Ntt Data Aivista Principal Security Engineer at NTT DATA AIVista owning security for AI products, cloud environments, and compliance programs. Responsible for architecture, threat modeling, and security engineering.
Responsibilities
Product & AI Security
Lead secure design reviews and threat modeling for our AI products, including agentic and multi-agent systems, identifying risks that don’t map to existing frameworks.
Define security architecture and secure-by-design standards for AI agents, tool use, sandboxing, and delegated-credential and identity boundaries.
Partner with Engineering and the CTO organization to embed security into the product and development lifecycle (secure SDLC, code review, dependency and supply-chain security).
Build or introduce security tooling and guardrails that let product security scale with the business.
Cloud & Infrastructure Security
Own cloud security architecture and posture across AWS, Azure, and/or Google Cloud Platform — IAM design, network security, secure baselines, logging, monitoring, and vulnerability management.
Define the security standards that IT and DevOps implement and operate against.
Lead threat detection, posture management, and remediation prioritization across cloud environments.
Security Program & Compliance
Own the company security program, roadmap, risk register, and security policies.
Direct the SOC 2 and ISO 27001 programs — setting the control framework and audit strategy while IT operates day-to-day compliance tooling and evidence collection.
Qualification
10+ years in security engineeringStrong cloud security expertise (AWSExcellent communication skillsExperience at a technology
Required
10+ years in security engineering, with deep expertise in application/product security and cloud security.
Hands-on experience leading threat modeling and secure design reviews for complex, distributed systems.
Strong cloud security expertise (AWS, Azure, or Google Cloud Platform): IAM, network security, secure baselines, logging/monitoring, and vulnerability management.
Experience securing AI/ML or agentic systems, or clear ability to reason about novel threat models (sandboxing, delegated credentials, untrusted tool/output boundaries, prompt/agent abuse).
Working ownership of security compliance programs (SOC 2, ISO 27001) and the ability to direct auditors and compliance tooling (e.g., Vanta).
Experience owning incident response and security risk management.
Excellent communication skills, with the ability to influence engineering, executives, customers, and auditors.
Comfortable operating as a hands-on solo owner in a fast-paced startup, with the ambition and ability to build and lead a team.
Experience at a technology, AI, or enterprise-software company serving regulated industries is preferred.