
Real job — pulled straight from Skit.ai’s careers page · Verified July 12, 2026 · No reposts.
Job description
Skit.ai is hiring a Senior Security Engineer, Cloud, AI & Compliance — a full-time, based in Bangalore, India role. Apply directly on Skit.ai's careers page below.
Senior Security Engineer (Cloud, AI & Compliance)
Location: Bangalore, India
Department: Technology
Experience: 5+ years
- Own threat detection and posture management across AWS and Azure — AWS GuardDuty, Security Hub, Inspector, Config; Microsoft Defender for Cloud and Azure Policy.
- Establish and maintain CIS Benchmark compliance for AWS and Azure; track drift and remediate.
- Drive IAM hygiene, network segmentation, encryption, secrets management, and least-privilege access.
- Own container image and runtime security — scanning with Trivy / Grype, configuration auditing with Dockle and Docker Bench, and Kubernetes hardening.
- Maintain SBOMs and dependency / vulnerability scanning across services; manage remediation SLAs.
- Integrate infrastructure-as-code scanning (e.g. Checkov, tfsec) into pipelines.
- Run and operationalize SAST and DAST (e.g. SonarQube / Semgrep / Snyk; OWASP ZAP / Burp Suite); triage findings and drive fixes.
- Embed security into the SDLC — secure coding standards, PR / security review gates, secrets detection.
- Coordinate external penetration tests and own remediation tracking.
- Own the platform’s LLM guardrails — content safety (e.g. Azure OpenAI content filtering), prompt-injection defenses, output validation, and grounding controls.
- Maintain mappings to the OWASP Top 10 for LLMs and MITRE ATLAS; run AI red-teaming and close gaps.
- Define guardrail-breach detection and AI-specific monitoring, in partnership with the AI engineering team.
- Be the primary point of contact for customer (banking / telecom) security questionnaires, due diligence, and audits.
- Keep a living, audit-ready evidence library: SAST/DAST summaries, GuardDuty and container-security reports, CIS posture, guardrails documentation, pen-test summaries, SBOMs.
- Support and progress formal certifications and frameworks (e.g. ISO/IEC 27001, SOC 2, NIST AI RMF, ISO/IEC 42001) and applicable regulatory expectations (e.g. PCI-DSS where payments are in scope, data-protection requirements).
- Mature logging, alerting, and threat detection across the stack; integrate with existing observability.
- Own and rehearse incident-response runbooks; lead investigations and post-incident reviews.
- What you bring
- 5+ years in security engineering, DevSecOps, cloud security, or product security, with senior ownership of security programs.
- Hands-on production security across both AWS and Azure, including native security services (GuardDuty / Security Hub / Defender for Cloud).
- Strong container and Kubernetes security — image scanning, runtime, hardening, supply-chain / SBOM.
- Application security depth — SAST/DAST, secure SDLC, secrets management, vulnerability management.
- Demonstrated experience responding to enterprise customer security reviews and audits (questionnaires, evidence packages, certification programs).
- Excellent written communication — clear security documentation for technical and non-technical audiences, including external client InfoSec teams.
- Working knowledge of AI/LLM security — OWASP Top 10 for LLMs, MITRE ATLAS, prompt-injection and content-safety controls — or clear aptitude and intent to own this fast-evolving area.
- Experience in a regulated domain (financial services, telecom, healthcare) and with frameworks such as ISO 27001, SOC 2, NIST AI RMF, or ISO 42001.
- Familiarity with CI/CD security integration and infrastructure-as-code (Terraform).
- Relevant certifications a plus: CISSP, CCSP, AWS/Azure security specialty, CKS, OSCP.
- Operate independently as the dedicated owner, but partner closely with engineering and AI teams.
- Balance hands-on technical work with customer-facing assurance and documentation.
- Are pragmatic — prioritize the controls and evidence that reduce real risk and unblock customers.
- Cloud: AWS (GuardDuty, Security Hub, Inspector, Config, IAM), Azure (Defender for Cloud, Azure Policy, Azure OpenAI content safety).
- Containers: Docker, Kubernetes, Trivy, Grype, Dockle, Docker Bench.
- AppSec: SonarQube / Semgrep / Snyk, OWASP ZAP, Burp Suite.
- Posture & IaC: CIS Benchmarks, Checkov, tfsec. Supply chain: Syft / CycloneDX SBOMs.
- AI security: OWASP LLM Top 10, MITRE ATLAS, NIST AI RMF. Secrets: managed secret store / Vault.
Get Security Engineer jobs like this→
New roles from thousands of companies land hourly, straight from their careers pages. Get the freshest matches by email so you never miss one.
Email me new jobsSimilar jobs




Frequently asked questions
What skills are required for Senior Security Engineer, Cloud, AI & Compliance at Skit.ai?
The required skills for Senior Security Engineer, Cloud, AI & Compliance at Skit.ai include: AWS, Azure, Kubernetes, Docker, IAM, ISO 27001, SOC 2, PCI DSS, Terraform, CISSP.
What is the seniority level for Senior Security Engineer, Cloud, AI & Compliance at Skit.ai?
Senior Security Engineer, Cloud, AI & Compliance at Skit.ai is a Senior level position.
How do I apply for Senior Security Engineer, Cloud, AI & Compliance at Skit.ai?
You can view the full description and apply for Senior Security Engineer, Cloud, AI & Compliance at Skit.ai on EchoJobs: https://echojobs.io/job/skit-ai-senior-security-engineer-cloud-ai-compliance-edhk4.