
Cybersecurity AI Platform Advisor (R5)
- AI
- RAG
- LangGraph
- AutoGen
- CrewAI
- CI/CD
- IaC
- AWS
- Azure
- GCP
- SIEM
- EDR
- AI/ML
- Network Security
- Threat Intelligence
- Python
- LangChain
- LlamaIndex
- OWASP
- PowerShell
- Bash
- REST API
- Docker
- Kubernetes
- Agile
- Scrum
At Lilly, the work is demanding because patients are waiting. We unite caring with discovery to help make life better for people around the world, knowing that every decision, every detail, and every day matters. Headquartered in Indianapolis, Indiana, our over 50,000 employees around the globe take on complex challenges to discover and deliver life-changing medicines, strengthen how health is understood and managed, and support the communities we serve. This is hard, urgent, selfless work—but it’s work worth doing. If you’re driven by purpose and ready to bring your best to work that truly matters for patients, we invite you to join us.Â
Job Title: Cybersecurity AI Platform Advisor (R5)Â
Role OverviewÂ
Cybersecurity AI Platform Advisor provides senior technical leadership and advisory guidance for AI-powered use cases across Eli Lilly's Cybersecurity platforms. This role owns the architectural vision and technical direction across the full delivery lifecycle — from identifying and scoping use cases through design, build, test, and production deployment — while partnering with engineering teams to execute against that architecture. Core responsibilities include architecting Agentic AI automation pipelines and RAG workflows that address real security challenges such as platform operations automation. The role requires close collaboration with security operations, data privacy, compliance, and platform engineering teams to ensure solutions are secure, explainable, and appropriate for a highly regulated pharmaceutical environment.Â
Key ResponsibilitiesÂ
Agentic AI Use Case Discovery & ArchitectureÂ
- Serve as the principal technical translator, converting complex business challenges into clear, actionable Agentic AI requirements.Â
- Architect end-to-end agentic systems by defining solution blueprints, staging plans, agent roles, tool inventories, memory strategies, orchestration patterns, and inter-agent communication protocols.Â
- Advise business stakeholders in refining AI adoption objectives and translating them into scalable, viable AI architectures.Â
- Guide stakeholders through Proof of Concepts (PoCs) and development initiatives, from opportunity identification to production handover.Â
- Establish agentic AI guardrails and approved architecture patterns that address prompt injection, unintended action loops, tool misuse, autonomy escalation, and lateral movement risks arising from agent-to-agent trust.Â
- Define agentic AI security acceptance criteria, including sandboxing requirements, permission boundaries, HITL trigger conditions, and kill-switch mechanisms, before solutions progress to development.Â
- Partner with cross-functional teams to identify, scope, and prioritise agentic AI use cases.Â
- Maintain a version-controlled registry of agentic AI use cases, including design blueprints, threat models, tool manifests, and reusable agent patterns to support cross-team adoption.Â
Â
Agentic AI Architecture & Technical AdvisoryÂ
- Define reference architectures and technical standards for AI agents built on frameworks such as LangGraph, AutoGen, and CrewAI, enabling engineering teams to execute multi-step cybersecurity workflows autonomously and reliablyÂ
- Establish and promote Agentic AI coding standards and best practices across engineering teamsÂ
- Design and provide guidance on agent tool layers for security platforms, defining least-privilege access controls and strict input/output contracts for implementation by engineering teamsÂ
- Architect RAG pipelines for agent knowledge retrieval by defining source validation, document-level injection protections, and context boundaries to prevent data exfiltration through agent outputsÂ
- Implement runtime enforcement engines that intercept, validate, and sanitise agent inputs, tool calls, and outputs against configurable security policies, blocking unsafe actions before executionÂ
- Implement and motivate teams to implement automations in different manual work done by teams today Â
- Apply CI/CD, Infrastructure-as-Code, and version control practices to agent configurations, tool definitions, prompt templates, and orchestration logic to ensure reproducibility and auditabilityÂ
Â
Testing, & Safety ValidationÂ
- Design and execute agentic-specific test plans covering multi-step reasoning accuracy, tool call correctness, loop detection, boundary enforcement, and failure mode handling across diverse scenario typesÂ
- Validate that human-in-the-loop checkpoints, sandboxing controls, permission gates, and emergency kill-switch mechanisms engage correctly under adversarial and edge-case conditionsÂ
- Benchmark production-candidate agents against security policy compliance, action explainability, latency SLAs, and cost efficiency before sign-off for deploymentÂ
Â
Production Deployment & Lifecycle ManagementÂ
- Deploy agentic AI systems to enterprise cloud environments (AWS, Azure, GCP) with structured action logging, decision tracing, cost monitoring, and real-time alerting on anomalous agent behaviourÂ
- Implement agent health monitoring covering task completion rates, tool failure patterns, reasoning drift, and policy enforcement effectiveness — with automated alerts and rollback triggersÂ
- Manage the full agentic lifecycle: version-controlled agent releases, controlled rollouts, A/B evaluation of agent variants, scheduled re-validation against updated threat landscapes, and deprecation of obsolete agentsÂ
- Integrate agents with upstream / downstream security platforms — SIEM, SOAR, EDR, identity, and ticketing systems — through governed API layers that enforce authentication, rate limits, and action audit trailsÂ
- Provide Level 3 engineering support for agentic incidents including runaway action loops, unexpected tool invocations, and agent-induced security events — with structured post-incident reviewsÂ
Â
Governance, Collaboration & Knowledge SharingÂ
- Define and maintain agentic AI governance standards covering action logging requirements, human oversight triggers, permissible tool scopes, and escalation procedures for high-risk autonomous decisionsÂ
- Collaborate with data privacy, legal, compliance, and quality assurance teams to ensure agentic systems meet regulatory obligations around auditability, explainability, and high-risk AI classificationsÂ
- Create and maintain comprehensive documentation: agent architecture diagrams, tool manifests, decision trace examples, red-team reports, runbooks, and post-deployment model cardsÂ
- Mentor junior engineers and security operations personnel on safe agentic design patterns, tool authoring best practices, and responsible AI principles in cybersecurity contextsÂ
- Engage with vendors, open-source communities, and technology partners to evaluate emerging agentic frameworks, influence platform roadmaps, and bring best practices back into Lilly's engineering standardsÂ
Â
QualificationsÂ
RequiredÂ
- 10+ years of software or platform engineering experience, including significant experience in an architecture, technical leadership, or senior advisory capacity, with at least 2 years focused on AI/ML or LLM application developmentÂ
- Demonstrated experience delivering AI use cases end-to-end: from design through testing to production deploymentÂ
- Working knowledge of cybersecurity domains including SIEM, EDR, network security, threat intelligence, or identity platformsÂ
- Proficiency in Python for ML model development, LLM orchestration (e.g. LangChain, LlamaIndex), and API integrationÂ
- Strong understanding of LLM-specific threat models: prompt injection (direct and indirect), hallucination, jailbreaks, data poisoning, and model misuseÂ
- Familiarity with OWASP Top 10 for LLM Applications and MITRE ATLAS adversarial AI threat frameworkÂ
- Experience building or operating CI/CD pipelines for ML/LLM systems including automated testing and deployment gatesÂ
- Solid understanding of cloud security across AWS, Azure, and GCP environmentsÂ
- Strong scripting capabilities in Python, PowerShell, or Bash; proficient in RESTful APIs and system integration patternsÂ
- Excellent written and verbal communication skills with the ability to translate AI concepts for both technical and business audiencesÂ
- Bachelor’s degree in computer science, Cybersecurity, Information Systems, or related technical field, or equivalent practical experienceÂ
PreferredÂ
- Experience with AI security reviews, adversarial red-teaming, or AI governance frameworks in regulated industriesÂ
- Exposure to agentic AI frameworks (AutoGen, CrewAI, LangGraph) and associated safety mechanisms such as HITL, sandboxing, and tool-call guardrailsÂ
- Familiarity with AI regulatory expectations including high-risk AI classifications, auditability requirements, and conformity assessmentsÂ
- Experience with containerization (Docker, Kubernetes) and cloud-native architectures for ML workloadsÂ
- Project management exposure or Agile / Scrum experience within cross-functional AI delivery teamsÂ
Â
Eli Lilly is an equal opportunity employer and is committed to creating a diverse and inclusive workplace.Â
Lilly is dedicated to helping individuals with disabilities to actively engage in the workforce, ensuring equal opportunities when vying for positions. If you require accommodation to submit a resume for a position at Lilly, please complete the accommodation request form (https://careers.lilly.com/us/en/workplace-accommodation) for further assistance. Please note this is for individuals to request an accommodation as part of the application process and any other correspondence will not receive a response.
Lilly does not discriminate on the basis of age, race, color, religion, gender, sexual orientation, gender identity, gender expression, national origin, protected veteran status, disability or any other legally protected status.
#WeAreLillyCybersecurity AI Platform Advisor (R5) · Eli Lilly and Company