
In Progress
Posted
Paid on delivery
I’m looking for a seasoned threat-modelling professional who can guide me through a complete IriusRisk engagement for our AI-powered Claims Document Summarisation platform. The platform spans EDM on Azure, a TIBCO integration layer, GCP-hosted summarisation APIs that invoke Gemini / Vertex AI, and finally publishes the generated summaries back to EDM. My top priority is understanding—and securing—the end-to-end data flow and publication path. To get there, I first need help identifying any gaps in our current architectural knowledge, deciding which artefacts we’re missing, and shaping the questions for a focused discovery workshop. Once that foundation is clear, we can move into detailed modelling and risk treatment. Please be comfortable driving an interactive discovery phase and then producing formal artefacts directly in IriusRisk. Experience with STRIDE, GenAI-specific threat libraries, and cloud-native controls for Azure and GCP will be essential. Key deliverables (all to be handed over in editable format): • Discovery workshop agenda, facilitation, and outcome notes • Reviewed and, where necessary, redrawn architecture overview • Data Flow Diagram with clearly marked trust boundaries • IriusRisk project file containing the full threat model • STRIDE analysis augmented with GenAI-specific threats • Prioritised risk register with likelihood, impact, and recommended controls • Residual risk assessment and executive-level summary Acceptance criteria: each threat is mapped to a concrete security control (preferably with CIS, NIST or CSA references), all risks are ranked, and residual risk is explicitly called out once controls are applied. If you can start by outlining the questions and artefacts you’ll need from me to kick off the discovery session, let’s talk.
Project ID: 40505167
10 proposals
Remote project
Active 5 days ago
Set your budget and timeframe
Get paid for your work
Outline your proposal
It's free to sign up and bid on jobs

Hi there, I’ve spent several years securing AI pipelines that span Azure EDM, GCP GenAI services and complex integration layers—exactly the stack you described for your claims‑summarisation platform. Here’s how I work: ? Build the core artefacts within 24 hrs once the requirements are locked‑down. ? Daily progress videos + screen‑time logs via our [login to view URL] tracker. ? Real‑time ticketing for any change requests during the engagement. Your focus on end‑to‑end data flow security and a comprehensive IriusRisk model is spot on. I can deliver: ✅ Facilitated discovery workshop agenda, notes and refined architecture diagram (Azure, GCP, TIBCO). ✅ Data Flow Diagram with explicit trust boundaries, ready for IriusRisk import. ✅ Full STRIDE + GenAI threat library analysis, mapped to CIS/NIST/CSA controls. ✅ Prioritised risk register with likelihood, impact, recommended mitigations and residual risk summary. I have 14 years of full‑stack and cloud security experience, including multiple engagements modeling threats for Azure and GCP workloads using IriusRisk and industry‑standard frameworks. Could you share any existing architecture docs or API specs you have so I can prep the discovery questions? Looking forward to shaping a secure foundation for your platform. Best regards, Dinesh Kumar Full Stack Web & Mobile App Developer
₹1,050 INR in 7 days
0.0
0.0
10 freelancers are bidding on average ₹935 INR for this job

Hi! The mix of Azure EDM, TIBCO, and GCP-powered GenAI summarisation is a real-world tangle—especially with data moving between clouds and into/out of AI pipelines. Your focus on clear trust boundaries and GenAI threat libraries makes sense given the risks. I’ve led threat modelling sessions for SaaS with cloud+AI flows before, including hands-on IriusRisk and STRIDE with GenAI libraries. Mapping data movement and publishing back to EDM is a sticking point I’ve seen catch teams out before. First, I’d draft a list of artefacts and stakeholder questions for the discovery, then plan the workshop to surface where the model is thin or assumptions are untested. Outcomes feed straight into IriusRisk and a risk register, with NIST controls suggested for each mapped risk. Quick question: do you already have a formal data flow or architecture diagram, or do we need to build that from scratch at the workshop? Happy to send a sample outline of discovery questions and artefacts I’d use. For other high-security SaaS work, you’ll find examples at work.techindika.com. — Pradeep
₹1,050 INR in 7 days
3.2
3.2

I have experience in security architecture reviews, threat modeling, and cloud-native risk assessments across Azure, GCP, and AI/LLM-based platforms. I can lead the discovery workshops, create DFDs with trust boundaries, build the complete IriusRisk threat model, perform STRIDE and GenAI-specific analysis, map risks to NIST/CIS/CSA controls, and deliver a prioritized risk register with residual risk assessment and executive-ready documentation.
₹1,050 INR in 7 days
3.0
3.0

Hi, I can help you run a complete IriusRisk threat modelling engagement for your Agentic AI claims summarisation platform across Azure EDM, TIBCO, and GCP (Gemini/Vertex AI). I will first focus on a structured discovery phase to map end-to-end data flow, trust boundaries, and AI invocation points to identify gaps before formal modelling. Example: I would trace a claim document from Azure ingestion → TIBCO orchestration → GCP AI summarisation → return to EDM, highlighting risks like data leakage, insecure API chaining, and prompt injection across each boundary. Deliverables: • Discovery workshop agenda + notes • Architecture review and improved diagrams • Data Flow Diagram with trust boundaries • STRIDE + GenAI threat modelling • IriusRisk project file • Prioritised risk register with controls • Residual risk summary To start, I need: • Current architecture diagrams • Data classification details • API flows between Azure/TIBCO/GCP • Auth model and security controls • AI prompt/usage flow I can begin with the workshop structure immediately.
₹1,050 INR in 7 days
1.0
1.0

Hello, My background is primarily in AI systems, cloud architectures, enterprise integrations, and secure application development, which makes this project particularly interesting to me. I have worked on AI-powered platforms involving RAG pipelines, embeddings, OpenAI/Gemini integrations, workflow automation, Azure/GCP deployments, API security, and multi-service enterprise architectures where sensitive data moves across several systems. For your engagement, I would begin by mapping the complete flow from EDM → TIBCO → Gemini/Vertex AI → EDM, identifying missing architectural artifacts, trust boundaries, authentication flows, data classifications, and AI-specific attack surfaces before moving into detailed threat modeling. My experience includes: • AI/LLM and GenAI integrations • Azure & GCP cloud architectures • API security and authentication • OWASP security reviews • SonarQube and OWASP ZAP assessments • Enterprise workflow and integration platforms Given the GenAI component, I understand the importance of assessing risks such as prompt injection, data leakage, unauthorized access, output manipulation, model misuse, and cross-system trust boundary violations. I'd be happy to discuss the current architecture and help identify the key artifacts and questions needed to kick off the discovery phase. Best Regards, Kshitij
₹600 INR in 5 days
0.6
0.6

Hello, I am a Backend Developer and Team Lead with 4+ years of experience in API development, system architecture, cloud integrations, and technical documentation. I can assist in reviewing application architecture, mapping end-to-end data flows, documenting integration points, creating technical diagrams, and identifying potential security considerations across Azure, GCP, and API-based systems. My experience includes designing scalable backend solutions, leading development teams, and working closely with stakeholders to understand business and technical requirements. I would be happy to discuss your architecture and requirements further. Regards, Daman Ohri
₹1,050 INR in 7 days
0.0
0.0

Scope Understanding: Your AI claims platform needs a clear, security-focused threat model that maps the full Azure–TIBCO–GCP–Gemini data flow, trust boundaries, GenAI risks, and residual exposure before risk treatment decisions are made. Who we are: SCAIMLON LABS PVT. LTD. is a Bengaluru & Chennai-based Cloud MSP and certified Microsoft Azure, AWS, and Google Partner. Your Ask: Lead discovery, identify missing architecture artefacts, create DFDs, build the IriusRisk threat model, perform STRIDE with GenAI-specific threats, and deliver ranked risks with mapped controls. Our Solution Approach: We will run a focused discovery workshop, review/redraw architecture, define data flows and trust boundaries, model threats in IriusRisk, map controls to CIS/NIST/CSA, prepare the risk register, and document residual risk. Deliverables: Workshop notes, architecture review, DFD, IriusRisk model, STRIDE analysis, risk register, executive summary. Relevant Experience: Firepack needed secure cloud architecture review. Platform: AWS. Problem solved: threat-aware design, access control, and risk documentation. Outcome: clearer security posture and handover-ready artefacts. Call to Action: If you need a structured IriusRisk engagement that connects AI threats to real controls and executive-ready risk decisions, SCAIMLON LABS is ready to deliver. Happy to jump on a quick call to walk you through our approach before you decide.
₹850 INR in 8 days
0.0
0.0

Delhi, India
Payment method verified
Member since Sep 2, 2015
₹600-1500 INR
₹600-1500 INR
₹600-1500 INR
₹600-1500 INR
₹1500-12500 INR
€30-250 EUR
min $50 USD / hour
₹600-1500 INR
$250-750 AUD
$30-250 USD
$250-750 USD
₹100-400 INR / hour
₹37500-75000 INR
$15-25 USD / hour
$750-1500 USD
$10-30 USD
£250-750 GBP
₹12500-37500 INR
₹750-1250 INR / hour
$750-1500 USD
$10-30 USD
$250-750 USD
₹37500-75000 INR
min $50 USD / hour