Zurich
Senior AI Security Architect / GenAI Security Architect (m/f/d) – Banking
- 05 October 2026
- 45%
- Temporary
About the job
For a long-term mandate at a leading Swiss financial institution, we are seeking an experienced Senior AI Security Architect with a solid background in Cyber Security, Cloud/Application Security, as well as modern GenAI, LLM, and RAG architectures.
Senior AI Security Architect / GenAI Security Architect (m/f/d) – Banking
Job description:
- Design and further development of a holistic security architecture for AI/GenAI use cases
- Development of AI-specific threat models for LLM, RAG, and agent architectures
- Identification and assessment of risks such as prompt injection, jailbreaking, model manipulation, data poisoning, data leakage, insecure output handling, and security-relevant hallucinations
- Derivation and definition of appropriate preventive and detective security controls
- Establishment of security-by-design for RAG applications, retrieval processes, vector databases, and connected knowledge sources
- Ensuring existing permission models within AI/RAG contexts
- Prevention of cross-user and cross-tenant leakage, unauthorised information aggregation, and data exfiltration
- Development of identity, authorisation, and trust concepts for users, models, agents, and tools
- Definition of role and permission concepts according to least-privilege principles
- Securing agent-to-tool and agent-to-agent communication
- Design of security mechanisms for autonomous agents as well as control of critical or privileged actions
- Development of reusable AI security guardrails
- Design of mechanisms for input/output validation, prompt and context protection, content filtering, and policy enforcement
- Definition of security requirements for tool/plugin approvals, secrets handling, and sandboxing
- Development of monitoring, logging, and detection concepts for AI-based applications
- Translation of technical AI risks into comprehensible architecture, governance, and control requirements
- Close collaboration with security, enterprise architecture, engineering, operations, infrastructure, as well as business and IT stakeholders
- Advising technical and non-technical stakeholders on AI security risks and appropriate protective measures
About the customer:
The role is part of a strategically relevant AI/security environment and focuses on building a holistic security architecture for modern AI usage scenarios. These include, among others, chat-based interactions, retrieval-augmented generation applications, agent workflows, and the use of foundation models.
The goal is to systematically address new attack surfaces and trust boundaries between users, models, agents, tools, data sources, and external services, enabling secure, controllable, and regulatory-compliant AI solutions.
Framework conditions:
- Zurich / Hybrid
- Start: November 2026
- Duration: until February 2028
- Workload: 100%
Requirements:
- Several years of professional experience as a security architect, cyber security architect, cloud security architect, application security architect, or comparable role
- Solid experience in developing and implementing security-by-design concepts
- Very good knowledge in the area of threat modelling
- Profound technical understanding of modern GenAI, LLM, RAG, and agent architectures
- Experience with the security risks of modern AI systems, especially prompt injection, jailbreaking, data leakage, model manipulation, and insecure output handling
- Good knowledge of identity & access management, authorisation, role-based access control, least privilege, and trust models
- Experience with security concepts for APIs, microservices, cloud platforms, and complex enterprise applications
- Experience with monitoring, logging, detection, and security controls in complex system landscapes
- Ability to analyse technical risks in a structured manner and translate them into concrete architecture and control requirements
- Strong communication skills towards technical teams, architecture, management, and business units
- Experience in a regulated environment, ideally banking, financial services, or insurance, is an advantage
- Practical experience securing productive LLM, RAG, or AI agent platforms is a great plus
- Knowledge of relevant AI, cyber security, or regulatory frameworks is advantageous
You will work in a complex and highly regulated banking and financial environment with high demands on security, availability, data protection, and compliance.
The position is embedded in an interdisciplinary environment of architecture, security, engineering, operations, and business units. You will work closely with various transformation, infrastructure, and AI initiatives and take a central role in the secure introduction and scaling of modern AI technologies.
The environment combines agile and traditional project structures and offers a high degree of personal responsibility as well as direct exchange with relevant stakeholders from business and IT management.