Senior Lead Security Architect, AI/ML Platforms

Plano, TXFull-timePosted Aug 4, 2026

As a Senior Lead Cybersecurity Architect at JPMorganChase within the Cybersecurity and Technology Controls organization, you are an integral part of a team that develops high-quality cybersecurity solutions for AI applications, AI agents, and platform products. You will drive measurable business impact by applying deep technical expertise and structured problem-solving methodologies to a diverse array of cybersecurity challenges spanning AI, Machine Learning, and agentic systems. You will partner with product, engineering, and risk stakeholders to identify emerging threats and implement scalable controls that enable responsible innovation. You will help set technical direction through clear guidance, hands-on design reviews, and measurable risk reduction.

We are looking for an experienced AI Systems Cybersecurity Architect to join our team—not only as an AI/ML security subject matter expert, but as someone who is passionate about advancing safe and secure AI at enterprise scale. You’ll work in a collaborative, trusting, thought-provoking environment that values diversity of thought and creative solutions aligned to our customers’ best interests. Best yet, you will join a team of highly motivated AI and security professionals who will help you build a strong foundation for a long-term career at JPMorganChase.

Job responsibilities 

  • Develop and enhance security strategies, red teaming programs, and solution designs, while troubleshooting technical issues and creating scalable solutions across AI platforms, AI applications, and agentic workflows.
  • Design secure, high-quality AI and software architectures, reviewing and challenging designs and code to ensure adversarial resilience, secure-by-default patterns, and appropriate compensating controls.
  • Reduce AI, LLM, and agent security vulnerabilities by applying industry standards and emerging AI safety research, and by evolving policies, testing protocols, and technical controls across the full model development lifecycle (MDLC) and agent runtime.
  • Collaborate with stakeholders across product, data science, cyber, legal, and risk to understand AI and agent use cases, drive alignment on AI risk tolerance and mitigation priorities, and recommend modifications during periods of heightened vulnerability, incident response, or regulatory change.
  • Conduct discovery, threat modeling, and adversarial testing on generative AI, RAG pipelines, ML systems, and AI agents to identify vulnerabilities such as prompt injection, jailbreaking, data poisoning, tool abuse, insecure memory/context handling, and unauthorized action execution.
  • Define and assess agent security/safety controls, including authentication and authorization (authN/authZ) for users, services, and tools; secure session management; least-privilege tool access; and governance for tool/skill registration, enablement, and lifecycle management.
  • Provide guidance on secure design, logging, monitoring, and observability for AI applications and agents, including auditability of prompts, tool calls, policy decisions, and model outputs, with controls to support detection, triage, and forensics.
  • Evaluate and influence agent harness/orchestration patterns to ensure safe execution boundaries, reliable policy enforcement, and strong controls around delegation, automation, and human-in-the-loop requirements.
  • Assess and secure integration patterns for Model Context Protocol (MCP) and similar tool-connection mechanisms, including authorization models, trust boundaries, data minimization, and controls to prevent exfiltration or unsafe tool invocation.
  • Work with platform and cloud security teams to ensure secure infrastructure configuration and alignment with enterprise security architecture, including controls for AI/ML services and agent runtime dependencies.
  • Engage with external researchers, vendors, and standards bodies to track emerging AI and agent threats, and translate best practices into actionable guidance and engineering guardrails.

 

Required qualifications, capabilities, and skills

  • 5 years of applied experience in cybersecurity architecture and/or securing AI/ML systems, including architecture reviews and risk-based control design.
  • Practical cloud-native experience in AWS, GCP and/or Azure, with hands-on experience using Public Cloud AI/ML services (e.g., SageMaker, Bedrock) and applying enterprise security patterns in production environments.
  • Advanced proficiency in one or more programming languages or applications, with the ability to review code and architecture for security and resilience concerns.
  • Advanced knowledge of cybersecurity architecture, applications, and technical processes, with considerable in-depth knowledge in artificial intelligence and machine learning.
  • Experience with AI and machine learning concepts and technologies, including notebooks, Python, TensorFlow, PyTorch, and common ML development workflows.
  • Solid understanding and practical experience across the model development lifecycle (MDLC), including data acquisition and preparation, model experimentation, training and testing, serving, and MLOps.
  • Solid understanding of the AI system attack surface, threats, and mitigating controls across the MDLC, including AI-specific risks such as prompt injection, training data compromise, unsafe output handling, and retrieval risks.
  • Working knowledge of AI agent security/safety fundamentals, including authN/authZ, secure tool/skill use, least-privilege execution, secure context and memory handling, and requirements for logging and observability suitable for audit and incident response.
  • Knowledge of AI safety, AI alignment, and AI cybersecurity concepts and trends, with the ability to translate evolving threats into practical engineering controls.

 

Preferred qualifications, capabilities, and skills

  • Practical experience designing, developing, or securing AI agents following security best practices, including safe orchestration patterns, secure tool connectivity, and controlled autonomy.
  • Experience with API security + IAM/enterprise authorization, including authentication, authorization, abuse-prevention controls for AI-facing and agent-facing APIs, and OAuth 2.0, OpenID Connect, and SAML.
  • Knowledge of containers and container orchestration (Docker, Kubernetes, Helm) and the security implications of runtime isolation and workload identity.
  • Knowledge of cloud infrastructure as code (IaC) (Terraform), including secure-by-default patterns and control enforcement.
  • Knowledge of networking concepts and protocols (TCP/IP, routing, DNS, DHCP) and how these affect secure deployment and segmentation of AI systems.
  • Familiarity with MCP and/or other agent tool-connection standards, including security implications of tool discovery, trust boundaries, and authorization delegation.
  • Preferred certifications (one or more): AWS Certified Machine Learning – Specialty, Microsoft Certified: Azure Data Scientist Associate, AWS Certified Security – Specialty, Microsoft Certified: Cybersecurity Architect Expert, and/or CISSP.

 

This role is designated as a High Risk Role (HRR) and is subject to additional pre-hire screening and/or role-based requirements in accordance with applicable firm policies

#CTC

Want jobs like this matched to you?

SimpleCareer scores fresh postings against your résumé so you only see the matches that matter.

Get started free