Senior Principal Architect Cyber Security AI positions focus on delivering results in their domain. This page aggregates open Senior Principal Architect Cyber Security AI roles and what employers typically expect.
## Company Description Reporting to the Director of Cyber Security Architecture, the Senior Principal Cyber Security Architect – AI will act as the lead security architecture advisor for AI-related initiatives across the organisation. The role will provide strategic and technical guidance to ensure that AI systems, platforms, models, data pipelines, development environments, and third-party AI services are designed, deployed, and operated securely. Working closely with cyber security, engineering, data science, AI/ML, cloud, privacy, legal, risk, compliance, and product teams, the role will identify AI-specific security risks and define practical controls that protect the confidentiality, integrity, availability, privacy, and resilience of AI-enabled services. The role will help shape and mature the organisation’s AI security architecture, governance, standards, control framework, and secure-by-design patterns. Key areas of focus include secure AI architecture, GenAI and LLM security, MLOps security, data protection, model security, AI threat modelling, third-party AI assurance, security testing, incident readiness, and continuous control improvement. ## Job Description - Provide senior security architecture leadership for AI initiatives, ensuring AI systems and services are secure by design and aligned with enterprise cyber security strategy, risk appetite, and regulatory expectations. - Define and maintain AI security principles, standards, guardrails, reference architectures, design patterns, and production readiness criteria across the AI lifecycle. - Advise on secure architecture for AI platforms, MLOps pipelines, data pipelines, model registries, vector databases, RAG solutions, prompt orchestration layers, APIs, AI agents, and cloud-based AI services. - Design and support implementation of security controls across identity and access management, privileged access, secrets management, encryption, key management, network security, secure APIs, logging, monitoring, resilience, and incident response. - Conduct AI-focused risk assessments, threat modelling, architecture reviews, and control gap assessments for new and existing AI use cases. - Identify and support mitigation of AI-specific risks, including data leakage, prompt injection, model extraction, model inversion, training data poisoning, insecure output handling, excessive agency, insecure RAG implementations, supply chain compromise, and unauthorised access. - Partner with engineering, data science, platform, and security teams to embed security into AI development, MLOps, CI/CD pipelines, deployment workflows, and operational monitoring. - Advise on secure handling of training, validation, test, and production data, including data minimisation, anonymisation, access control, retention, lineage, provenance, and protection of confidential or regulated information. - Assess security risks associated with third-party AI platforms, foundation models, SaaS AI tools, APIs, open-source models, datasets, plugins, extensions, and model marketplaces. - Define security requirements for AI vendor due diligence, procurement, onboarding, contractual review, and ongoing supplier assurance. - Work with security operations and incident response teams to define AI-specific logging, monitoring, detection, investigation, and response requirements. - Monitor AI security developments, emerging threats, attack techniques, industry standards, and regulatory expectations, translating them into practical internal controls and guidance. - Promote AI security awareness across engineering, production, data science, business, and technology teams through guidance, workshops, reusable patterns, and stakeholder engagement. - Support the Director of Cyber Security Architecture with AI security strategy, governance, reporting, and other duties as required. ## Qualifications - Significant experience in cyber security architecture, application security, cloud security, platform security, data securit…