Overview
In this role you will design and implement security controls for AI and ML solutions, ensuring safe deployment across Checkout’s platforms. You will collaborate with engineering, governance, and business teams to embed security into AI tools, assess risks, and enable secure AI adoption at scale. You will shape reference architectures, guardrails, and monitoring capabilities to defend AI systems and data pipelines. This is a hands-on, security-focused role at the intersection of cyber and AI, with real impact on our digital payment platform. You will work in a fast-moving environment that values initiative and cross-functional collaboration.
Responsibilities
- Design and implement security controls for AI/ML solutions, including LLM-based applications and cloud infrastructure
- Assess security, privacy, and compliance risks of AI systems (e.g., model misuse, prompt injection, data leakage)
- Develop standards, guardrails, and reference architectures for secure AI use
- Review AI use cases and deployments for alignment with security policies and governance
- Build and maintain monitoring, detection, and response capabilities for AI threats
- Identify opportunities to use AI to enhance cyber security operations (e.g., alert triage, automation)
- Stay current on AI security risks, regulations, and industry practices (e.g., EU AI Act, ISO42001)
Key requirements
- Experience in cyber security engineering or security architecture
- Strong knowledge of IAM, cloud security, application security, data protection, logging/monitoring, and incident response
- Knowledge of AI/ML and LLM concepts, including model deployment, embeddings, prompt handling, and AI security risks
- Experience securing cloud environments on AWS, Azure, or GCP
- Familiarity with risks such as prompt injection, data exfiltration, insecure model access, supply chain risks, model poisoning
- Experience conducting architecture reviews, threat modelling, and security assessments
- Ability to translate risk into actionable guidance for technical and non-technical stakeholders
- Strong collaboration across cyber security, engineering, data, legal, and business teams
- Proactive mindset in a fast-evolving security landscape
- collaboration
- communication
- proactive mindset
- AI/ML concepts
- LLMs and prompt handling
- model deployment patterns
…
