Agentic AI Claims processing Threat Modelling

Job ID: 40505167

Budget: ₹600 – ₹1,500 INR

I’m looking for a seasoned threat-modelling professional who can guide me through a complete IriusRisk engagement for our AI-powered Claims Document Summarisation platform. The platform spans EDM on Azure, a TIBCO integration layer, GCP-hosted summarisation APIs that invoke Gemini / Vertex AI, and finally publishes the generated summaries back to EDM.

My top priority is understanding—and securing—the end-to-end data flow and publication path. To get there, I first need help identifying any gaps in our current architectural knowledge, deciding which artefacts we’re missing, and shaping the questions for a focused discovery workshop. Once that foundation is clear, we can move into detailed modelling and risk treatment.

Please be comfortable driving an interactive discovery phase and then producing formal artefacts directly in IriusRisk. Experience with STRIDE, GenAI-specific threat libraries, and cloud-native controls for Azure and GCP will be essential.

Key deliverables (all to be handed over in editable format):

• Discovery workshop agenda, facilitation, and outcome notes
• Reviewed and, where necessary, redrawn architecture overview
• Data Flow Diagram with clearly marked trust boundaries
• IriusRisk project file containing the full threat model
• STRIDE analysis augmented with GenAI-specific threats
• Prioritised risk register with likelihood, impact, and recommended controls
• Residual risk assessment and executive-level summary

Acceptance criteria: each threat is mapped to a concrete security control (preferably with CIS, NIST or CSA references), all risks are ranked, and residual risk is explicitly called out once controls are applied.

If you can start by outlining the questions and artefacts you’ll need from me to kick off the discovery session, let’s talk.