Eli Lilly
US, Indianapolis IN, United States of America; US: USA Remote
Other
Posted 1 hour ago
Verified open on Oct 7, 2026 · posted today
At Lilly, the work is demanding because patients are waiting. We unite caring with discovery to help make life better for people around the world, knowing that every decision, every detail, and every day matters. Headquartered in Indianapolis, Indiana, our over 50,000 employees around the globe take on complex challenges to discover and deliver life-changing medicines, strengthen how health is understood and managed, and support the communities we serve. This is hard, urgent, selfless work—but it’s work worth doing. If you’re driven by purpose and ready to bring your best to work that truly matters for patients, we invite you to join us.Â
The Enterprise AI Security Advisor leads how Eli Lilly secures AI systems across the enterprise. Lilly teams use a mix of commercial AI assistants and coding agents, internally built agents and integrations, internal and third-party models, and company-managed AI compute. As adoption grows, this role provides a consistent approach to understanding the risks, putting effective controls in place, and helping teams deploy AI safely.
The Advisor owns the strategy, security requirements, control architecture, tooling, and roadmap for enterprise AI security within Lilly's Cybersecurity organization.
This is a hands-on senior technical leadership role: the Advisor assesses what exists today, identifies the gaps that matter most, evaluates available products, and works with engineering, platform, and security operations teams to implement and operate solutions. The role also shapes security requirements for AI systems built within Lilly and advises leadership on emerging AI risks, practical trade-offs, and where investment will have the greatest impact, all within a highly regulated pharmaceutical environment.
The position may be filled at the Advisor or Sr. Advisor level depending on experience and scope of accountability.
AI Security Strategy & Roadmap
•    Establish and own a companywide approach to securing AI agents, models, applications, and the infrastructure that supports them, aligned with Lilly's cybersecurity strategy, policies, and regulatory obligations.
•    Maintain a prioritized view of AI security risk across commercial AI products, internally built agents, internal models, and AI compute platforms, and use it to set priorities for the team and its partners.
•    Own the roadmap for AI security controls, tooling, and improvements; sequence work by risk reduction, cost, and user impact; report progress and measurable outcomes to leadership.
•    Advise senior leaders on emerging AI threats, the practical trade-offs between safety and productivity, and where investment will have the greatest effect.
Â
Security Requirements & Reference Architecture
•    Define security requirements and approved patterns for AI systems covering agent identity, permissions and tool access, data access and classification boundaries, human approval and kill-switch mechanisms, logging and monitoring, and incident response.
•    Publish reference architectures and acceptance criteria that teams building AI applications, agents, and integrations (including agent-to-tool protocols such as MCP) can apply without a bespoke review each time.
•    Set control expectations for inference-time guardrails (prompt-injection defense, sensitive-data detection and blocking, tool-call policy), AI gateways, and model and agent registries.
•    Integrate AI security requirements into Lilly's existing security architecture review, risk acceptance, and change management processes.
Â
Assessment, Testing & Assurance
•    Assess internally built AI systems and third-party AI products to understand how they are used, what data and systems they can access, what actions they can take, and where controls are needed.
•    Develop and lead an approach to testing AI systems for prompt injection (direct and indirect), sensitive data exposure, excessive permissions, unsafe or unintended agent actions, and jailbreak or misuse scenarios, including adversarial red-team exercises.
•    Define the evidence required before an AI control moves from monitoring to blocking, including false-positive tolerances, user impact, and rollback plans.
•    Maintain threat models for high-value AI systems using frameworks such as OWASP Top 10 for LLM Applications and MITRE ATLAS.
Â
Guardrail Platforms, Tooling & Visibility
•    Evaluate, select, and tune security capabilities from existing platforms and vendors, including cloud, endpoint, identity, data protection, and AI-specific security tools, distinguishing capabilities that address Lilly's actual risks from features that do not.
•    Establish visibility into AI usage and agent activity across the enterprise (who is using which AI systems, what they can access, and what actions agents take) so teams can investigate issues and measure whether controls are working.
•    Lead the design and operation of enterprise AI guardrail services, including detection content, policy tuning, telemetry, dashboards, and integration with SIEM, SOAR, EDR, identity, and ticketing platforms.
•    Define detection, alerting, and incident response playbooks for AI-specific events such as data exfiltration through AI tools, compromised or misbehaving agents, and unsafe tool use.
Â
Partnership, Governance & Knowledge Sharing
•    Partner with teams building AI applications and agents to incorporate security into their design, build, and deployment processes, and give them a clear, supported path to deploy AI securely.
•    Collaborate with data privacy, legal, compliance, quality, and AI governance functions so that AI security controls meet regulatory expectations for auditability, explainability, and high-risk AI classifications.
•    Mentor engineers and security operations personnel on AI threat models, safe agent design patterns, and responsible AI principles in cybersecurity contexts.
•    Engage with vendors, industry groups, and technology partners to evaluate emerging AI security capabilities and bring proven practices back into Lilly's standards.
•    At the Sr. Advisor level: serve as Lilly's enterprise authority on AI security, own the multi-year strategy and investment case, represent Cybersecurity with executive leadership, auditors, and external partners, and set technical direction for other advisors and engineers working on AI security.
Â
In the first year, Lilly has a clear inventory of its most important AI systems and agent capabilities, a prioritized view of their risks, and a practical set of controls that teams can apply. Security can see where agents operate, understand what they can access and do, and respond when something goes wrong. Teams building AI have a clear path to deploy it securely, supported by tools and guidance that fit how they work, and leadership has measurable evidence that AI security controls are working.
Â
Preferred
Â
Lilly is dedicated to helping individuals with disabilities to actively engage in the workforce, ensuring equal opportunities when vying for positions. If you require accommodation to submit a resume for a position at Lilly, please complete the accommodation request form (https://careers.lilly.com/us/en/workplace-accommodation) for further assistance. Please note this is for individuals to request an accommodation as part of the application process and any other correspondence will not receive a response.
Lilly is proud to be an EEO Employer and does not discriminate on the basis of age, race, color, religion, gender identity, sex, gender expression, sexual orientation, genetic information, ancestry, national origin, protected veteran status, disability, or any other legally protected status.
Our employee resource groups (ERGs) offer strong support networks for their members and are open to all employees. Our current groups include: Africa, Middle East, Central Asia (AMECA), Black Employees at Lilly (BE@Lilly), Chinese Culture Network (CCN), EnAble, Evolve, Lilly Indian Network (LIN), Organization of Latinx at Lilly (OLA), Pride (LGBTQ+ Allies), Veterans Leadership Network (VLN) and Women’s Initiative for Leading at Lilly (WILL).
Actual compensation will depend on a candidate’s education, experience, skills, and geographic location. The anticipated wage for this position is
$129,000 - $231,000Full-time equivalent employees also will be eligible for a company bonus (depending, in part, on company and individual performance). In addition, Lilly offers a comprehensive benefit program to eligible employees, including eligibility to participate in a company-sponsored 401(k); pension; vacation benefits; eligibility for medical, dental, vision and prescription drug benefits; flexible benefits (e.g., healthcare and/or dependent day care flexible spending accounts); life insurance and death benefits; certain time off and leave of absence benefits; and well-being benefits (e.g., employee assistance program, fitness benefits, and employee clubs and activities).Lilly reserves the right to amend, modify, or terminate its compensation and benefit programs in its sole discretion and Lilly’s compensation practices and guidelines will apply regarding the details of any promotion or transfer of Lilly employees.
#WeAreLilly
Not ready to apply?
Get AI jobs in United States in your inbox
Join 100+ AI professionals · Weekly, free, unsubscribe anytime
Hiring for a role like this?
Reach AI professionals browsing the board - your listing goes live instantly.
MercorMercor, 181 Fremont Street