AI Security Architect - Applied AI Security
ByLabs
About the Role
As we deploy AI agents across trading, risk, compliance, and customer systems, we're building the security architecture that keeps those systems trustworthy at scale.
This isn't a compliance checkbox role. You'll architect the security layer for systems where a compromised AI agent can authorize transactions, move funds, or access millions of user records. The threat model includes nation-state actors, sophisticated financial fraud, and the exact class of autonomous AI attack campaigns that are actively targeting financial infrastructure today.
You'll work directly with Group Risk & Security leadership to define how we build, deploy, and operate AI safely — from model selection to runtime monitoring to red team automation.
Key Responsibilities
AI System Security Architecture
- Design end-to-end security architecture for AI stack: LLM inference pipelines, AI agents, MCP-based tool orchestration, and agentic workflows
- Define trust boundaries, authorization models, and least-privilege principles for multi-agent systems
- Architect the AI Security Gateway: prompt/response inspection, rate limiting, anomaly detection, circuit breaking across all AI-powered products
Threat Modeling & Red Teaming
- Build and operate an AI-specific threat model covering prompt injection, jailbreak, model inversion, supply chain poisoning, and autonomous agent misuse
- Lead red team exercises against our AI deployments; evolve our Red vs Blue automation platform (currently in production, LLM-driven)
- Define detection signatures for AI-assisted attacks — we've seen the Hermes/Strix/Cairn class of autonomous attack campaigns firsthand
Secure AI Development Lifecycle (AI-SDL)
- Define security review processes for AI features: model selection, fine-tuning pipelines, RAG system design, tool call authorization
- Evaluate third-party AI vendors and integrations (model APIs, vector DBs, agent frameworks) for security posture
- Work with product and infra teams to embed security requirements from design through deployment
TEE & Confidential Computing
- Architect TEE-based deployments for sensitive AI inference (AMD SEV-SNP, Nvidia Confidential Computing)
- Design attestation flows, measurement coverage, and post-deployment verification — with the rigor of a Trail of Bits-level audit
Required
- 6+ years in security engineering or architecture; 2+ years focused on ML/AI systems
- Deep understanding of LLM internals: pretraining, RLHF, inference, safety alignment mechanisms — and how each layer can be attacked
- Hands-on experience with prompt injection, jailbreak research, or adversarial ML (published work, CTF, or production red team)
- Experience building or evaluating security for production AI systems (not just reading papers)
- Familiarity with AI agent frameworks: LangChain, CrewAI, OpenAI Assistants, Anthropic's tool use, MCP
Strong Signal
- Published red team research, CVEs in AI tooling, or presented at Black Hat / DEF CON / IEEE S&P on AI security topics
- Experience with TEE deployment in production (SGX/TDX/SEV-SNP)
- Background in financial services, crypto, or other high-stakes transaction systems
- Contributed to AI safety frameworks (responsible disclosure, model cards, safety evals)
Why ByLabs
- The threat surface is real. AI-powered autonomous attack campaigns are already hitting financial infrastructure. You won't be building defenses for hypothetical future threats — the Cairn-class agent that chains SQLi → RCE → AWS secrets extraction in one autonomous run is already operational against our industry.
- The scope is unusually large. We run AI across risk scoring, fraud detection, customer support, compliance screening, and internal tooling. The security architecture you design will cover all of it.
- You'll ship, not just advise. This role produces systems, not slide decks. Red team automation platform, AI security gateway, TEE attestation flows — built and running in production.
- Becoming a product. Our security capabilities are on a path to commercialization. The AI security architecture you build here will eventually be offered as a product to other exchanges and financial institutions.
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to AI Security Architect - Applied AI Security. Be the first to apply!
