Enterprise AI Security Advisor

Eli Lilly 2 Locations Updated 8 October 2026
PharmaRegulatory AffairsQuality Assurancepythonemacroinformazureaws

Job description

At Lilly, the work is demanding because patients are waiting. We unite caring with discovery to help make life better for people around the world, knowing that every decision, every detail, and every day matters. Headquartered in Indianapolis, Indiana, our over 50,000 employees around the globe take on complex challenges to discover and deliver life-changing medicines, strengthen how health is understood and managed, and support the communities we serve. This is hard, urgent, selfless work—but it’s work worth doing. If you’re driven by purpose and ready to bring your best to work that truly matters for patients, we invite you to join us. Role Overview The Enterprise AI Security Advisor leads how Eli Lilly secures AI systems across the enterprise. Lilly teams use a mix of commercial AI assistants and coding agents, internally built agents and integrations, internal and third-party models, and company-managed AI compute. As adoption grows, this role provides a consistent approach to understanding the risks, putting effective controls in place, and helping teams deploy AI safely. The Advisor owns the strategy, security requirements, control architecture, tooling, and roadmap for enterprise AI security within Lilly's Cybersecurity organization. This is a hands-on senior technical leadership role: the Advisor assesses what exists today, identifies the gaps that matter most, evaluates available products, and works with engineering, platform, and security operations teams to implement and operate solutions. The role also shapes security requirements for AI systems built within Lilly and advises leadership on emerging AI risks, practical trade-offs, and where investment will have the greatest impact, all within a highly regulated pharmaceutical environment. The position may be filled at the Advisor or Sr. Advisor level depending on experience and scope of accountability. Key Responsibilities AI Security Strategy & Roadmap • Establish and own a companywide approach to securing AI agents, models, applications, and the infrastructure that supports them, aligned with Lilly's cybersecurity strategy, policies, and regulatory obligations. • Maintain a prioritized view of AI security risk across commercial AI products, internally built agents, internal models, and AI compute platforms, and use it to set priorities for the team and its partners. • Own the roadmap for AI security controls, tooling, and improvements; sequence work by risk reduction, cost, and user impact; report progress and measurable outcomes to leadership. • Advise senior leaders on emerging AI threats, the practical trade-offs between safety and productivity, and where investment will have the greatest effect. Security Requirements & Reference Architecture • Define security requirements and approved patterns for AI systems covering agent identity, permissions and tool access, data access and classification boundaries, human approval and kill-switch mechanisms, logging and monitoring, and incident response. • Publish reference architectures and acceptance criteria that teams building AI applications, agents, and integrations (including agent-to-tool protocols such as MCP) can apply without a bespoke review each time. • Set control expectations for inference-time guardrails (prompt-injection defense, sensitive-data detection and blocking, tool-call policy), AI gateways, and model and agent registries. • Integrate AI security requirements into Lilly's existing security architecture review, risk acceptance, and change management processes. Assessment, Testing & Assurance • Assess internally built AI systems and third-party AI products to understand how they are used, what data and systems they can access, what actions they can take, and where controls are needed. • Develop and lead an approach to testing AI systems for prompt injection (direct and indirect), sensitive data exposure, excessive permissions, unsafe or unintended agent actions, and jailbreak or misuse scenarios, including adversarial red-team exercises. • Define the evidence required before an AI control moves from monitoring to blocking, including false-positive tolerances, user impact, and rollback plans. • Maintain threat models for high-value AI systems using frameworks such as OWASP Top 10 for LLM Applications and MITRE ATLAS. Guardrail Platforms, Tooling & Visibility • Evaluate, select, and tune security capabilities from existing platforms and vendors, including cloud, endpoint, identity, data protection, and AI-specific security tools, distinguishing capabilities that address Lilly's actual risks from features that do not. • Establish visibility into AI usage and agent activity across the enterprise (who is using which AI systems, what they can access, and what actions agents take) so teams can investigate issues and measure whether controls are working. • Lead the design and operation of enterprise AI guardrail services, including detection content, policy tuning, telemetry, dashboards, and integration with SIEM, SOAR, EDR, identity, and ticketing platforms. • Define detection, alerting, and incident response playbooks for AI-specific events such as data exfiltration through AI tools, compromised or misbehaving agents, and unsafe tool use. Partnership, Governance & Knowledge Sharing • Partner with teams building AI applications and agents to incorporate security into their design, build, and deployment processes, and give them a clear, supported path to deploy AI securely. • Collaborate with data privacy, legal, compliance, quality, and AI governance functions so that AI security controls meet regulatory expectations for auditability, explainability, and high-risk AI classifications. • Mentor engineers and security operations personnel on AI threat models, safe agent design patterns, and responsible AI principles in cybersecurity contexts. • Engage with vendors, industry groups, and technology partners to evaluate emerging AI security capabilities and bring proven practices back into Lilly's standards. • At the Sr. Advisor level: serve as Lilly's enterprise authority on AI security, own the multi-year strategy and investment case, represent Cybersecurity with executive leadership, auditors, and external partners, and set technical direction for other advisors and engineers working on AI security. What Success Looks Like In the first year, Lilly has a clear inventory of its most important AI systems and agent capabilities, a prioritized view of their risks, and a practical set of controls that teams can apply. Security can see where agents operate, understand what they can access and do, and respond when something goes wrong. Teams building AI have a clear path to deploy it securely, supported by tools and guidance that fit how they work, and leadership has measurable evidence that AI security controls are working. Basic Qualifications Bachelor's degree in Computer Science, Cybersecurity, Information Systems, or a related IT technical field. 10+ years of experience in cybersecurity, security architecture, or platform/software engineering, including experience in a technical leadership, architecture, or senior advisory capacity; a track record of setting technical direction at enterprise scale and influencing executive investment decisions. Preferred Experience designing or l

Stand out for this role

NoxPharm tailors your CV to this job description by aligning your experience with the role requirements and terminology. Built for pharma & life sciences.

Tailor my CV now — free to try