Lenovo is a global technology powerhouse focused on delivering Smarter Technology for All. The Sr Cloud Security Architect will lead the implementation of security measures for Azure AI services, ensuring the protection of AI solutions through proactive vulnerability management and incident response.
Responsibilities:
- Lead security implementation of Azure AI Services (OpenAI Service, Machine Learning, Cognitive Services, AI Studio), ensuring protection from development to deployment
- Design and implement security playbooks for AI models, addressing encryption, access control, data integrity, model scanning, and AI model governance
- Perform AI model analysis/usage alerting
- Automate security guardrails via Azure Policies, ARM/Bicep templates and modules to ensure consistent security across Azure AI services
- Lead and manage security incident response efforts and implement responsible AI Patterns
- Analyze threat intelligence to identify and address threats
- Continuously identify and remediating vulnerabilities
Requirements:
- Bachelor's degree in Computer Science, Information Security, or a related field
- 8+ years of hands‑on experience in cybersecurity operations, with demonstrated expertise in vulnerability management, threat hunting, and incident response
- Experience building out KQL queries and dashboards around System/AI Security
- 2+ years of experience with AI Firewall solutions such as Azure AI Content Safety/proxy configurations
- Experience with cloud security platforms (e.g., Microsoft Azure, Intune, Defender for Cloud, etc)
- Experience with automation and scripting for security operations (e.g., Python, PowerShell)
- Experience with Responsible AI Controls (fairness, safety, privacy, transparency)
- Advanced Microsoft Sentinel configuration
- Microsoft Defender for Cloud and AI
- SOC Type II Compliance Prep and Reporting
- Deep understanding of security frameworks (e.g., NIST, MITRE ATTCK, CIS Controls) and regulatory requirements
- Strong analytical and problem‑solving skills; ability to communicate complex technical issues clearly to multiple audiences, including IT and DevOps teams
- Understanding of AI Attack patterns and threat hunting
- Relevant certifications such as CISSP, GIAC, CEH, or AWS/Azure/GCP security certifications