We are looking for a Corporate Security Engineer, AI to own the security of how artificial intelligence is adopted and operated across Capital.com.
AI tools are already embedded in how the company works — and the security risks they introduce are unlike those any other team currently owns. This role sits in Corporate Security and is responsible for AI system integration security, AI-specific threat detection, data protection in AI contexts, shadow AI governance, and the regulatory compliance obligations that AI adoption brings with it.
The ideal candidate understands how LLMs, RAG systems, and AI automation tools actually work — and can apply that understanding to evaluate what risks they introduce, design controls that hold, and build the governance framework that makes AI adoption secure and auditable in a regulated financial services environment.
Review and assess the security of AI system integrations across the corporate environment: LLM deployments, RAG pipelines, AI APIs, and AI-enabled automation tools
Evaluate configuration, access controls, and data flows of AI systems — the security of how AI is deployed and connected to corporate data and infrastructure
Conduct threat modelling for AI integrations and define secure deployment patterns for AI-powered tools
Support security reviews for new AI initiatives, tools, and vendor integrations before they reach production
Identify and mitigate AI-specific threats: prompt injection & jailbreaks, model poisoning & data contamination, adversarial attacks, training-data leakage, insecure model serialisation, excessive permissions in AI agents
Develop guardrails, content filters, and output-validation mechanisms
Implement monitoring for anomalous AI behaviour across integrated systems
Own data protection controls in AI contexts: govern what data reaches LLM integrations, AI APIs, and AI-enabled tools
Design and maintain DLP policies specifically for AI channels — share links, API-connected AI tools, AI browser extensions, and automation agents
Ensure AI system compliance with GDPR, data-privacy regulations, and financial-industry data handling requirements
Perform AI-specific data risk assessments aligned with the internal risk methodology
Operate the controls that govern AI tool use across the organisation — detection policies, sanctioned-tool enforcement, share-link and egress controls
Lead third-party AI tool due diligence and ongoing assurance of AI vendor integrations
Monitor AI tool usage patterns and investigate anomalous behaviour
Contribute to AI security standards, internal policies, and the company's AI risk classification framework
Own the AI security governance framework: policy authoring, risk classification, control design, and regulatory mapping
Maintain the AI risk register and report on AI-related risk posture to management
Map AI security controls against applicable regulatory frameworks: EU AI Act, NIST AI RMF, ISO/IEC 42001, GDPR, and financial-sector requirements across FCA, CySEC, ASIC, SCB, and SCA jurisdictions
Participate in audit cycles; provide technical evidence and explain AI control design to auditors and regulators
3–5+ years in cybersecurity with hands-on experience in AI/ML system security or a strong AI security focus;
Deep knowledge of AI-specific security risks and mitigations: prompt injection, model poisoning, data leakage, adversarial attacks, excessive permissions in AI agents;
Hands-on experience securing LLM integrations, RAG pipelines, and AI APIs — reviewing configurations, access controls, and data flows;
Experience authoring AI security policies, standards, and risk classification frameworks;
Familiarity with AI governance frameworks: EU AI Act, NIST AI RMF, ISO/IEC 42001, and their application in a regulated financial services context;
Experience running AI risk assessments and maintaining an AI risk register;
Ability to manage third-party AI tool due diligence and control shadow AI across a distributed workforce;
Python proficiency for automation and scripting.
Recognised certifications: CISM, CISSP, or equivalent;
Experience in fintech or a regulated financial services environment;
Multi-jurisdiction compliance exposure (FCA, CySEC, ASIC, SCB, or SCA);
Experience building AI-powered security automation — autonomous agents, LLM-driven triage, automated response workflows;
Experience presenting AI security risk posture to leadership or board-level audiences.
Strong analytical and problem-solving skills;
Ability to translate technical AI risk into business and regulatory impact;
Able to explain AI security risks and mitigations to non-security teams;
Cross-functional collaboration with risk, compliance, product, and engineering teams;
Clear documentation and communication skills.
Published on: 7/27/2026

Capital.com
Capital.com is a high-growth, investment trading fintech group of companies empowering people to participate in financial markets.
Please let Capital.com know you found this job on Wantapply.com. It helps us to get more jobs on our site. Thanks!