
Corporate Security Engineer, AI
capital.com1 month ago
Warsaw, PolandMid Level / Senior
Responsibilities
- Assess the security of LLM deployments, RAG pipelines, AI APIs, and AI-enabled automation tools.
- Evaluate AI configurations, access controls, data flows, integrations, and secure deployment patterns.
- Threat-model AI integrations and mitigate prompt injection, jailbreaks, model poisoning, data leakage, adversarial attacks, insecure serialization, and excessive agent permissions.
- Develop guardrails, content filters, output validation, and monitoring for anomalous AI behavior.
- Own AI-specific data protection and DLP controls covering LLM integrations, AI APIs, browser extensions, share links, and automation agents.
- Govern shadow AI usage, enforce sanctioned-tool controls, investigate anomalous usage, and conduct third-party AI tool due diligence.
- Author AI security policies and standards, maintain the AI risk register, design controls, and report risk posture to management.
- Map controls to applicable AI, privacy, and financial-sector regulations and support audits with technical evidence.
Requirements
- 3–5+ years of cybersecurity experience with hands-on AI/ML system security or a strong AI security focus.
- Deep knowledge of prompt injection, model poisoning, data leakage, adversarial attacks, and excessive permissions in AI agents.
- Hands-on experience securing LLM integrations, RAG pipelines, and AI APIs, including configuration, access-control, and data-flow reviews.
- Experience authoring AI security policies, standards, and risk-classification frameworks.
- Familiarity with the EU AI Act, NIST AI RMF, and ISO/IEC 42001 in regulated financial-services environments.
- Experience conducting AI risk assessments, maintaining an AI risk register, managing third-party AI due diligence, and controlling shadow AI.
- Python proficiency for automation and scripting.
- Preferred qualifications include CISM, CISSP, or equivalent certification; fintech or regulated-finance experience; multi-jurisdiction compliance exposure; AI-powered security automation experience; and experience presenting risk posture to leadership or boards.
Benefits
- Hybrid work arrangement.
- Annual leave and work-life support.
- Medical insurance, pension benefits, and location-specific perks.
- 30 additional days to work remotely from anywhere in the world, subject to restrictions.
- Two additional paid volunteer days per year.
- Employee referral program.