Security & Agentic AI DevSecOps Engineer (Product Security)
Role:- Security & Agentic AI DevSecOps Engineer (Product Security) Location:- Milpitas, CA(Onsite) Job Description :- Role Overview As a AI Security & Agentic AI DevSecOps Engineer, you will act as a hands-on technical authority responsible for designing and implementing fully automated security controls across the software and AI lifecycle. Your focus will be to ensure that every meaningful security decision is enforced through automation, not manual processes. You will embed security as code, policy as code, and continuous verification into modern software platforms and agentic AI systems, enabling secure innovation at scale across cloud, hybrid, and air-gapped environments. Key Responsibilities AI Security & Agentic Systems (Automation-First)Design and implement automated Agentic and AI security controlsfor agentic systems, including:Automated model access control, inference authorization, and rate limitingPolicy-driven prompt/instruction validation and misuse detectionAutomated enforcement of agent-to-agent authentication and authorizationImplement continuous, automated threat modeling for:LLM pipelinesAgent orchestration frameworksAI gateways and inference servicesBuild secure-by-default reference architectures where AI guardrails are enforced via:Configuration-as-codeRuntime policy enginesAutomated security testing pipelinesCreate Plugins , Hooks and Skills using claude code and or Microsoft AI foundry DevSecOps & Secure SDLC (End-to-End Automation)Implement fully automated Secure SDLC pipelines, integrating:SAST, DAST, SCA, secrets detection, container scanning, and IaC scanningAI-specific security testing (prompt injection, model misuse, data leakage)Automated build and release policy enforcement (fail gates, conditional approvals)Ensure all security checks are:Triggered automatically via CI/CD and MLOps pipelinesEnforced consistently across dev, test, and productionAutomate security validation during:Design reviews (template-driven controls)Architecture reviews (reusable security patterns)Pre-release readiness checks SBOM, AI-BOM & Supply Chain AutomationDesign and operate automated SBOM and AI-BOM pipelines, including:Continuous generation of SBOMs for software, containers, firmware, and artifactsAutomated AI-BOMs covering models, datasets, checkpoints, and training artifactsImplement automated vulnerability, license, and provenance analysis:Continuous ingestion of CVEs and advisoriesAutomated policy enforcement for non-compliant componentsIntegrate SBOM and AI-BOM outputs into:CI/CD pipelinesDeployment gatesAudit and compliance reporting workflows Runtime Security, Risk & Metrics AutomationImplement continuous, automated security monitoringacross:Application runtimesAI/ML inference servicesAgent workflows and interactionsDevelop automated security metrics and telemetry to measure:Vulnerability exposure and remediation velocitySecure SDLC and DevSecOps maturityModel and AI risk posture over timeAutomate security feedback loops so findings:Generate actionable tasksFeed directly into engineering backlogsDrive measurable risk reduction Technical Influence & EnablementAbility and willing to learn,teach and develop agentic AI workflow automation using copilot studio and or Claude codeAct as a technical authority on AI security automation and DevSecOps.Define reusable security automation patterns, templates, and reference implementations.Partner with engineering, AI/ML, platform, and compliance teams to replace manual security workflows with automated controls.Contribute to internal security standards that mandate automation by default.Strong hands-on experience designing automated Product Security or AI Security systems.Deep knowledge of:Operating systems, infrastructure, cloud platforms, and hybrid environmentsAutomation frameworks and pipeline-driven enforcement modelsAbility to interpret and secure code written in multiple languages, with automation as the primary mitigation strategy.Experience integrating security tooling via APIs and pipelines, not manual review.Familiarity with security intelligence ingestion and automation, including:CVE feedsSecurity advisoriesAutomated alerting and remediation workflowsStrong understanding of cybersecurity, privacy, and AI governance requirements, with experience translating them into automated controls.Ability to concurrently deliver multiple security automation initiatives. Minimum QualificationsBachelor's degree in Computer Science, Cybersecurity, IT Security, or equivalent experience.Experience in DevOps, SecOps, DevSecOps, or MLOps, with a strong automation focus.Demonstrated success implementing automated Secure SDLC pipelines.Ability to evaluate code and architecture risk and remediate through automation, not policy alone.Familiarity with security frameworks and scoring systems:MITRE ATT&CKCVSSCWEStrong technical communication skills and cross-functional influence.