- Company Name
- OPENCHIP & SOFTWARE TECHNOLOGIES
- Job Title
- AI Security Architect
- Job Description
-
**Job Title:** AI Security Architect
**Role Summary:**
Lead the security‑by‑design strategy for a cloud‑native AI platform that runs large language models and multi‑agent systems. Define and implement secure foundations across infrastructure, runtime, and application layers, ensuring zero‑trust principles, confidential computing, and privacy‑preserving technologies are integrated from day one.
**Expactations:**
- Design and enforce a secure architectural baseline that satisfies regulatory frameworks (NIS2, CRA, ISO 27001, AI Act).
- Collaborate with engineering, GRC, and platform teams to embed security controls into every stage of the AI lifecycle.
- Drive continuous improvement of security practices, including automated compliance, threat modelling, and internal culture.
**Key Responsibilities:**
- Establish a secure Kubernetes‑based foundation in partnership with platform architecture.
- Design and maintain a cloud‑native security reference architecture covering:
- Pod security policies and runtime controls.
- IAM, RBAC, multi‑tenancy, and network segmentation.
- Secret management and zero‑trust communication.
- Secure the software supply chain through SBOMs, signing, provenance, and verification processes.
- Define and apply security controls for container workloads, operators, and extensions.
- Partner with platform engineers on secure CI/CD pipelines, IaC policies, and deployment workflows.
- Lead threat‑modeling, security design reviews, and risk mitigation initiatives.
- Integrate confidential computing, fully‑homomorphic encryption, and zero‑knowledge proof technologies into the platform.
- Contribute to internal security training, culture, and best‑practice documentation.
**Required Skills:**
- Proven experience in security architecture, infrastructure security, or platform engineering roles.
- In‑depth knowledge of Kubernetes internals (control plane, admission controllers, namespaces, operators).
- Expertise in cloud‑native security, IAM, RBAC, and network segmentation.
- Strong background in secure SDLC, software supply‑chain security, and security reviews.
- Familiarity with Confidential Computing, FHE, and ZKP concepts (preferred).
- Understanding of generative AI and agentic application security threats and mitigations.
- Excellent communication, collaboration, and problem‑solving skills.
- Proactive, automation‑driven mindset with a “can‑do” attitude.
**Required Education & Certifications:**
- Bachelor’s degree in Computer Science, Information Security, or related field (or equivalent experience).
- Industry certifications such as CISSP, CISM, CEH, or cloud‑native security credentials (e.g., GCP Professional Cloud Security Engineer, AWS Security Specialty) are highly desirable.