Corporate Security Engineer, AI
Brak informacji o wynagrodzeniu
SeniorFull-time
#396455·Dodano 10 dni temu·4
Źródło: Capital.comTech Stack / Keywords
SecurityAILLMAPICybersecurityPythonScripting
Firma i stanowisko
Capital.com is a rapidly expanding company operating in the financial services sector, focusing on regulated environments involving AI adoption and integration.
Wymagania
- 3–5+ years in cybersecurity with hands-on experience in AI/ML system security or a strong AI security focus.
- Deep knowledge of AI-specific security risks and mitigations including prompt injection, model poisoning, data leakage, adversarial attacks, and excessive permissions in AI agents.
- Hands-on experience securing LLM integrations, RAG pipelines, and AI APIs including reviewing configurations, access controls, and data flows.
- Experience authoring AI security policies, standards, and risk classification frameworks.
- Familiarity with AI governance frameworks such as EU AI Act, NIST AI RMF, ISO/IEC 42001, and their application in regulated financial services.
- Experience running AI risk assessments and maintaining AI risk registers.
- Ability to manage third-party AI tool due diligence and control shadow AI across distributed workforces.
- Proficiency in Python for automation and scripting.
Nice to have:
- Recognised certifications like CISM, CISSP, or equivalent.
- Experience in fintech or regulated financial services environments.
- Multi-jurisdiction compliance exposure including FCA, CySEC, ASIC, SCB, or SCA.
- Experience building AI-powered security automation such as autonomous agents, LLM-driven triage, and automated response workflows.
- Experience presenting AI security risk posture to leadership or board-level audiences.
Obowiązki
AI/ML Security — Integrations & Environment:
- Review and assess the security of AI system integrations across the corporate environment, including LLM deployments, RAG pipelines, AI APIs, and AI-enabled automation tools.
- Evaluate configuration, access controls, and data flows of AI systems.
- Conduct threat modelling for AI integrations and define secure deployment patterns.
- Support security reviews for new AI initiatives, tools, and vendor integrations before production.
AI Threat Detection & Mitigation:
- Identify and mitigate AI-specific threats such as prompt injection, jailbreaks, model poisoning, data contamination, adversarial attacks, training-data leakage, insecure model serialization, and excessive permissions in AI agents.
- Develop guardrails, content filters, and output-validation mechanisms.
- Implement monitoring for anomalous AI behaviour across integrated systems.
AI Data Egress & Data Protection:
- Own data protection controls in AI contexts, governing data reaching LLM integrations, AI APIs, and AI tools.
- Design and maintain DLP policies specifically for AI channels including share links, API-connected AI tools, AI browser extensions, and automation agents.
- Ensure AI system compliance with GDPR, data-privacy regulations, and financial-industry data handling requirements.
- Perform AI-specific data risk assessments aligned with internal risk methodology.
AI Tool Risk & Shadow AI:
- Operate controls governing AI tool use across the organisation including detection policies, sanctioned-tool enforcement, share-link, and egress controls.
- Lead third-party AI tool due diligence and ongoing assurance of AI vendor integrations.
- Monitor AI tool usage patterns and investigate anomalous behaviour.
- Contribute to AI security standards, internal policies, and AI risk classification framework.
Compliance & Governance:
- Own the AI security governance framework: policy authoring, risk classification, control design, and regulatory mapping.
- Maintain the AI risk register and report on AI-related risk posture to management.
- Map AI security controls against regulatory frameworks including EU AI Act, NIST AI RMF, ISO/IEC 42001, GDPR, and financial-sector requirements across FCA, CySEC, ASIC, SCB, and SCA jurisdictions.
- Participate in audit cycles; provide technical evidence and explain AI control designs to auditors and regulators.
Benefity
- Competitive salary.
- Work-life harmony with hybrid work arrangement.
- Generous annual leave.
- Employee referral program rewards.
- Comprehensive health and pension benefits including medical insurance and pension plans.
- Option to work remotely for up to 30 extra days per year with some restrictions (workation).
- Two additional paid volunteer days per year.
Płatne święta
Capital.com
12 aktywnych ofert