| Title | AI Security Architect |
|---|---|
| Department | Information Security / AI Security / Engineering |
| Reports to | [CISO / Head of Security Architecture] |
| Location | [Remote / Hybrid / On-site] |
| Employment type | Full-time |
| Salary | [Salary range. Postings with a range perform significantly better, and several states require one.] |
Position overview
The AI Security Architect defines and drives the security architecture for [Company]'s AI and machine learning systems. This role designs controls that protect models, training data, pipelines, and AI-enabled applications from adversarial and conventional threats.
Working with security engineering, machine learning, platform, and governance teams, the AI Security Architect performs threat modeling, sets security patterns and standards, and reviews AI systems before and after deployment.
As AI moves into production and into agentic workflows, the AI Security Architect ensures AI capabilities are built and operated securely by design.
Key responsibilities
AI security architecture
- Define reference architectures and security patterns for AI and LLM systems.
- Set security requirements for model training, deployment, and inference pipelines.
- Design controls for AI agents, tool use, and orchestration.
- Establish secure-by-design standards for AI-enabled applications.
Threat modeling and assessment
Perform threat modeling and security assessments of AI systems, addressing risks such as:
- Prompt injection, jailbreaks, and data exfiltration
- Data and model poisoning and supply-chain compromise
- Model theft, inversion, and membership inference
- Insecure output handling and excessive agent permissions
Frameworks and standards
Apply the NIST AI Risk Management Framework, MITRE ATLAS, the OWASP Top 10 for LLM Applications, and ISO/IEC 27001 to shape AI security controls, testing, and standards.
Security review and testing
- Review AI systems and data flows against security requirements.
- Coordinate red teaming and adversarial testing of models and applications.
- Define logging, monitoring, and detection for AI-specific threats.
- Validate remediation of identified AI security findings.
Data and model protection
- Design controls for training data confidentiality and integrity.
- Set access, secrets, and key management patterns for AI systems.
- Protect model artifacts, weights, and endpoints.
- Address privacy-enhancing and data-minimization techniques.
Advisory and enablement
Advise engineering and machine learning teams on secure AI design, contribute to AI security policy and governance, and help build organizational capability in AI security.
Required qualifications
- Bachelor's degree in Computer Science, Cybersecurity, Information Systems, or a related discipline.
- 8 to 12+ years of experience in security architecture, application or cloud security, or security engineering, including work on AI, machine learning, or data platforms.
- Strong understanding of AI and LLM threat landscapes and secure design.
- Experience with threat modeling, security reviews, and control design.
- Ability to communicate security architecture to technical and business audiences.
Preferred certifications
One or more of: CISSP, CCSP, SABSA, GIAC security certifications, cloud security certifications.
Technical knowledge
AI and LLM security, security architecture, threat modeling, adversarial machine learning, MLOps and pipeline security, cloud and application security, identity and secrets management, red teaming, detection and monitoring, and privacy-enhancing techniques.
Essential competencies
Architectural thinking, technical influence, clear communication of risk, collaboration with engineering teams, and pragmatic control design.
About [Company]
[Two or three sentences about your organization, the maturity of your program, and what the first year looks like. Candidates in this field respond to honesty about whether they are joining a build or an established function.]
Post this role on GRC Careers
Reach professionals who specialize in AI and machine learning security rather than hoping they find you in a general feed. Hand reviewed, live within one business day.
See how others are hiring
Review live AI governance jobs postings to benchmark scope, level, and posted salary before you publish yours.
Stay close to the market
Job alerts
Get new AI governance jobs roles sent to you as they post.
Newsletter
Hiring trends, salary signals, and new templates from GRC Careers.
Frequently asked questions
What does an AI Security Architect do?
An AI Security Architect designs the security architecture for AI and machine learning systems. They set secure-by-design patterns, perform threat modeling, coordinate adversarial testing, and define controls that protect models, data, and pipelines in production.
What qualifications and certifications does an AI Security Architect need?
Most AI Security Architects bring 8 to 12 or more years in security architecture, application, cloud, or security engineering, with AI or machine learning exposure. Common certifications include CISSP, CCSP, and SABSA, alongside cloud security credentials.
What frameworks does an AI Security Architect use?
Common reference points include the NIST AI Risk Management Framework, MITRE ATLAS, the OWASP Top 10 for LLM Applications, and ISO/IEC 27001, applied to AI-specific threats and controls.
What AI-specific threats does an AI Security Architect defend against?
The role addresses threats such as prompt injection and jailbreaks, data and model poisoning, model theft and inversion, insecure output handling, and excessive permissions granted to AI agents.