportunity employer that is committed to hiring a diverse workforce. All qualified applicants will receive consideration for employment without regard to sex, gender identity, sexual orientation, race, color, religion, national origin, disability, protected Veteran status, age, or any other characteristic protected by law. #LI-SC1
Senior Security Specialist
Nokia
Cybersecurity Specialist
Bceglobaltech
Solutions Delivery Specialist - HPE Nonstop Security
Partner One Capital
Associate - Product Security Specialist
Tiaa
Automotive Cyber Security Specialist (6- 10 Years)
Veoneer Safety Systems, India
Cyber Security Specialist
Mhymatch