AI Security Engineer
Also posted as: AI Security Engineer · LLM Security Engineer · AI Red Team Engineer · AI Cybersecurity Engineer · LLM Red Teaming Lead · AI Offensive Security Specialist · AI Security Architect · Responsible AI Security Engineer
An AI Security Engineer in India secures the AI other teams are shipping: building guardrail and detector libraries in front of LLM endpoints, threat-modelling RAG pipelines and agent tool permissions, running adversarial tests before a model reaches production, and writing the AI governance controls (OWASP LLM Top 10, MITRE ATLAS, NIST AI RMF, ISO 42001) an audit will ask for. The buyers are enterprises and BFSI GCCs — Cognizant, Infosys, Wipro and Deloitte on the services side, HSBC, Societe Generale GSC, HDFC Bank, TransUnion, Danaher and Qualys in-house — with Bengaluru taking 12 of the 22 job postings behind this page; red teaming is one capability inside this job rather than the job itself, because only 4 of those 22 postings are predominantly offensive AI work and two of them never name the end client. It is also closed to freshers: not one posting in this sample is open at 0-2 years, the lowest bars are Thales and SIXT at 3-5, the mode is 5-10+ and HDFC Bank asks for 18+, so this is a move made by someone already doing security, or already doing AI/ML and willing to learn the attack surface.
- Across 92 AI Security Engineer job postings in India, the most-requested capabilities are Secure keys, auth and data in AI apps (98%), Apply guardrails, safety and privacy controls (90%) and Explain how LLMs work and where they fail (79%).
- Pay at 5+ yrs averages about ₹15.7 LPA (based on Security Engineer pay · verified across 3 salary sites: AmbitionBox, Glassdoor, PayScale); employers offer ₹12–21 LPA (median of 8 job postings that state pay, 5+ yrs · Naukri, other sites, LinkedIn).
- At least 88 open roles in India — the dated job postings for this role we read in the last 60 days; portals count a title's exact phrase, which undercounts a job posted under many titles, checked 02-10-2026.
- Hiring is concentrated in Bengaluru, Hyderabad and Delhi NCR.
- Postings read from LinkedIn 96% and other portals 4% — one portal supplies most of this sample, so the shares lean to the employers that post there.
Hire for this role? Add your read to this page — what decides the offer, what it closes at. An email to Ajeet, ten minutes, credited or not as you choose. How that read is shown.
Capabilities employers ask for
How often employers ask for each capability, measured across the job descriptions behind this page. Click one to see what "knowing it" means, how to learn it, and how to prove it.
Have a posting open? Check it against this map →
Secure keys, auth and data in AI apps
Strip away the AI vocabulary and this is application and cloud security pointed at a model endpoint. Wipro runs design reviews 'covering IAM, API permissions, data flows, prompt governance, and logging', Danaher engineers 'model access controls, prompt handling, RAG pipelines, tool/agent permissions', and TransUnion keeps security postures tight across AWS and GCP. You must be able to threat-model an AI feature end to end: who can call it, what credentials it holds, where the data goes and what the logs prove.
Explore 3 practice tools →Apply guardrails, safety and privacy controls
This is the centre of the job, not a side quest: Cognizant, Qualys, Meesho and Deloitte all name prompt injection and jailbreak testing, HSBC wants jailbreak defence built into its guardrails, and J.S. Held threat-models 'prompt injection, model abuse, data leakage, RAG poisoning'. Infosys asks you to help design 'guardrail components, safety filters, validation controls' rather than just file findings. You must be able to break a model with direct and indirect injection, then build the filter that stops it.
Explore 3 practice tools →Explain how LLMs work and where they fail
You cannot defend a stack you cannot explain. Societe Generale wants you to assess 'GenAI applications, LLM integrations, AI agents, RAG architectures' in one breath, Thales asks for 'deep knowledge in LLM/transformer architecture and fine-tuning', and HDFC Bank's red-team lead is expected to know LLM vulnerabilities and agentic architectures first-hand. Be able to say why a model followed the injected instruction, what a context window holds, and what an agent does the moment it calls a tool.
Explore 4 practice tools →Write production-quality Python for AI work
Python here is for building attack tooling and automation, not notebooks. Danaher wants 'proficiency in Python for building security automation and integrations (including SIEM/SOAR)', Alter Domus asks for hands-on AI/ML development in Python with LangChain or LlamaIndex, and Alter Domus and Infosys want adversarial testing frameworks and scripts you write yourself. You should be able to script a fuzzing run against an LLM endpoint, parse the results and wire them into the tools the security team already uses.
Explore 4 practice tools →Apply responsible-AI and data-protection basics
Somebody will audit this work, and the postings say against what. Wipro, Aurigo, Alter Domus and Deloitte name NIST AI RMF alongside ISO 42001 or the EU AI Act, SIXT wants usage kept aligned with 'the EU AI Act, GDPR', and Alvarez & Marsal routes findings into AI risk registers. Know the main frameworks well enough to map a finding to a control and write it up as a risk with an owner.
Explore 3 practice tools →Build a grounded RAG application with citations
RAG is a thing you will be asked to attack again and again, so you need to know it from the inside. TransUnion threat-models 'LLM architectures, RAG pipelines, and agentic workflows', o9 Solutions runs 'RAG pipeline poisoning' engagements, HCLTech wants 'grounding integrity, retrieval controls, source trust', and Alter Domus expects LangChain or LlamaIndex hands-on. Build one yourself, then show how a poisoned document or an over-broad retriever leaks what it should not.
Explore 5 practice tools →Integrate LLM APIs into an application
You will call models yourself, not just guard other people's calls. Aurigo, Alter Domus and J.S. Held name the OpenAI, Anthropic and Gemini APIs, Deloitte works on Azure OpenAI, and Deutsche Börse wants experience 'integrating AI/LLM APIs (e.g., OpenAI, Claude, LangChain) into engineering workflows'. You should be able to wire a model into a small tool of your own, because that is how you learn where the request can be tampered with.
Explore 4 practice tools →Automate builds, tests and deploys with CI/CD
Controls that live in a policy document get skipped; the postings want them in the pipeline. Societe Generale wants AI security validation inside 'SDLC, DevSecOps, CI/CD, SAST, DAST', Deloitte embeds 'security checks, policy validation, secrets handling into CI/CD pipelines', and EY wants testing and governance controls integrated there too. Be able to add a stage that runs your injection tests and blocks the deploy when they fail.
Explore 3 practice tools →Communicate AI trade-offs to stakeholders
Plenty of these seats are assessment and governance work, where a finding nobody acts on is wasted. HDFC Bank, Wipro, PayPal and Google all list communication and presentation, and EXL's GenAI governance role is a senior manager seat that lives on it. You must be able to write a finding as a business risk with severity and a fix, and defend it in a room that would rather ship.
Explore 3 practice tools →Expose and consume tools via MCP
MCP shows up as the newest attack surface in the role. Alter Domus wants 'MCP gateway integrations to prevent unauthorized tool invocation, privilege escalation', Cargill wants security controls for MCP and similar agent patterns, and RealPage asks for 'secure deployment, authentication, authorization, and monitoring' of MCP integrations. Be able to stand up an MCP server, then show how a tool can be abused and how an allowlist stops it.
Explore 3 practice tools →Build an LLM evaluation harness
The better seats want attacks rerun as a harness, not a one-off pentest. RealPage names PyRIT and Promptfoo, Data Security Council of India wants 'evaluation pipelines using open-source frameworks and custom Python tooling', and Ecolab asks for LangSmith, TruLens or DeepEval. Be able to turn a pile of jailbreaks into a scored regression suite that runs again after every model or prompt change.
Explore 4 practice tools →Use managed AI platforms (Bedrock / Vertex / Azure AI Foundry)
When the work runs on a hyperscaler, it runs on that vendor's AI stack and its built-in controls. Deloitte names Bedrock and SageMaker, Cognizant and TE Connectivity want Bedrock Guardrails alongside Azure AI Foundry, Systems Limited names 'Azure AI Foundry Prompt Shields' and Vertex AI safety controls, and Xerox wants Bedrock security best practices championed. Know what each platform's native guardrails and access controls do, and where they stop.
Explore 3 practice tools →Trace, monitor and debug LLM apps in production
A smaller group wants the AI stack watched, not only hardened. HSBC asks for 'telemetry, tracing, dashboards, audit trails' around its guardrails, United Airlines wants agents secured on Bedrock AgentCore including its observability, and EXL and Ecolab name LangSmith. Be able to trace a request through prompt, retrieval and tool calls, and spot the one that looks like an attack.
Explore 4 practice tools →Evaluate and harden agents
No posting in this sample names agent evaluation outright except RealPage, which wants 'agent evaluation frameworks, guardrails, prompt/version management'. The nearest asks are all about agents misbehaving: Alter Domus wants MCP tool allowlisting, o9 Solutions tests 'agent identity spoofing, and tool-layer exploitation', and AppViewX builds 'controlled attack scenarios against AI agents, MCP servers, tools'. Learn to test what an agent can be talked into doing with the permissions it holds, because that is where this role is heading.
Explore 3 practice tools →Families: Cloud, deployment & production · Evaluation, safety & observability · Product, business & communication · Programming foundations · Retrieval & knowledge systems · LLM application development · Agents & workflows
"AWS" on a JD is not "learn AWS"
The words employers write, translated into what they want you to be able to do for this role.
Skip, for now
- Positioning yourself as an LLM red teamer only — Only 4 of 22 postings are predominantly offensive AI work, and two of those (Jobgether, DJM Tech Solutions) are aggregator or consulting listings that never name the end client. The postings that name a real employer want guardrails, threat modelling and AI-GRC with red teaming as one of your capabilities. Learn to attack, but apply as a builder of defences.
- Adversarial ML research (model inversion, evasion, TextAttack, IBM ART) — Named in 3 of 22 postings - Infosys, Thales and Alter Domus - and only Thales makes it the centre of the role. It is a research track with a maths prerequisite, not the enterprise work that is hiring. Know what data poisoning and model inversion are; do not spend a quarter implementing the attacks.
- Fine-tuning and training your own models — 3 of 22 postings mention fine-tuning at all, and only Thales asks you to build with PyTorch. Every other employer buys the model and hires you to put controls around it - prompt handling, retrieval, tool permissions, output filtering.
- Security certifications before any hands-on AI work — CISSP, CISM, CRISC, CCSP, ISO 27001 and ISO 42001 appear in 5 of 22 postings, always beside an 8-12 year experience bar. They help a CV that already has AI security work on it; on their own they will not move you across, because the technical rounds ask you to break and then fix a live LLM app.
- Kubernetes — Named in 3 of 22 postings (Societe Generale, HSBC, TransUnion) and always inside a longer platform list. Docker appears in 4 and covers the container question. Get an AI service deployed and instrumented on one cloud first.
Break a RAG-and-agent app you built, then ship the guardrails, the test harness and the risk report
Build a small enterprise-style AI app - a RAG assistant over a document set plus an agent with two or three real tools, one of which writes something - and then attack your own system: direct and indirect prompt injection, system-prompt leakage, retrieval-based data exfiltration, vector-store poisoning, and an agent tricked into calling a tool it should not have. Turn the findings into a defensive layer (input and output filters, PII redaction, tool allowlisting with least-privilege scopes, a policy service that can allow, block, redact or escalate) and into a repeatable adversarial test suite mapped to OWASP LLM Top 10 and MITRE ATLAS, running Garak or PyRIT and promptfoo in GitHub Actions so the build fails on a regression. Finish with the artefact these employers actually buy: a threat model and risk report with severity, business impact and remediation, written the way Wipro and HDFC Bank describe it. This is close to a line-by-line rebuild of the Cognizant, Danaher and J.S. Held JDs, which is why it interviews well.
Start from An app you build yourself, then attack against the OWASP Top 10 for LLM Applications
- A written threat model of your own app covering prompt injection, RAG poisoning, data exfiltration and over-privileged agent actions, each mapped to an OWASP LLM Top 10 or MITRE ATLAS entry
- At least six working attacks in the repo, each with a before/after: the payload succeeds against the unguarded build and is blocked, redacted or escalated by the guarded one
- The adversarial suite runs in CI on every commit (Garak or PyRIT plus promptfoo), reports a pass rate, and fails the build when a previously blocked attack gets through again
- The agent's tools are allowlisted and scoped, every model call and tool call is traced with an audit trail, and a short risk report states severity, business impact and remediation for each finding
What the interviews look like
The rounds you'll actually face, in the order they usually come.
- 1
Screening
Recruiter or hiring manager checks the two experience bars these postings are built on: years of security or AI/ML engineering (5-10+ in 20 of 22 postings), and how much of it has touched LLMs, agents or RAG. Have one sentence on an AI system you assessed or defended, plus the frameworks you work to - OWASP LLM Top 10, MITRE ATLAS, NIST AI RMF - because those words are the filter.
- 2
Technical / hands-on
Live or take-home work on a real LLM application: craft a direct and an indirect prompt injection, get data out of a RAG corpus, bypass a naive filter, then write the guardrail that stops it. Expect Python (named in 15 of 22 postings), questions on Garak, PyRIT, LLM Guard or promptfoo, and follow-ups on why regex filtering fails and what an LLM-as-judge detector costs you in latency.
- 3
Architecture / threat model
Threat-model an enterprise AI system on a whiteboard: model endpoints and their IAM, prompt and response handling, retrieval and its poisoning paths, agent tool permissions and blast radius, logging and detection, and where the controls belong in the SDLC. Senior loops (Deloitte, Alter Domus, Meesho, TransUnion) push into least privilege, sandboxing, key management and what you would block versus merely alert on.
- 4
Governance / stakeholder
A conversation with a CISO, risk or Responsible AI lead about mapping controls to NIST AI RMF, ISO 42001, SOC 2, the EU AI Act and India's DPDP obligations, assessing a third-party AI vendor, and telling a delivery team their launch is blocked without stopping the business. BFSI GCCs also check domain comfort and how you write a finding for leadership.
What people ask before choosing this role
Can a fresher get an AI Security Engineer job in India?
Realistically, no — not straight away. Only 1 of the 92 job postings behind this page accept 0–2 years; most want people who have already shipped software or run projects. It is a strong second move rather than a first job.
What is the salary of an AI Security Engineer in India?
Pay at 5+ yrs averages about ₹15.7 LPA (based on Security Engineer pay · verified across 3 salary sites: AmbitionBox, Glassdoor, PayScale); employers offer ₹12–21 LPA (median of 8 job postings that state pay, 5+ yrs · Naukri, other sites, LinkedIn). Not every posting states pay, and pay varies widely by city and by whether the employer is an IT-services firm, a global capability centre or a product startup.
How long does it take to become an AI Security Engineer?
The six capabilities employers ask for most add up to roughly 80 focused hours — about 10 weeks at 8 hours a week, if you are starting from zero on all of them. Most people are not: the self-check on this page works out what you can skip, which is usually a large part of it.
What skills do you need for an AI Security Engineer role?
Across the 92 job postings behind this page, the most-requested capabilities are Secure keys, auth and data in AI apps (98% of postings), Apply guardrails, safety and privacy controls (90% of postings) and Explain how LLMs work and where they fail (79% of postings). Note these are capabilities, not tools — employers write tool names, but what they are buying is the ability to do the work.
Which cities in India post the most AI Security Engineer jobs?
Bengaluru (47), Hyderabad (10), Delhi NCR (9) and Remote (India) (8) — counted across the 92 job postings behind this page. Remote-India roles are counted separately where the posting said so.
Is demand for AI Security Engineer roles in India growing?
AI agents are now the centre of the job: of 23 postings collected in the latest cycle, 16 treat agents (agent identity, tool-calling, MCP) as part of the attack surface and 12 name the OWASP Top 10 for LLMs, with MITRE ATLAS in 8. Hiring stays senior — 63 of the 90 postings on file ask for 5+ years — and is spreading beyond IT services and banks to global firms building AI security teams in India, such as Cencora's AI security centre of excellence and Ford's Chennai team.
Do I need a degree or a paid certificate for this?
Nothing on this page requires a paid certificate, and none of the 92 job postings behind it asked for one by name. What they ask for is evidence you can do the work — a public repo, a deployed project, something a hiring manager can open. That is what the path on this page is built to produce.
Companies with this role open in India
A sample of employers we saw hiring for this role — IT services, global capability centres, product companies and startups. Each links to one of the company's postings for this role, checked open on 04-10-2026; where none is open, to its current openings instead.
What it pays
most earn ₹5–10 LPA (base pay) · based on Security Engineer pay · verified across 3 salary sites: AmbitionBox, Glassdoor, PayScale
based on Security Engineer pay · verified across 3 salary sites: AmbitionBox, Glassdoor, PayScale
based on Security Engineer pay · verified across 3 salary sites: AmbitionBox, Glassdoor, PayScale
Employers offer ₹12–21 LPA: median of 8 job postings that state pay, 5+ yrs · Naukri, other sites, LinkedIn
Across all levels: the middle half earns ₹5.6–17.2 LPA · Glassdoor · Security Engineer pay
How much demand
What each job portal shows for this role's title — the readings behind the openings figure above.
- 3131 of 311 results, read in full, carry the title · checked 04-10-2026naukri
- at least 2828 of the first 1000 results carry the title (reading stopped: cap) · checked 04-10-2026linkedin
- 1313 of 17 results, read in full, carry the title · checked 04-10-2026indeed
- 88dated job postings for this role we read in the last 60 days — the figure above, because no portal's count reached it
Where this role is heading
- AI agents are now the centre of the job: of 23 postings collected in the latest cycle, 16 treat agents (agent identity, tool-calling, MCP) as part of the attack surface and 12 name the OWASP Top 10 for LLMs, with MITRE ATLAS in 8.
- Hiring stays senior — 63 of the 90 postings on file ask for 5+ years — and is spreading beyond IT services and banks to global firms building AI security teams in India, such as Cencora's AI security centre of excellence and Ford's Chennai team.
Capability percentages come from 92 job descriptions read in full on 03-10-2026. How we do this