Sr. AI & Agentic Security Architect

The Sr. AI & Agentic Security Architect will define, govern, and secure MetLife’s enterprise AI ecosystem by establishing the Agentic Security Control Plane and enabling the safe, compliant, and scalable adoption of AI technologies. This role supports AI innovation while ensuring robust security, risk management, and regulatory readiness across global operations, focusing on Agentic AI Security, AI/LLM Guardrails, AI Security Posture Management (AI-SPM), Shadow AI Discovery, and secure AI platform architecture.

What you'd actually do

  1. Build security controls that govern agent permissions, tool access boundaries, and inter-agent trust — preventing privilege escalation, unauthorized tool invocation, and unintended autonomous actions across agentic workflows.
  2. Define and operationalize threat models for LLM-based systems covering prompt injection (direct and indirect), insecure output handling, excessive agency, training data poisoning, and model misuse — aligned to OWASP LLM Top 10 and MITRE ATLAS.
  3. Own the architecture of the enterprise AI SPM capability — providing continuous visibility into the full AI asset inventory including models, agents, MCP servers, orchestrators, and tool registries, as well as risk posture and policy compliance status.
  4. Lead the technical design and implementation of Shadow AI Discovery capabilities — detecting unsanctioned AI tools, models, services, and agentic deployments across the enterprise through network telemetry, cloud resource scanning, API gateway analysis, and endpoint signals.
  5. Embed security controls and automated benchmarks into CI/CD pipelines across the AI development lifecycle — covering model training, fine-tuning, agent deployment, and inference stages.

Skills

Required

  • 5-7 years of overall experience
  • Designing and implementing enterprise AI security, governance, and risk management programs
  • Implementing AI security controls, AI guardrails, AI application security, and AI asset discovery capabilities
  • Strong knowledge of AI security and risk frameworks such as NIST AI RMF, MITRE ATLAS, OWASP AI guidance, or equivalent industry standards
  • Securing AI applications, copilots, LLM-based solutions, agentic systems, or comparable AI technologies in cloud environments
  • Strong cloud and security architecture background with the ability to assess and mitigate AI-related risks
  • Ability to operate independently, influence technical decisions without direct authority, and communicate effectively with both engineering teams and executive stakeholders

Nice to have

  • AI Security Posture Management (AI-SPM)
  • Shadow AI Discovery
  • ISO/IEC 42001
  • LangChain, LangGraph, AutoGen, CrewAI, Semantic Kernel, or similar frameworks
  • MCP (Model Context Protocol) architecture and security implications
  • Experience with agentic AI security assessments and threat modeling (e.g., MITRE ATLAS)

What the JD emphasized

  • establishing the Agentic Security Control Plane
  • safe, compliant, and scalable adoption of AI technologies
  • Agentic AI Security
  • AI/LLM Guardrails
  • AI Security Posture Management (AI-SPM)
  • Shadow AI Discovery
  • secure AI platform architecture at scale
  • agent permissions
  • tool access boundaries
  • inter-agent trust
  • unintended autonomous actions
  • agentic workflows
  • LLM-based systems
  • prompt injection
  • insecure output handling
  • excessive agency
  • training data poisoning
  • model misuse
  • OWASP LLM Top 10
  • MITRE ATLAS
  • AI SPM capability
  • AI asset inventory
  • risk posture
  • policy compliance
  • Shadow AI Discovery capabilities
  • unsanctioned AI tools
  • models
  • services
  • agentic deployments
  • network telemetry
  • cloud resource scanning
  • API gateway analysis
  • endpoint signals
  • CI/CD pipelines
  • AI development lifecycle
  • model training
  • fine-tuning
  • agent deployment
  • inference stages
  • AI and agentic security
  • AI system designs
  • production deployment
  • AI platform engineering
  • MLOps
  • DevOps
  • IAM
  • Enterprise Architecture
  • Security Engineering
  • Regional teams
  • AI development practices
  • enterprise AI security
  • governance
  • risk management programs
  • AI security controls
  • AI guardrails
  • AI application security
  • AI asset discovery capabilities
  • AI security and risk frameworks
  • NIST AI RMF
  • MITRE ATLAS
  • OWASP AI guidance
  • AI applications
  • copilots
  • LLM-based solutions
  • agentic systems
  • cloud environments
  • cloud and security architecture
  • AI-related risks
  • AI Security Posture Management (AI-SPM)
  • Shadow AI Discovery
  • agentic AI security assessments
  • threat modeling

Other signals

  • establishing the Agentic Security Control Plane
  • enabling the safe, compliant, and scalable adoption of AI technologies
  • shape the security foundation for the next generation of AI and agentic technologies
  • enterprise-wide capabilities in Agentic AI Security, AI/LLM Guardrails, AI Security Posture Management (AI-SPM), Shadow AI Discovery, and secure AI platform architecture at scale