Corporate Security Engineer, AI

Brak informacji o wynagrodzeniu
SeniorFull-time
#396455·Dodano 10 dni temu·4
Źródło: Capital.com
Aplikuj teraz

Tech Stack / Keywords

SecurityAILLMAPICybersecurityPythonScripting

Firma i stanowisko

Capital.com is a rapidly expanding company operating in the financial services sector, focusing on regulated environments involving AI adoption and integration.

Wymagania

  • 3–5+ years in cybersecurity with hands-on experience in AI/ML system security or a strong AI security focus.
  • Deep knowledge of AI-specific security risks and mitigations including prompt injection, model poisoning, data leakage, adversarial attacks, and excessive permissions in AI agents.
  • Hands-on experience securing LLM integrations, RAG pipelines, and AI APIs including reviewing configurations, access controls, and data flows.
  • Experience authoring AI security policies, standards, and risk classification frameworks.
  • Familiarity with AI governance frameworks such as EU AI Act, NIST AI RMF, ISO/IEC 42001, and their application in regulated financial services.
  • Experience running AI risk assessments and maintaining AI risk registers.
  • Ability to manage third-party AI tool due diligence and control shadow AI across distributed workforces.
  • Proficiency in Python for automation and scripting.

Nice to have:

  • Recognised certifications like CISM, CISSP, or equivalent.
  • Experience in fintech or regulated financial services environments.
  • Multi-jurisdiction compliance exposure including FCA, CySEC, ASIC, SCB, or SCA.
  • Experience building AI-powered security automation such as autonomous agents, LLM-driven triage, and automated response workflows.
  • Experience presenting AI security risk posture to leadership or board-level audiences.

Obowiązki

AI/ML Security — Integrations & Environment:

  • Review and assess the security of AI system integrations across the corporate environment, including LLM deployments, RAG pipelines, AI APIs, and AI-enabled automation tools.
  • Evaluate configuration, access controls, and data flows of AI systems.
  • Conduct threat modelling for AI integrations and define secure deployment patterns.
  • Support security reviews for new AI initiatives, tools, and vendor integrations before production.

AI Threat Detection & Mitigation:

  • Identify and mitigate AI-specific threats such as prompt injection, jailbreaks, model poisoning, data contamination, adversarial attacks, training-data leakage, insecure model serialization, and excessive permissions in AI agents.
  • Develop guardrails, content filters, and output-validation mechanisms.
  • Implement monitoring for anomalous AI behaviour across integrated systems.

AI Data Egress & Data Protection:

  • Own data protection controls in AI contexts, governing data reaching LLM integrations, AI APIs, and AI tools.
  • Design and maintain DLP policies specifically for AI channels including share links, API-connected AI tools, AI browser extensions, and automation agents.
  • Ensure AI system compliance with GDPR, data-privacy regulations, and financial-industry data handling requirements.
  • Perform AI-specific data risk assessments aligned with internal risk methodology.

AI Tool Risk & Shadow AI:

  • Operate controls governing AI tool use across the organisation including detection policies, sanctioned-tool enforcement, share-link, and egress controls.
  • Lead third-party AI tool due diligence and ongoing assurance of AI vendor integrations.
  • Monitor AI tool usage patterns and investigate anomalous behaviour.
  • Contribute to AI security standards, internal policies, and AI risk classification framework.

Compliance & Governance:

  • Own the AI security governance framework: policy authoring, risk classification, control design, and regulatory mapping.
  • Maintain the AI risk register and report on AI-related risk posture to management.
  • Map AI security controls against regulatory frameworks including EU AI Act, NIST AI RMF, ISO/IEC 42001, GDPR, and financial-sector requirements across FCA, CySEC, ASIC, SCB, and SCA jurisdictions.
  • Participate in audit cycles; provide technical evidence and explain AI control designs to auditors and regulators.

Benefity

  • Competitive salary.
  • Work-life harmony with hybrid work arrangement.
  • Generous annual leave.
  • Employee referral program rewards.
  • Comprehensive health and pension benefits including medical insurance and pension plans.
  • Option to work remotely for up to 30 extra days per year with some restrictions (workation).
  • Two additional paid volunteer days per year.
Płatne święta
Capital.com

Capital.com

12 aktywnych ofert

Zobacz wszystkie oferty
Aplikuj teraz