Enterprise Security Architect - Agentic AI Platform Security
Date: Sep 22, 2026
Company: NTT DATA Services
NTT DATA strives to hire exceptional, innovative and passionate individuals who want to grow with us.
We are currently seeking a Enterprise Security Architect - Agentic AI Platform Security to join our team in Bangalore, Karnātaka (IN-KA), India (IN).
About the Role
We are looking for an experienced Enterprise Security Architect who will own the security architecture and risk posture for our Agentic AI platforms - the systems where autonomous or semi-autonomous AI agents plan, reason, invoke tools, and take actions across enterprise environments. This is a senior, hands-on architecture role that sits at the intersection of traditional enterprise security, cloud/application security, and the emerging discipline of AI/LLM security. You will design the security controls, reference architectures, and governance frameworks that allow the business to deploy agentic AI (LLM agents, multi-agent orchestration, tool-calling/function-calling systems, RAG pipelines, autonomous workflows) safely, at scale, and in compliance with regulatory and internal risk requirements.
Key Responsibilities
Architecture & Design
- Design end-to-end security architecture for agentic AI platforms, including agent orchestration layers, tool/plugin integrations, model endpoints, memory/context stores, and inter-agent communication.
- Define reference architectures and security patterns for safe tool use, function calling, plugin sandboxing, and API access by autonomous agents.
- Establish identity and access models for non-human/agent identities, including scoped credentials, delegated authority, and least-privilege action permissions.
- Architect guardrails for prompt injection, jailbreaking, data exfiltration, and unauthorized tool invocation across single- and multi-agent systems.
- Design secure patterns for RAG (retrieval-augmented generation), vector databases, and knowledge base access controls.
Risk & Governance
- Build threat models specific to agentic AI (e.g., goal hijacking, tool misuse, cascading multi-agent failures, insecure output handling, excessive agency).
- Define and maintain an AI security risk framework aligned to standards such as OWASP Top 10 for LLM Applications, MITRE ATLAS, NIST AI RMF, and ISO/IEC 42001.
- Partner with GRC, Legal, and Privacy teams to ensure agentic AI deployments meet regulatory requirements (data residency, model governance, auditability, explainability).
- Establish approval gates, security review processes, and architecture standards for teams building or integrating agentic systems.
Platform & Operational Security
- Define monitoring, logging, and observability requirements for agent behavior, tool calls, and decision trails to support detection and forensic investigation.
- Work with SOC/detection engineering to build detection use cases for anomalous agent behavior (e.g., unexpected tool chains, privilege escalation attempts, data exfiltration patterns).
- Define incident response playbooks specific to agentic AI incidents.
- Evaluate and harden CI/CD and MLOps pipelines feeding agentic systems (model supply chain, dependency, and plugin/tool vetting).
Cloud & Network Security
- Architect secure cloud landing zones and network segmentation for agentic AI workloads, isolating agent runtimes, model endpoints, tool/plugin execution environments, and data stores from broader enterprise networks.
- Define secure patterns for outbound/inbound agent network calls, including egress control, allow-listing of external tools/APIs, and prevention of unauthorized or unbounded network access by autonomous agents.
- Establish cloud security controls (IAM policies, VPC/VNet design, security groups, private endpoints, service mesh policies) tailored to multi-tenant AI platforms and agent orchestration layers.
- Design network-level guardrails to contain agent "blast radius" - e.g., microsegmentation, zero-trust network access (ZTNA), and just-in-time network permissions for agent-initiated actions.
- Partner with cloud platform and network engineering teams to secure model inference endpoints, API gateways, service-to-service communication (mTLS), and data-in-transit for agent-to-agent and agent-to-tool traffic.
- Evaluate and harden cloud-native AI/ML services (e.g., SageMaker, Azure AI Foundry, Vertex AI, Bedrock) and their associated networking, storage, and access control configurations.
- Define DDoS, WAF, and API gateway protections for externally exposed agentic AI services and endpoints.
Leadership & Collaboration
- Act as the security architecture authority and trusted advisor to AI/ML engineering, platform engineering, product, and data science teams.
- Review and approve architecture designs for new agentic AI use cases before production deployment.
- Mentor security engineers and evangelize secure-by-design principles for AI systems across the organization.
- Represent the organization in industry forums, vendor evaluations, and internal executive briefings on agentic AI risk.
Required Qualifications
- 10+ years in security architecture, application security, or cloud security roles, including enterprise-scale environments.
- 3+ years of hands-on experience securing AI/ML or LLM-based systems, with direct exposure to agentic architectures (tool/function calling, multi-agent frameworks, autonomous workflows).
- Strong understanding of LLM-specific threat models: prompt injection, jailbreaking, insecure output handling, training data poisoning, model extraction, excessive agency, and sensitive information disclosure.
- Familiarity with agentic AI frameworks and protocols (e.g., LangChain, LangGraph, AutoGen, CrewAI, Model Context Protocol (MCP), OpenAI Assistants/function calling, Semantic Kernel).
- Deep knowledge of identity and access management, including workload identity, OAuth/OIDC, secrets management, and zero-trust principles as applied to non-human/agent identities.
- Solid grounding in cloud security architecture (AWS/Azure/GCP), container and Kubernetes security, and API security.
- Strong network security fundamentals: network segmentation, microsegmentation, firewalls, ZTNA, VPN, private connectivity (PrivateLink/Private Endpoint), and secure API gateway design.
- Hands-on experience designing cloud landing zones, VPC/VNet architecture, IAM, security groups/NSGs, and service mesh (e.g., Istio) policies for multi-service or multi-agent platforms.
- Experience securing data-in-transit and service-to-service communication (mTLS, certificate management) across hybrid or multi-cloud environments.
- Working knowledge of frameworks: OWASP Top 10 for LLM Applications, MITRE ATLAS, NIST AI RMF, ISO/IEC 42001, and relevant data privacy regulations (GDPR, CCPA, etc.).
- Experience producing architecture artifacts: threat models, data flow diagrams, control matrices, and security design reviews.
- Strong stakeholder communication skills — able to translate technical AI security risk into business risk for executives and non-technical audiences.
Preferred Qualifications
- Relevant certifications: CISSP, SABSA, CCSP, or equivalent; cloud certifications (AWS/Azure/GCP Security Specialty) and AI/ML security certifications a plus.
- Experience with SD-WAN, cloud-native firewalls (e.g., Azure Firewall, AWS Network Firewall, Palo Alto/Cisco), and network detection & response (NDR) tooling.
- Experience with red-teaming or adversarial testing of LLM/agentic systems.
- Hands-on experience with vector databases, embedding pipelines, and RAG security controls.
- Background in MLOps/DevSecOps and securing model training/inference pipelines.
- Prior experience building or contributing to an enterprise AI governance program.
- Familiarity with guardrail/evaluation tooling (e.g., Guardrails AI, NeMo Guardrails, Lakera, model evaluation harnesses).
What Success Looks Like in the First 6-12 Months
- A published enterprise reference architecture and security standard for agentic AI deployments.
- A threat model and control catalog specific to the organizations agentic AI use cases, reviewed and adopted by engineering teams.
- Security review and sign-off process integrated into the AI platform's SDLC.
- At least one detection/monitoring capability