Job Purpose
The Lead AI Application Engineering & DevSecOps Consultant is responsible for creating a controlled and
repeatable pathway that transforms business-built AI prototypes into secure, production-grade risk
applications.
Working closely with risk practitioners, business builders, platform architects, and cyber teams, the role
establishes the engineering standards, testing practices, security controls, deployment patterns, and
governance guardrails required for enterprise adoption. The consultant acts as the production-readiness
authority for AI agents, reviewing, testing, hardening, and preparing applications for Azure deployment while
enabling business users to continue innovating responsibly.
The role ensures all Risk AI agents operate under common engineering standards, with practical controls
covering GitHub, testing, secrets management, access control, documentation, monitoring, and release
management, creating solutions that are reliable, auditable, secure, and maintainable.
Key Responsibilities
- Assess AI agents and application codebases for production readiness across architecture, code quality, security, testing, and deployment.
- Identify and remediate engineering, security, and operational gaps in business-built AI prototypes.
- Harden applications through secure authentication, authorization, secrets management, input validation, and safe AI model integration practices.
- Refactor prototype solutions into maintainable, scalable, and enterprise-ready applications with robust
engineering standards.
- Establish coding standards, repository governance, branching strategies, pull-request processes, and code
review practices.
- Collaborate with cloud, infrastructure, security, and architecture teams to ensure compliant and scalable
deployments.
- Develop reusable application templates, starter kits, reference architectures, and implementation checklists.
- Ensure consistent integration of AI applications with enterprise platforms, data services, and architectural
standards.
- Design, implement, and optimize CI/CD pipelines using GitHub Actions, Azure DevOps, and approved enterprise
tooling.
- Define and implement secure Azure deployment patterns covering App Services, Functions, Container Apps, API Management, Key Vault, and Managed Identities.
- Establish comprehensive testing frameworks including unit, integration, regression, end-to-end, user
acceptance, and AI-specific testing.
- Implement AI assurance practices including prompt testing, response evaluation, adversarial testing, and model output validation.
- Define quality benchmarks, golden datasets, confidence thresholds, and auditability standards for AI
applications.
- Embed Secure SDLC practices, threat modeling, vulnerability management, dependency scanning, and least privilege access controls.
- Define standards for application monitoring, logging, alerting, resilience, and operational support.
- Deliver governance, training, workshops, and developer enablement initiatives that accelerate innovation
while maintaining control.
Key competencies
- Conduct architecture reviews and code reviews to improve quality, security, and maintainability.
- Coach and mentor business developers, citizen developers, and risk practitioners on secure software
engineering practices.
Technical Competencies
- Candidates should have a B.E./B.Tech/MCA/MBA in Information Systems, Computer Science or a related field
- Strong hands-on expertise in React, TypeScript, JavaScript, Node.js, Python, and modern web application
frameworks.
- Proven experience building, deploying, and supporting enterprise web applications, APIs, and microservices.
- Deep knowledge of Azure cloud services including App Service, Functions, Container Apps, API Management,
Key Vault, Managed Identity, and Azure Monitor.
- Strong DevOps and CI/CD experience using GitHub Enterprise, GitHub Actions, Azure DevOps, and automated
deployment pipelines.
- Knowledge of AI application risks including prompt injection, hallucination management, model evaluation, and
AI testing methodologies.
- Expertise in application architecture, software engineering best practices, and production support models.
- Strong understanding of API design, service-to-service authentication, authorization, and API governance.
- Hands-on experience with secure application development, threat modeling, secure SDLC, vulnerability
management, and security engineering practices.
- Experience implementing logging, monitoring, observability, incident management, and operational controls.
Preferred Competencies
- Experience building and operationalizing AI, GenAI, LLM, RAG, and agent-based applications.
- Experience with frameworks such as FastAPI, Flask, Streamlit, LangChain, Semantic Kernel, and Azure AI
services.
- Experience in financial services, risk management, compliance, or other highly regulated environments.
- Familiarity with enterprise data governance, semantic layers, and controlled data-access patterns.
Leadership & Behavioral Competencies
- Strong stakeholder management and cross-functional collaboration skills.
- Ability to influence engineering practices without direct authority.
- Strong coaching, mentoring, and developer enablement capabilities.
- Pragmatic approach to governance, balancing innovation, speed, and control.
- Excellent problem-solving and analytical skills.
- Strong written and verbal communication skills with both business and technical audiences.
- Ability to drive engineering discipline, quality, and continuous improvement across distributed teams.