Sr. Information Security Architect – AI & Cloud Security

Bank of America Bank of America · Banking · Washington, WA +2

Senior Information Security Architect focused on AI & Cloud Security at Bank of America. The role involves defining secure architecture patterns, assessing AI/ML solutions, and ensuring compliance with security policies. Key responsibilities include evaluating system impacts, performing threat modeling, and translating requirements into controls for cloud, data, and application environments, with a specific emphasis on Generative AI, LLMs, RAG, and enterprise AI agents. The candidate will collaborate with various teams to embed security into the design of AI systems.

What you'd actually do

  1. Develop and maintain secure design patterns and controls for AI/ML solutions, including LLMs, RAG architectures, vector databases, and enterprise AI agents.
  2. Conduct AI-specific risk assessments using frameworks including MITRE ATLAS, OWASP Top 10 for LLMs/GenAI, and NIST AI RMF.
  3. Perform detailed threat modeling (STRIDE or equivalent) for cloud, application, data, and AI use cases.
  4. Work across lines of business, operations, enterprise architecture, data science, and development teams to ensure clear solution intent and secure-by-design outcomes.
  5. Provide solution options to resolve architectural constraints and remove design impediments.

Skills

Required

  • 8+ years of experience in information security or enterprise architecture
  • recent focus on AI/ML or Generative AI security
  • Proven experience performing secure architecture assessments, design reviews, and threat models for complex, integrated systems
  • Strong understanding of Generative AI, LLM risk, and security frameworks (MITRE ATLAS, OWASP LLM Top 10, NIST AI RMF)
  • Broad experience across cloud platforms (AWS), identity, key management, secrets management, networking, containers, and API security
  • Expertise in interpreting and applying internal security policies, standards, and controls
  • Strong communication skills
  • Demonstrated ability to drive decisions, collaborate across teams, and balance risk vs. business needs
  • Hands-on experience preparing technical diagrams and threat models

Nice to have

  • Experience with advanced developer tools such as GitHub Copilot, Microsoft Copilot Studio, or similar AI coding assistants
  • Certifications such as CISSP, CISM, CCSP, CCSK, CRISC, or cloud architecture/security certifications
  • Familiarity with agile methodologies, DevOps practices, CI/CD pipelines, and developer experience platforms
  • Experience in financial services or other regulated industries

What the JD emphasized

  • recent focus on AI/ML or Generative AI security
  • Proven experience performing secure architecture assessments, design reviews, and threat models
  • Strong understanding of Generative AI, LLM risk, and security frameworks (MITRE ATLAS, OWASP LLM Top 10, NIST AI RMF)
  • Broad experience across cloud platforms (AWS), identity, key management, secrets management, networking, containers, and API security
  • Hands-on experience preparing technical diagrams and threat models
  • AI-specific risk assessments
  • detailed threat modeling
  • AI/ML pipelines

Other signals

  • Assessing emerging AI/ML solutions
  • Ensuring alignment with Global Information Security (GIS) policies
  • Defining secure architecture patterns
  • Evaluating system impacts, data flows, integration points
  • Translating complex requirements into actionable controls
  • Partnering closely with technology leaders, product teams, developers, and enterprise architects
  • Ensuring security is embedded into early design
  • Deploying Generative AI systems in a resilient, safe, and compliant manner
  • Broad architecture experience
  • Hands-on technical depth
  • Strong threat modeling skills
  • Demonstrated expertise securing AI, ML, and LLM-based systems