Senior Lead Security Architect, Ai/ml Platforms

JPMorgan Chase JPMorgan Chase · Banking · Plano, TX +1 · Corporate Sector

Senior Lead Security Architect focused on developing and implementing cybersecurity solutions for AI applications, AI agents, and platform products within an enterprise environment. The role involves driving security strategies, designing secure architectures, identifying and mitigating AI-specific vulnerabilities, and collaborating with various stakeholders to ensure responsible AI innovation.

What you'd actually do

  1. Develop and enhance security strategies, red teaming programs, and solution designs, while troubleshooting technical issues and creating scalable solutions across AI platforms, AI applications, and agentic workflows.
  2. Design secure, high-quality AI and software architectures, reviewing and challenging designs and code to ensure adversarial resilience, secure-by-default patterns, and appropriate compensating controls.
  3. Reduce AI, LLM, and agent security vulnerabilities by applying industry standards and emerging AI safety research, and by evolving policies, testing protocols, and technical controls across the full model development lifecycle (MDLC) and agent runtime.
  4. Collaborate with stakeholders across product, data science, cyber, legal, and risk to understand AI and agent use cases, drive alignment on AI risk tolerance and mitigation priorities, and recommend modifications during periods of heightened vulnerability, incident response, or regulatory change.
  5. Conduct discovery, threat modeling, and adversarial testing on generative AI, RAG pipelines, ML systems, and AI agents to identify vulnerabilities such as prompt injection, jailbreaking, data poisoning, tool abuse, insecure memory/context handling, and unauthorized action execution.

Skills

Required

  • 5 years of applied experience in cybersecurity architecture and/or securing AI/ML systems, including architecture reviews and risk-based control design.
  • Practical cloud-native experience in AWS, GCP and/or Azure, with hands-on experience using Public Cloud AI/ML services (e.g., SageMaker, Bedrock) and applying enterprise security patterns in production environments.
  • Advanced proficiency in one or more programming languages or applications, with the ability to review code and architecture for security and resilience concerns.
  • Advanced knowledge of cybersecurity architecture, applications, and technical processes, with considerable in-depth knowledge in artificial intelligence and machine learning.
  • Experience with AI and machine learning concepts and technologies, including notebooks, Python, TensorFlow, PyTorch, and common ML development workflows.
  • Solid understanding and practical experience across the model development lifecycle (MDLC), including data acquisition and preparation, model experimentation, training and testing, serving, and MLOps.
  • Solid understanding of the AI system attack surface, threats, and mitigating controls across the MDLC, including AI-specific risks such as prompt injection, training data compromise, unsafe output handling, and retrieval risks.
  • Working knowledge of AI agent security/safety fundamentals, including authN/authZ, secure tool/skill use, least-privilege execution, secure context and memory handling, and requirements for logging and observability suitable for audit and incident response.
  • Knowledge of AI safety, AI alignment, and AI cybersecurity concepts and trends, with the ability to translate evolving threats into practical engineering controls.

Nice to have

  • Practical experience designing, developing, or securing AI agents following security best practices, including safe orchestration patterns

What the JD emphasized

  • AI applications, AI agents, and platform products
  • AI, Machine Learning, and agentic systems
  • responsible innovation
  • AI Systems Cybersecurity Architect
  • safe and secure AI at enterprise scale
  • AI platforms, AI applications, and agentic workflows
  • AI and software architectures
  • AI, LLM, and agent security vulnerabilities
  • full model development lifecycle (MDLC) and agent runtime
  • AI and agent use cases
  • AI risk tolerance
  • generative AI, RAG pipelines, ML systems, and AI agents
  • prompt injection, jailbreaking, data poisoning, tool abuse, insecure memory/context handling, and unauthorized action execution
  • agent security/safety controls
  • authentication and authorization (authN/authZ)
  • least-privilege tool access
  • AI applications and agents
  • auditability of prompts, tool calls, policy decisions, and model outputs
  • agent harness/orchestration patterns
  • secure execution boundaries
  • Model Context Protocol (MCP)
  • tool-connection mechanisms
  • AI/ML services and agent runtime dependencies
  • emerging AI and agent threats
  • engineering guardrails
  • securing AI/ML systems
  • Public Cloud AI/ML services
  • enterprise security patterns
  • artificial intelligence and machine learning
  • common ML development workflows
  • model development lifecycle (MDLC)
  • AI system attack surface, threats, and mitigating controls
  • AI-specific risks
  • AI agent security/safety fundamentals
  • AI safety, AI alignment, and AI cybersecurity concepts

Other signals

  • Develop and enhance security strategies, red teaming programs, and solution designs, while troubleshooting technical issues and creating scalable solutions across AI platforms, AI applications, and agentic workflows.
  • Design secure, high-quality AI and software architectures, reviewing and challenging designs and code to ensure adversarial resilience, secure-by-default patterns, and appropriate compensating controls.
  • Reduce AI, LLM, and agent security vulnerabilities by applying industry standards and emerging AI safety research, and by evolving policies, testing protocols, and technical controls across the full model development lifecycle (MDLC) and agent runtime.
  • Conduct discovery, threat modeling, and adversarial testing on generative AI, RAG pipelines, ML systems, and AI agents to identify vulnerabilities such as prompt injection, jailbreaking, data poisoning, tool abuse, insecure memory/context handling, and unauthorized action execution.
  • Define and assess agent security/safety controls, including authentication and authorization (authN/authZ) for users, services, and tools; secure session management; least-privilege tool access; and governance for tool/skill registration, enablement, and lifecycle management.