What You'll Do:AI Security Architecture: Architect and maintain secure approaches for implementing AI platforms, agentic AI systems, AI agents, and AI-generated code, ensuring alignment with security policies and regulatory requirements.
AI Update & Change Review: Review AI platform updates, feature releases, and configuration changes across the Bank's AI ecosystem; assess security impact and recommend remediation or safeguards before adoption.
AI Security Controls Implementation: Design, configure, and optimize security controls for AI systems, including access controls, guardrails, data protection, logging, and monitoring, to improve visibility, detection, and protection.
AI Data Protection: Identify, document, and help govern how sensitive data and personally identifiable information flow into and out of AI platforms, supporting data classification, labeling, and DLP practices for AI use.
Agentic AI & Connector Security: Evaluate and secure agentic AI capabilities, connectors, plugins, and integrations, applying least-privilege permissions and monitoring across users, departments, and platforms.
AI Security Assessments: Perform security assessments of AI tools, models, services, and configurations to validate alignment with internal standards, bank AI policy, and industry frameworks such as the NIST AI RMF.
Research & Gap Analysis: Evaluate emerging AI security products, threats, and techniques such as prompt injection, model abuse, and data leakage; perform comparative analysis to identify opportunities to improve the Bank's AI security posture.
Cross-Functional Collaboration: Partner with Information Technology, Risk, Compliance, and business stakeholders to implement AI security initiatives, communicate findings, and support secure AI adoption.
Continuous Improvement: Monitor evolving AI threats, platform changes, and emerging best practices to help keep the Bank's AI security capabilities current and effective.
Secure AI Development: Support secure use of AI in development, including review of AI-generated code, secure coding guardrails, and integration of AI security checks into development workflows.
Perform Monitoring: Provide metrics, including KPIs and KRIs, supporting appropriate AI security monitoring and underlying processes.
What Do You Need?Must-Haves- 5-7+ years' experience in security engineering, architecture, or operations, with hands-on exposure to AI/ML platforms or AI security.
- Strong knowledge of AI platforms and services (e.g., Azure Foundry, Microsoft Copilot, Claude, ChatGPT/OpenAI, GitHub Copilot), including native security and governance capabilities.
- Experience reviewing and managing security configurations for AI tools, connectors, and integrations.
- Hands-on experience with configuring and maintaining security tools (SIEM, EDR, DLP, IAM, CASB) and applying them to AI use cases.
- Solid understanding of AI concepts including large language models, agentic AI, RAG, APIs, and associated risks (prompt injection, data leakage, model abuse).
- Bachelor's degree in Information Security, Computer Science, or related field, or equivalent work experience.
Key Skills- Strong troubleshooting and analytical skills.
- Ability to balance security needs with business requirements.
- Excellent communication skills, with the ability to translate technical findings into clear, actionable recommendations.
- Proficiency in Microsoft Office applications for reporting and documentation.
Nice-to-Haves- Security or AI certifications such as CISSP, CCSP, AZ-500, IAPP AIGP, or ISO/IEC 42001 training.
- Experience with Microsoft Purview, Defender for Cloud Apps, Splunk, and AI usage monitoring or model governance tools.
- Knowledge of DevSecOps practices and integrating AI security reviews into CI/CD pipelines.
- Banking or financial services industry experience; familiarity with FFIEC guidance and NIST AI RMF.
Technology Skills:- Ability to work with the Microsoft Suite and learn/work with other Customers Bank's applications.
- Expertise with AI and automation tools that support productivity, workflow efficiency, and client engagement.