GenAI Security Platform Architect
Listed on 2025-12-20
-
IT/Tech
AI Engineer, Cybersecurity, Machine Learning/ ML Engineer
GenAI Security Platform Architect role at Liberty Mutual Insurance
Base pay range: $/yr - $/yr
DescriptionWe deliver peace of mind to our customers by protecting what they value most. At Liberty Mutual, we are a tech startup within a Fortune 100 company driving a digital disruption that redefines the insurance experience. This role offers a hybrid work schedule (2 days onsite) for candidates in Portsmouth, NH;
Boston, MA;
Plano, TX;
Indianapolis, IN; and Columbus, OH.
The Security Architecture & Innovation team within the Global Cybersecurity organization is seeking a seasoned GenAI Security Platform Architect. You will define and implement the security architecture, controls, and governance for our AI platforms, models, and AI-enabled products, partnering closely with Data Science, Enterprise Data & Analytics Technology, MLOps, Platform/Cloud, Legal/Privacy, and Global Cybersecurity Governance Risk and Compliance.
Responsibilities- Architect and strategize the end-to-end security architecture for AI/ML systems including training, fine‑tuning, inference, RAG, agents, and integrations.
- Develop and maintain reference architectures and guardrails for common AI patterns such as RAG with vector databases, multi‑agent workflows, LLM API integrations, and on‑prem versus cloud model hosting.
- Create an AI security controls library mapped to frameworks (e.g., NIST AI RMF, OWASP Top 10 for LLM Apps, MITRE ATLAS).
- Establish risk appetite and control requirements, perform design reviews, and sign off on AI initiatives.
- Define security baselines, secure configurations, and kill‑switch/rollback strategies for AI components.
- Continuously assess threat landscape and update risk models specific to AI/ML, GenAI, and the insurance sector.
- Integrate security into the ML/LLM SDLC and CI/CD pipelines across dataset curation, feature engineering, model training, evaluation, packaging, registry, and deployment.
- Partner with Global Cybersecurity, Global Digital Solutions, and Liberty IT to enforce least privilege, secrets management, and policy‑as‑code for AI pipelines and serving infrastructure.
- Champion Dev Sec Ops automation for AI projects by embedding security controls directly into development pipelines.
- Recommend and consult on adversarial testing and red‑team efforts, including jailbreak/prompt‑injection testing, model evasion scenarios, and safety evaluations.
- Design defenses such as input/output filtering, content moderation, prompt hardening, retrieval sanitization, and adversarial training.
- Implement monitoring for model drift, anomaly detection, and harmful output prevention; develop response playbooks for AI incidents.
- Ensure data minimization, classification, encryption, and access controls for training and inference data, including embeddings and vector stores.
- Maintain compliance with global privacy regulations (CCPA, NYDFS, GDPR, etc.) in AI/ML contexts.
- Collaborate with GRC on AI security governance, policies, and standards; define control objectives and measurable KPIs.
- Recommend governance and compliance standards, support vendor/security assessments, and guide build‑vs‑buy decisions for AI security tools.
- Mentor teams on best practices, building internal capability across engineering, risk, and product functions.
- Bachelor’s degree in Computer Science, Engineering, Information Security, or equivalent experience.
- Minimum 8+ years in Cybersecurity with 3+ years focused on securing AI/ML systems or GenAI applications.
- CISSP certification required.
- Deep technical experience designing secure architectures for ML pipelines, MLOps platforms, GenAI workloads, and cloud‑native environments.
- Strong knowledge of AI‑specific threats and mitigations including data poisoning, model inversion, prompt injection, and LLM supply‑chain risks.
- Familiarity with security frameworks: NIST AI RMF, OWASP Top 10 for LLM apps, MITRE ATT&CK & ATLAS.
- Hands‑on experience with identity and access controls, secrets management, encryption, data tokenization, DLP, and AI system monitoring.
- Demonstrated ability to rapidly learn new technologies and influence architecture across stakeholders.
- Excellent written and verbal…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).