Info Security Architect - AI
Webster, MA, US
Summary
The AI Security Architect is responsible for designing, implementing, and governing security frameworks and requirements to enable the secure use of AI including Generative AI (GenAI), Agentic AI, and related AI technologies and related infrastructure. This role ensures AI technologies are developed and deployed securely and in compliance with regulatory and organizational requirements throughout the AI solution lifecycle, including model development, deployment, inference, and operational monitoring. This role will be part of cybersecurity organization with a matrix line to the AI team and serve as the primary subject matter expert on AI-specific security risks, threats, and controls across the enterprise.
Key Responsibilities
- Develop secure-by-design architecture guidelines for AI/ML platforms, including data ingestion, model training, model deployment, and inference layers.
- Define security architectures and guardrails for Generative AI, Agentic AI, AI agents, tool use, orchestration frameworks, and enterprise AI integrations
- Lead AI-specific threat modeling activities and develop reusable security patterns for GenAI, RAG, and Agentic AI solutions to address risks such as prompt injection, model manipulation, excessive permissions, and data exposure.
- Define reference security architectures, patterns, and guardrails that enable secure AI development while minimizing manual review and approval friction.
- Partner with respective engineering teams to automate / integrate in the security guardrails and controls where possible.
- Design risk-based, proportionate AI security controls that satisfy regulatory and enterprise requirements while enabling rapid AI development and experimentation.
- Identify threats unique to AI systems—model inversion, poisoning, evasion attacks, data leakage, prompt injection, etc. Evaluate emerging AI security threats, tools, and best practices.
- Lead AI-specific risk assessments and security design reviews.
- Work with red teams to validate model robustness against adversarial attacks.
- Define and maintain AI security requirements, standards, and technical controls that support the objectives of the AI Policy and AIS Governance Program. Ensure security requirements are aligned with enterprise security policies, applicable regulations, and approved governance standards.
- Partner with Data & AI Governance, Advance Analytics, platform engineering, cloud security, and compliance teams.
- Assess the cybersecurity risks associated with third-party AI vendors, models, platforms, and services, and recommend security requirements and mitigating controls.
- Define security logging, monitoring, .detection, and response requirements for AI systems, including agent misuse, prompt attacks, unauthorized model access, abnormal inference activity, and sensitive data exposure.
Required Skills & Qualifications
- 10+ years in cybersecurity architecture or engineering roles.
- Strong knowledge of modern AI/ML architectures,Generative AI, RAG, and Agentic AI architectures, pipelines, and tooling. Experience with LLM security, prompt safety testing, adversarial AI risks, and AI security control design.
- Experience securing enterprise AI platforms and cloud AI services (e.g., Azure OpenAI, AWS Bedrock, Google Vertex AI, Databricks, or equivalent).
- Experience applying AI security and governance frameworks such as NIST AI RMF, MITRE Atlas or similar frameworks.
- Understanding of AI based attacks and threats.
- Strong knowledge of data protection and controls required to protect data.
- Knowledge of creating and communicating cybersecurity risks both in technical and non-technical manner.
- Experience working in AI/ML or data engineering environments.
- Proven track record designing enterprise security frameworks or architecture patterns.
- Excellent communication with technical and non-technical stakeholders.
- Strong analytical, problem-solving, and decision-making abilities.
- Leadership skills to guide engineering teams and influence organizational policy.
- Knowledge of regulatory frameworks specific to Insurance (HIPAA, PCI, etc.)
- Experience operating within complex enterprise environments where platform, cloud, or infrastructure ownership is distributed across multiple teams.
Why Mapfre?
As a global insurance leader with a strong local presence, we offer more than a job — we provide a purpose-driven career where your growth, well-being, and impact truly matter.
Purpose & Culture: Join a company built on trust, collaboration, and inclusion. Our values guide everything we do, creating a workplace where people feel respected and empowered.
Comprehensive Benefits: Enjoy competitive health coverage, retirement plans, paid time off, flexible work options, and lifestyle perks like employee discounts.
Career Growth: Advance your skills through tuition reimbursement, leadership programs, and internal mobility opportunities. Your development is our priority.
Social Responsibility: Contribute to meaningful initiatives through Fundación Mapfre, supporting communities and sustainability worldwide.
Pay Philosophy: The typical starting salary range for this role is determined by several factors including skills, experience, education, certifications, and location. Some roles at Mapfre are eligible for commission and/or bonus earnings, in addition to salary, calculated based upon factors set forth in the compensation plan for the role.
Salary Range: $120,000 - $160,000
If you require an accommodation for a disability so that you may participate in the selection process, you are encouraged to contact the Mapfre Insurance Talent Acquisition team at talentacquisition@mapfreusa.com.
We are proud to be an equal opportunity employer.
Nearest Major Market: Worcester
Job Segment:
Compliance, Recruiting, Cyber Security, Engineer, Law, Legal, Human Resources, Security, Engineering