Senior AI Security Architect / GenAI Security Architect (m/f/d) – Banking
- Employment type
- Contract
- Workload
- 100%
- Location
- Zürich
- Company
- Swisslinx AG, 8001 Zürich
- First posted
For a long-term mandate at a leading Swiss financial institution, we are looking for an experienced Senior AI Security Architect with a sound background in Cyber Security, Cloud/Application Security, as well as modern GenAI, LLM, and RAG architectures.
Senior AI Security Architect / GenAI Security Architect (m/f/d) – Banking
Job description:
- Conception and further development of a holistic security architecture for AI/GenAI use cases
- Development of AI-specific threat models for LLM, RAG, and agentic architectures
- Identification and assessment of risks such as Prompt Injection, Jailbreaking, Model Manipulation, Data Poisoning, Data Leakage, Insecure Output Handling, and security-relevant hallucinations
- Derivation and definition of suitable preventive and detective security controls
- Establishment of Security-by-Design for RAG applications, retrieval processes, vector databases, and connected knowledge sources
- Ensuring existing authorization models within AI/RAG contexts
- Avoidance of cross-user and cross-tenant leakage, unauthorized information aggregation, and data outflow
- Development of identity, authorization, and trust concepts for users, models, agents, and tools
- Definition of role and authorization concepts according to least-privilege principles
- Securing agent-to-tool and agent-to-agent communication
- Conception of security mechanisms for autonomous agents as well as control of critical or privileged actions
- Development of reusable AI security guardrails
- Conception of mechanisms for input/output validation, prompt and context protection, content filtering, and policy enforcement
- Definition of security requirements for tool/plugin approvals, secrets handling, and sandboxing
- Development of monitoring, logging, and detection concepts for AI-based applications
- Translation of technical AI risks into comprehensible architecture, governance, and control requirements
- Close cooperation with Security, Enterprise Architecture, Engineering, Operations, Infrastructure, as well as business and IT stakeholders
- Advising technical and non-technical stakeholders on AI security risks and suitable protective measures
About the customer:
The role is part of a strategically relevant AI/Security environment and focuses on building a holistic security architecture for modern AI usage scenarios. These include, among others, chat-based interactions, Retrieval-Augmented-Generation applications, agentic workflows, and the use of Foundation Models.
The goal is to systematically address new attack surfaces and trust boundaries between users, models, agents, tools, data sources, and external services and to enable secure, controllable, and regulatorily compliant AI solutions.
Framework conditions:
- Zürich / Hybrid
- Start: November 2026
- Duration: until February 2028
- Workload: 100%
Requirements:
- Several years of professional experience as a Security Architect, Cyber Security Architect, Cloud Security Architect, Application Security Architect, or comparable role
- Sound experience in the development and implementation of Security-by-Design concepts
- Very good knowledge in the area of Threat Modeling
- Sound technical understanding of modern GenAI, LLM, RAG, and agentic architectures
- Experience with the security risks of modern AI systems, especially Prompt Injection, Jailbreaking, Data Leakage, Model Manipulation, and Insecure Output Handling
- Good knowledge in Identity & Access Management, Authorization, Role-Based Access Control, Least Privilege, and Trust Models
- Experience with security concepts for APIs, microservices, cloud platforms, and complex enterprise applications
- Experience with monitoring, logging, detection, and security controls in complex system landscapes
- Ability to analyze technical risks in a structured manner and translate them into concrete architecture and control requirements
- Strong communication skills towards technical teams, architecture, management, and business departments
- Experience in a regulated environment, ideally Banking, Financial Services, or Insurance, is an advantage
- Practical experience with the securing of productive LLM, j4id10426461a j4it1041a j4iy26a
Automatically translated from the original.
Posted yesterday