Corporate Security Engineer, AI
TLDR
Secure AI adoption by governing AI integrations, threat detection, data protection, and third-party tool risk in a regulated financial services environment.
AI/ML Security — Integrations & Environment:
-
Review and assess the security of AI system integrations across the corporate environment: LLM deployments, RAG pipelines, AI APIs, and AI-enabled automation tools
-
Evaluate configuration, access controls, and data flows of AI systems — the security of how AI is deployed and connected to corporate data and infrastructure
-
Conduct threat modelling for AI integrations and define secure deployment patterns for AI-powered tools
-
Support security reviews for new AI initiatives, tools, and vendor integrations before they reach production
-
Identify and mitigate AI-specific threats: prompt injection & jailbreaks, model poisoning & data contamination, adversarial attacks, training-data leakage, insecure model serialisation, excessive permissions in AI agents
-
Develop guardrails, content filters, and output-validation mechanisms
-
Implement monitoring for anomalous AI behaviour across integrated systems
-
Own data protection controls in AI contexts: govern what data reaches LLM integrations, AI APIs, and AI-enabled tools
-
Design and maintain DLP policies specifically for AI channels — share links, API-connected AI tools, AI browser extensions, and automation agents
-
Ensure AI system compliance with GDPR, data-privacy regulations, and financial-industry data handling requirements
-
Perform AI-specific data risk assessments aligned with the internal risk methodology
-
Operate the controls that govern AI tool use across the organisation — detection policies, sanctioned-tool enforcement, share-link and egress controls
-
Lead third-party AI tool due diligence and ongoing assurance of AI vendor integrations
-
Monitor AI tool usage patterns and investigate anomalous behaviour
-
Contribute to AI security standards, internal policies, and the company's AI risk classification framework
-
Own the AI security governance framework: policy authoring, risk classification, control design, and regulatory mapping
-
Maintain the AI risk register and report on AI-related risk posture to management
-
Map AI security controls against applicable regulatory frameworks: EU AI Act, NIST AI RMF, ISO/IEC 42001, GDPR, and financial-sector requirements across FCA, CySEC, ASIC, SCB, and SCA jurisdictions
-
Participate in audit cycles; provide technical evidence and explain AI control design to auditors and regulators
AI Threat Detection & Mitigation:
AI Data Egress & Data Protection:
AI Tool Risk & Shadow AI:
Compliance & Governance:
-
3–5+ years in cybersecurity with hands-on experience in AI/ML system security or a strong AI security focus;
-
Deep knowledge of AI-specific security risks and mitigations: prompt injection, model poisoning, data leakage, adversarial attacks, excessive permissions in AI agents;
-
Hands-on experience securing LLM integrations, RAG pipelines, and AI APIs — reviewing configurations, access controls, and data flows;
-
Experience authoring AI security policies, standards, and risk classification frameworks;
-
Familiarity with AI governance frameworks: EU AI Act, NIST AI RMF, ISO/IEC 42001, and their application in a regulated financial services context;
-
Experience running AI risk assessments and maintaining an AI risk register;
-
Ability to manage third-party AI tool due diligence and control shadow AI across a distributed workforce;
-
Python proficiency for automation and scripting.
-
Recognised certifications: CISM, CISSP, or equivalent;
-
Experience in fintech or a regulated financial services environment;
-
Multi-jurisdiction compliance exposure (FCA, CySEC, ASIC, SCB, or SCA);
-
Experience building AI-powered security automation — autonomous agents, LLM-driven triage, automated response workflows;
-
Experience presenting AI security risk posture to leadership or board-level audiences.
-
Strong analytical and problem-solving skills;
-
Ability to translate technical AI risk into business and regulatory impact;
-
Able to explain AI security risks and mitigations to non-security teams;
-
Cross-functional collaboration with risk, compliance, product, and engineering teams;
-
Clear documentation and communication skills.
• Competitive Salary: We believe great work deserves great pay! Your skills and talents will be rewarded with a salary that makes you feel valued and motivated.
• Work-Life Harmony: Join a company that genuinely cares about you - because your life outside of work matters just as much as your time on the clock. #LI-Hybrid
• Generous Time Off: Need a breather? Our annual leave policy lets you recharge and enjoy life outside of work without a worry.
• Employee Referral Program: Love working here? Share the love! Bring your talented friends on board and get rewarded for growing our awesome team.
• Comprehensive Health & Pension Benefits: From medical insurance to pension plans, we’ve got your back. Plus, location-specific benefits and perks!
• Workation Wonderland: Live your digital nomad dreams with 30 extra days to work remotely from anywhere in the world (some restrictions apply). Adventure awaits!
• Volunteer Days: Make a difference! Take two additional paid days each year to support causes you care about and give back to the community.
Be a key player at the forefront of the digital assets movement, propelling your career to new heights! Join a dynamic and rapidly expanding company that values and rewards talent, initiative, and creativity. Work alongside one of the most brilliant teams in the industry.
Benefits
Health Insurance
Comprehensive Health & Pension Benefits: From medical insurance to pension plans, we’ve got your back. Plus, location-specific benefits and perks!
Paid Time Off
Volunteer Days: Make a difference! Take two additional paid days each year to support causes you care about and give back to the community.
Remote-Friendly
Workation Wonderland: Live your digital nomad dreams with 30 extra days to work remotely from anywhere in the world (some restrictions apply). Adventure awaits!
Capital.com is an innovative trading platform designed for a global audience, offering top-rated financial products that emphasize a seamless user experience. We're committed to pushing the boundaries of technology in the trading industry, making it easy for users to access the financial markets and achieve their investment goals.
- Founded
- Founded 2016
- Employees
- 201-500 employees
- Industry
- Internet Software & Services
- Total raised
- $25M raised