Farah Siddiqui, ai security engineer

Farah Siddiqui

Senior AI Security Engineer

Karachi, Pakistan · Asia/Karachi (UTC+5) · 10 years of experience

Farah focuses on securing AI applications, data paths, model supply chains, and agent permissions.

Request a shortlist

Why this profile fits

AI-specific threat modeling

Covers prompt injection, sensitive-data exposure, unsafe tool use, model supply chains, and excessive agency.

Least-privilege architecture

Scopes identities, tools, data access, secrets, and network paths to the minimum required for each workload.

Adversarial validation

Turns abuse cases and incidents into repeatable tests, monitoring signals, and response playbooks.

Relevant toolkit

Threat ModelingIAMKubernetes SecurityLLM Red TeamingSIEM

Delivery evidence

Selected work

AI Application Threat Model

digital banking

Designed and delivered a AI security programme focused on LLM application threat modeling; closed 84% of high-risk prompt-injection and data-exposure paths before production release. The release included threat models, least-privilege controls, adversarial tests, logging, and incident playbooks mapped to OWASP guidance.

Threat ModelingPython

Prompt-Injection Test Harness

digital banking operations

Built the supporting control and measurement layer for the primary system, covering review queues, regression checks, operational visibility, and a documented handoff to the owning team.

Threat ModelingKubernetes Security
View more profile detail →

Relevant experience

Career timeline

Senior AI Security Engineer

2023–Present

Devlyn client assignments · Remote

  • Led LLM application threat modeling delivery for a digital banking team and closed 84% of high-risk prompt-injection and data-exposure paths before production release.

AI Security Engineer

2016–2022

digital banking product company (confidential) · Karachi, Pakistan

  • Built production systems in digital banking, with increasing ownership of reliability, testing, and stakeholder delivery.

Skill depth

Show experience in context.

VerbalCommunicationDomainUnderstandingProblemSolvingCodeQualitySystemDesignDeliverySpeed
Competency shapeAssessment across the same six dimensions used for every profile.

Relevant experience by skill

Threat Modeling10 years
Python9 years
IAM8 years
Kubernetes Security7 years
LLM Red Teaming10 years
SIEM9 years
See the complete skill index

Languages

PythonTypeScriptSQLBash

Frameworks

PythonIAMKubernetes SecurityOPAVaultSemgrep

Tools

Burp SuiteFalcoTerraformGitHub ActionsDocker

Platforms

AWSGoogle CloudAzureKubernetes

Storage

VaultS3PostgreSQLSecurity Lake

Paradigms

Secure-by-design AIZero trustAdversarial testingSupply-chain security

Credentials

Certifications

HashiCorp Certified: Vault Associate (003)

HashiCorp · 2026 · Certified

Google Cloud Professional Cloud Security Engineer

Google Cloud · 2025 · Certified

Communication

Languages

English

Fluent

More examples

Similar AI Security Engineer profiles.