Full-Time

Senior Infrastructure and IT Engineer

Updated on 8/23/2026

NTT DATA AIVista

NTT DATA AIVista

11-50 employees

Runs governance-driven enterprise AI workloads

Compensation Overview

$150k - $190k/yr

Bellevue, WA, USA

In Person

The role is onsite in Bellevue.

Category
IT & Security (2)
,
Required Skills
Claude
Microsoft Azure
SOC 2
AWS
JIRA
Google Cloud Platform

Get referred to NTT DATA AIVista

See people who can refer or advise you

Requirements
  • The candidate must have 5–8 years of experience in IT operations, systems administration, or IT engineering.
  • The candidate must have hands-on experience with mobile device management platforms such as Jamf, Intune, or an equivalent, including zero-touch device deployment.
  • The candidate must have strong experience with identity and access management systems such as Okta, Microsoft Entra ID/Azure Active Directory, or an equivalent, as well as multifactor authentication and single sign-on.
  • The candidate must be proficient in administering software-as-a-service platforms such as Microsoft 365, Slack, Notion, and Google Workspace.
  • The candidate must have hands-on experience operating compliance and security tooling such as Vanta or an equivalent, with working familiarity with SOC 2 and/or ISO 27001 controls.
  • The candidate must have experience running access reviews, collecting audit evidence, and maintaining IT controls documentation.
  • The candidate must be cloud-literate and comfortable with cloud consoles and identity and access management basics in AWS, Azure, or Google Cloud Platform to support access, identity, and integrations.
  • The candidate must have experience managing IT ticketing systems such as Linear, Jira, or an equivalent, and owning service-level agreement accountability.
  • The candidate must be able to support both technical and non-technical stakeholders.
  • The candidate must be comfortable operating in a fast-paced startup environment with a high degree of autonomy.
Responsibilities
  • Own employee onboarding and offboarding IT processes end-to-end, including device provisioning and access setup.
  • Manage endpoint security and mobile device management, including zero-touch deployment and device compliance.
  • Administer identity and access management systems, including single sign-on, multifactor authentication, YubiKeys, and 1Password.
  • Manage software-as-a-service platforms including Notion, Slack, Microsoft 365, Ramp, DocuSign, Zoom, ChatGPT, and Claude.
  • Own IT asset inventory, purchasing, and lifecycle management.
  • Own IT setup, infrastructure, and support for the Bellevue office, and support the wider workforce.
  • Manage the IT help desk and support-ticket resolution via Linear, and own service-level agreement performance and reporting.
  • Operate day-to-day compliance in Vanta or a similar platform, including evidence collection, continuous control monitoring, and alert remediation.
  • Implement and maintain IT controls supporting SOC 2 and ISO 27001 programs owned by the Security team.
  • Run periodic user access reviews and remediate access gaps.
  • Apply security baselines and policies defined by the Security team across endpoints, identity, and software-as-a-service platforms.
  • Support NTT DATA group IT and security compliance requirements.
  • Maintain IT controls documentation.
  • Identify and implement process improvements to scale IT operations as the company grows.
  • Support executive meetings and onsite events with IT logistics.
Desired Qualifications
  • Experience at a technology or artificial intelligence company.

NTT DATA AIVista is a subsidiary of NTT DATA that helps large enterprises deploy AI in regulated environments by turning complex workflows into agentic AI systems through a Service-As-Software platform. It uses last-mile AI specialization to tailor foundation models to an organization’s specific domain, governance, and policies, enabling native workflow integration, deep domain expertise, and enterprise-grade governance to run AI safely and at scale. The platform pieces together AI software with the company’s existing processes and systems, leveraging NTT DATA’s industry knowledge and systems integration experience. The goal is to accelerate enterprise AI adoption, reduce costs, and improve reliability by operating within regulatory and policy constraints while delivering faster outcomes in mission-critical workflows such as finance and healthcare.

Company Size

11-50

Company Stage

N/A

Total Funding

N/A

Headquarters

N/A

Founded

2025

Get referred to NTT DATA AIVista

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • NTT DATA signed an AWS collaboration in February 2026 for agentic AI adoption.
  • May 2026 WinWire acquisition adds over 1,000 Azure engineers and AI specialists.
  • NTT DATA targets $2 billion from AI-native businesses by 2027, backing AIVista spend.

What critics are saying

  • AIVista launched December 1, 2025; it still lacks public customer traction.
  • AWS, Google Cloud, OpenAI, and Salesforce push similar agentic offerings into NTT DATA accounts.
  • Security and audit failures around agent permissions can block regulated deployments and kill trust.

What makes NTT DATA AIVista unique

  • Bratin Saha, ex-AWS and NVIDIA, gives AIVista rare product-to-scale execution.
  • AIVista combines AI products with NTT DATA's regulated-industry delivery and integration muscle.
  • Its service-as-software model targets last-mile specialization, not generic foundation-model wrappers.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

Dental Insurance

Vision Insurance

401(k) Retirement Plan

Health Savings Account/Flexible Spending Account

Paid Holidays

Hybrid Work Options

Company News

NOVALOGIQ
Jul 30th, 2026
NTT DATA AIVista and Snowflake: Identity alone won't secure enterprise AI agents.

NTT DATA AIVista and Snowflake: Identity alone won't secure enterprise AI agents. Presented by NTT DATA AIVista VentureBeat's June research found that 69% of enterprises are still running AI agents that share credentials, a practice associated with higher rates of security incidents and near-incidents. But at VB Transform 2026, Mukesh Karki, CTO of NTT DATA AIVista, and Mayank Upadhyay, chief security and trust officer at Snowflake, argued that fixing identity is only the first step. Enterprises also need action-level authorization and tamper-resistant audit trails built into every agent interaction if they're going to deploy autonomous systems safely at scale. "These organizations need to be able to prove to their auditors in a very tamper-resistant fashion that those records showing what they did actually prove what they're doing," Karki said. "And the provability is essentially your license to operate in a regulatory environment." Why shared credentials cause agentic AI security incidents. The problem, Upadhyay says, is many assumptions were carried over from an earlier generation of software. "In the traditional software world, a human being clicks somewhere and the software does something very deterministic, and you know which API it's going to call," he said. "But in the agentic world, the software has a brain of its own, and it's constantly rewiring itself. If you give this software more permission than it needs for a particular goal, agents are exploratory by nature, so they're going to try lots of different things, and you'll have unintended side effects." Embedding a single static API key compounds the exposure, he added. "It's a really bad pattern if you have one API key, you shove it into the agent, and it's talking as anybody to a particular SaaS service, because then you're giving this agent the union of everybody's needs," he said, noting that the second failure mode is forensic, since "things may go wrong, and you wouldn't be able to attribute it to the right agent." Scoped credentials are only the starting point in regulated industries. Karki, whose clients are mostly in insurance, healthcare, and finance, treats scoped credentials as table stakes. "In a regulatory setting, an agent that's not broadly scoped with shared scope credentials is not going to run, period," Karki said. "Having a scope credential is just a starting point. There are actually two layered constraints. One is the jurisdiction in which the agent operates, and then it's the jurisdiction or the rules of that organization." For instance, a claims adjustment agent in Washington State operates on different regulations than one in California, he adds, and every claim is different. "Those scoped credentials are not enough, because it has to be action-based and rules-based at the time it's taking action," he added. Where the employee analogy for AI agents breaks down. The employee analogy, Karki argued, only goes so far. Agents still need to learn an organization's unique context, much as a new employee does. But unlike people, enterprises can't realistically build trust with thousands of agents over time. "A star employee in one organization might not be the best employee when they move to a different organization, not because they became worse, but because they don't have the context of this new place, and the same is true with agents," Karki said. "If every employee has 100 agents, you can't say you're going to onboard these agents and do a background check on them." Upadhyay said the employee analogy should place agents one rung lower in the organizational hierarchy. "Treat them like interns," he suggested. "They have good intent, but they don't always know what they're doing, and you have to keep your eye on them while you gradually build trust." On the Snowflake platform, administrators can impose platform-wide guardrails such as read-only operations, while developers further narrow an agent's permissions when they launch each session. A three-layer approach to AI agent governance. There's no question where governance belongs, Karki says. "Governance has to happen at every agent action, and it has to sit outside the agent," he explained. "That's the only way you'll be able to prove later that the agent took an action it was allowed to take." Upadhyay broke governance into three layers: The agent layer covers identity, tool permissions, and MCP governance. The model layer addresses indirect prompt injection and enables models to run inside the customer's VPC so prompts remain invisible to the model provider. The data layer covers least-privilege access, zero-copy architecture, and role-based access control. For agents to work properly, governance is required across all three. What enterprises should audit first. For enterprises auditing the governance of existing AI agents, Upadhyay recommends starting in two places. The first is auditing permissions for static secrets, the largest fixable attack vector. Next is addressing shadow AI through an MCP gateway, so developers no longer have to run bootlegged open-source MCP servers under their desks and administrators have visibility into who's talking to which MCP server. There's a tradeoff between constraint and capability, and that can be addressed at the task level, with confidence scoring used to withhold autonomous execution on high-risk actions, and sandboxing as a middle path. But Karki cautions enterprises already scaling their agentic systems. "A lot of this can't be retrofitted after you have an agentic system running, and it's even harder to retrofit if you have to prove to your auditors why exactly the agent behaved the way it did," he explained. "Provability has to be built ground up when you're designing the system." Sponsored articles are content produced by a company that is either paying for the post or has a business relationship with VentureBeat, and they're always clearly marked. For more information, contact [email protected].