- Perform security and risk assessments of AI developer tools before enterprise deployment.
- Review AI tool architecture, data flow, vendor security posture, and integration capabilities to identify potential security risks.
- Evaluate AI-specific threats such as prompt injection, data leakage, unauthorized integrations, and MCP (Model Context Protocol) server risks.
- Recommend security controls, governance policies, and feature enablement decisions based on risk assessments.
- Assign risk ratings (High/Medium/Low) and provide recommendations for go/no-go decisions.
- Partner with Application Security, Information Security, and Cyber Security teams to accelerate enterprise security reviews.
- Define and implement governance controls, audit logging, monitoring, and security reporting for AI tools.
- Collaborate with MDM/Packaging teams to deliver secure, enterprise-approved versions of AI development tools.
- Embed security best practices into the software development lifecycle following DevSecOps principles.
- Independently own security assessments, communicate findings, and provide regular progress updates to stakeholders.
- 8+ years of experience in Information Security, Application Security, or DevSecOps.
- Hands-on experience securing AI developer tools such as GitHub Copilot, Claude, Cursor, Gemini Code Assist, Windsurf, Codex, or similar AI coding assistants.
- Strong understanding of Application Security and secure software development practices.
- Experience conducting:
- Security Risk Assessments
- Architecture Reviews
- Data Flow Reviews
- Vendor Security Assessments
- Knowledge of AI security threats, including:
- Prompt Injection
- Data Leakage
- AI Governance
- MCP (Model Context Protocol) Servers
- Experience implementing DevSecOps practices and integrating security into the SDLC.
- Ability to communicate technical risks effectively to both engineering and leadership teams.
- Strong stakeholder management skills with the ability to work independently in a fast-paced enterprise environment.
- Experience with MDM or enterprise software packaging solutions.
- Exposure to enterprise AI governance frameworks.
- Experience with AI observability or monitoring platforms such as LangSmith.
- Experience collaborating with centralized Information Security or Application Security teams.
- Knowledge of enterprise audit logging, compliance, and governance for AI platforms.
Skills Required
- 8+ years experience in Information Security, Application Security, or DevSecOps
- Hands-on experience securing AI developer tools (GitHub Copilot, Claude, Cursor, Gemini Code Assist, Windsurf, Codex)
- Strong understanding of Application Security and secure software development practices
- Experience conducting Security Risk Assessments
- Experience conducting Architecture Reviews
- Experience conducting Data Flow Reviews
- Experience conducting Vendor Security Assessments
- Knowledge of AI security threats including prompt injection, data leakage, AI governance, and MCP servers
- Experience implementing DevSecOps practices and integrating security into the SDLC
- Ability to communicate technical risks effectively to engineering and leadership teams
- Strong stakeholder management skills and ability to work independently in a fast-paced enterprise environment
- Experience with MDM or enterprise software packaging solutions
- Exposure to enterprise AI governance frameworks
- Experience with AI observability or monitoring platforms such as LangSmith
- Experience collaborating with centralized Information Security or Application Security teams
- Knowledge of enterprise audit logging, compliance, and governance for AI platforms
What We Do
@TechBlocks we power the software defined industries (SDI) of today and tomorrow. We are a software engineering and consulting firm. We build modern digital value chains and businesses reimagined to create frictionless experiences for innovative monetization methods and drive unforeseen efficiencies. We are known to build world class custom platforms and products that are cloud native for some of the worlds largest brands. We are the go to technology partners for born in digital businesses that grew with us from "Concept to Commercialization" and have revenues between $100M - $10B. We help modern businesses transition just from a technology outsourcing mentality to help create globally distributed digital COEs and mature them. Our converged COEs that we create in partnership with our clients help power software factories that are extremely dynamic. We have created modern digital COEs and factories that are created with a single minded goal to future proof our clients businesses. Everything we do is centred around two philosophies and practices - Design Thinking and Lean Engineering. Whether it is building digital commerce platforms, marketplace for worlds largest retailers or smart utilities applications and products or digital health products/platforms that power wearables, patches or devices across healthcare landscape; we do it all with speed and sophistication that is unmatched in the industry








