Nomado24 Logo

Remote job

AI Security Engineer

J.S. Held

Source: HimalayasLocation: RemoteConfirmed active: Jul 05, 2026
FinTech

Job description

J.S. Held , a global consulting firm providing specialized technical, scientific, financial, and advisory services, is seeking an AI Security Engineer is a senior, hands‑on technical role responsible for designing, engineering, and operationalizing AI security across J.S. Held ’s enterprise.

This role serves as the central Cyber Security owner for all AI Security, ensuring AI technologies are securely designed, implemented, and operated across AI‑enabled third‑party applications, internal AI agents, models, MCP, RAG architectures, training and fine‑tuning pipelines, and supporting AI platforms.

The role balances hands‑on engineering, solution design, and architectural leadership. While expected to influence standards, patterns, and roadmaps, this is not a purely strategic role—the engineer will actively design and enable controls.

Role weighting:

  • ~70% AI Security Engineering (primary)
  • ~30% Data Security Engineering (secondary), with emphasis on Microsoft Purview, especially where enterprise data is used by AI systems.

Core Responsibilities

AI Security Engineering (Primary – ~70%)

AI Security Architecture & Guardrails

  • Define and evolve the enterprise AI Security Architecture, guardrails, and security requirements aligned to business objectives.
  • Establish secure‑by‑design patterns across AI development, deployment, and operations, including requirements for hardening, hosting, access control, monitoring, and testing.

Platform & Engineering Enablement (Hands‑On)

  • Design and engineer security controls for:
  • AI‑enabled SaaS applications
  • Internal AI agents and automation workflows
  • Model hosting, inference services, APIs, and orchestration layers
  • RAG architectures, vector databases, and embeddings
  • Model training and fine‑tuning pipelines
  • MCP and agent‑to‑agent interaction patterns

AI Identity, Authentication & Authorization

  • Extend identity and access principles to non‑human identities and autonomous agents.
  • Treat AI agents as first‑class identities, defining authentication, authorization, lifecycle management, and revocation.
  • Implement delegated and “on‑behalf‑of” authorization patterns to distinguish human‑initiated actions from agent‑initiated actions.
  • Apply least‑privilege and scope‑limiting controls to prevent privilege escalation in automated and multi‑agent workflows.

Threat Modeling & Risk Reduction

  • Identify and mitigate AI‑specific risks including data leakage, prompt injection, jailbreaks, model abuse, data poisoning, model extraction, and AI supply‑chain risk.
  • Ensure appropriate security testing and validation is embedded into AI development and deployment workflows.

Monitoring & Incident Readiness

  • Define logging, monitoring, and detection requirements for AI systems, models, and agent activity.
  • Partner with SecOps to ensure AI‑related events are observable, auditable, and actionable.
  • Support incident response and post‑incident analysis for AI‑related security events.

Cross‑Functional Delivery

  • Work closely with IAM, SecOps, AppSec, GRC, IT engineering, AI platform teams, and business stakeholders to embed security controls where they belong.

Data Security Engineering (Secondary – ~30%)

Data Protection & Governance

  • Design and enhance enterprise data security controls with a focus on AI‑driven data access.
  • Implement and optimize Microsoft Purview, including data classification, sensitivity labeling, DLP, information protection, and visibility.

AI‑Aware Data Security

  • Ensure data security controls are aligned to AI architectures, reducing risk of sensitive data exposure via prompts, agents, outputs, and downstream sharing.
  • Support secure use of enterprise data in RAG pipelines, AI workflows, and training environments.

Multi‑Platform Data Flows

  • Contribute to data protection strategies across collaboration platforms, cloud services, and endpoints, ensuring consistent enforcement where possible.

Required Qualifications

  • This role requires high proficiency in English (verbal and written) due to regular interaction with global stakeholders. It also requires an excellent Wi‑Fi connection with stable internet.
  • Schedule aligned with  UK business hours. This usually means working from around 2:00 PM to 11:00 PM IST, to match the 8:30 AM to 5:30 PM GMT workday in the UK.
  • 8+ years of experience in cybersecurity engineering, cloud security, application security, or data security
  • Direct, hands‑on experience with Azure AI Foundry and Copilot Studio in enterprise environments
  • Strong experience securing cloud and SaaS platforms (Azure preferred)
  • Deep understanding of identity, access control, data protection, and secure application/API design
  • Proven ability to translate security requirements into practical, deployable controls

Preferred Qualifications

  • Experience securing generative AI, LLM‑based systems, and agentic architectures
  • Experience with Microsoft Copilot Administration, Anthropic and other AI platf
AI Security EngineeringCybersecurity EngineeringCloud SecurityData Security EngineeringInformation SecurityAI Security EngineerAI Cybersecurity EngineerAI Security Architect

This role is provided by an external source. Applications are handled on the source website.

Prepare your application with AI

Have the AI advisor draft a cover letter, analyze how your profile fits this role, and prep you for the interview.

Sign in & prepare with AI

Free — you'll continue right where you left off after signing in.

New jobs by email

We'll email you new matching remote jobs. Free, unsubscribe anytime.

You confirm your subscription by email (double opt-in) and can unsubscribe at any time via the link in every email. Our Privacy Policy.

Similar remote jobs